1.9 Viewing Orchestration Server Data in the Sentinel Event Source Server

The Sentinel Event Source Server displays data from the Orchestration Server.

For each logging event, the Orchestration Server passes a free form text log message and log event metadata to the Sentinel Event Source Server. The following table shows how the data are mapped:

Table 1-1 Orchestration Server Logged Data Mapped to Sentinel Event Source Server Fields

Sentinel Event Field Name

Orchestration Server Data Represented

Message

A free-form text log message.

TargetServiceName

The Orchestration Server grid name.

ReporterIP

The IP address of the Orchestration Server.

TargetServiceComp

The originating facility of the Orchestration Server event.

EventName

A name formatted as gridname: taxonomy_key. For more information, see Event Classification and Taxonomy Keys in the NetIQ Cloud Manager 2.3 Installation Guide.

ProductName

The product is always Cloud Manager Orchestration for convenient event filtering.

  • InitUserName
  • InitUserID

The name of the Orchestration Server user. Used for user-oriented events.

For some events, the Orchestration Server Sentinel Collector passes some structured data related to the log event. When available, this data appears in the ExtendedInformation Sentinel Event field, which is a list of key/value pairs delimited by semicolons. Some keys are always present in ExtendedInformation, but others appear only when relevant. The following table lists these keys:

Table 1-2 Orchestration Server Key/Value Pairs Displayed in the Sentinel Event Source Server

Key

Displayed

Value

loglevel

always

The original Orchestration Server log level, for example, NOTICE, or INFO.

eventclass

always

A symbolic identifier for this class of event, e.g. admin_login, policy_association. This also serves as the taxonomy key. The value is unclassified if the event does not contain any additional structured data.

group

when relevant

The Grid object group related to this log event.

job

when relevant

The job related to this log event.

jobinstance

when relevant

The job instance ID related to this log event.

member

when relevant

The Grid object group member related to this log event.

policy

when relevant

The policy related to this log event.

repository

when relevant

The repository related to this log event.

resource

when relevant

The resource related to this log event.

schedule

when relevant

The schedule related to this log event.

trigger

when relevant

The trigger related to this log event.

type

when relevant

The Grid object type related to this log event.

user

when relevant

The name of the user related to this log event. This key also appears in the InitUserName and InitUserID fields.

vbridge

when relevant

The Vbridge related to this log event.

vdisk

when relevant

The Vdisk related to this log event.

vm

when relevant

The VM related to this log event.

vmhost

when relevant

The VM host server related to this log event.

vnic

when relevant

The VNIC related to this log event.

target

when relevant

The name of the Grid object related to this log event.

action

when relevant

The action related to this log event.