Search Event Data from Logger

You can search Logger archived events using the same parameters as in regular searches.

Before running a search on the Logger data, review the following considerations:

 

  1. Select Search > +.
  2. From the list box next to the Search button, select Logger.
  3. Add the required query details.

    You must use the search operators supported in ArcSight Platform.

  4. Click Search.
Note: If UTC time wasn't specified in the time range for importing events, you will need to convert the archive UTC timestamp shown in the Import Logger Data tab to your browser time/selected time zone, and enter that value as search time to fetch events from that time range.