Search Event Data from Logger

Logger archive data can be viewed and consumed using the same parameters as in regular searches. From the Search page, hunt for ArcSight Logger events by selecting the Logger option from the list box next to the Search button.

Before searching Logger events, the data must be imported to the ArcSight Database. The import process might require several imports from several Loggers. Otherwise, the Logger option will not be displayed in the Search page.

Before running a search on the Logger data, review the following considerations:

If Recon and Logger are set to the same timezone, there should be no discrepancy when searching the Logger data.

 

  1. Select Search > +.
  2. From the list box next to the Search button, select Logger.
  3. Add the required query details.

    You must use the search operators supported in ArcSight Platform.

  4. Click Search.