The ESM Live View and Scratchpad are independent windows. This allows you to work on other tabs in Sentinel simultaneously as you work on ESM.
The Event Source Management windows include:
A Menu Bar with the ESM menus
A Tool Bar which helps you execute the functions of ESM
Several different types of frames to display ESM data
Display Health Monitor frame with graph and table views where you can perform your activities
Figure 10-1 Event Source Management-Live View
The Menu Bar has File, View, Tools and Help options.
Figure 10-2 Event Source Management-Menu Bar
The following are the options available in the each of the Menu Bar options which are described in the document:
File
Export Configuration
Import Configuration
Save Preferences
Close
View
Reset Layout
Redo Layout
Undo Layout
Tools
Connect to Event Source
Import plugin
Help
About
Help
These options allow you to perform a set of actions mentioned below:
Table 10-1 Event Source Management -User Interface
In ESM, you can use Magnifying Glass to zoom into a region.
HINT:To enable/disable magnifying glass in ESM, use the local zooming using a Magnifying Glass button on the toolbar.
You can increase or decrease the magnification factor with the following key combinations:
To increase: Ctrl key + Backward scrolling of the Mouse wheel
To decrease: Ctrl key + Forward scrolling of the Mouse wheel
To Zoom in: Forward movement of the Mouse wheel
To Zoom out: Backward movement of the Mouse wheel
NOTE:Magnification glass is available only in the Graphical View of ESM window.
You can see the following Frames in the Live View or Scratchpad window.
The Attribute Filter allows you to display the components of ESM. You can specify the components to be displayed based on the component name and status.
Figure 10-3 Attribute Filter frame
Text Filter: It allow you to filter the nodes that are displayed in the graphical and tabular view based on the text they type in.
State Filter: It allows you to filter the nodes that are displayed in the graphical and tabular view based on the current state of the node.
The Hierarchy filter sets the display based on the hierarchy you select in this frame. It allows the user to filter the nodes that are displayed in the graphical and tabular view based on the node hierarchy. All children and parents of selected nodes are shown.
Figure 10-4 Hierarchy Filter frame
In Sentinel Control Center, click the Event Source Management in the menu bar and select Live View or Scratch Pad.
Click the Hierarchy Filter frame.
Select the Hierarchy Level to display the components.
Connectors are plugins in Sentinel. Importing a Connector implements the Connector mechanism in the system. Connectors frame allows you to Add, Remove, and Refresh connectors and Add auxiliary file in the system.
Figure 10-5 Connector frame
Table 10-2 Connector frame Icons
Add |
Add Connectors to the system. |
|
Delete |
Delete Connectors. |
|
Refresh |
Refreshes the list. |
|
Add Auxiliary Files |
Add Auxiliary Files. For more information, see Add Auxiliary Files |
In Sentinel Control Center, click the Event Source Management in the menu bar and select Live View or Scratch Pad.
Click the Script or Connectors frame. You can plugin connectors from here. For more information, see Adding Connectors/Collector Plugins.
Collectors are plugins in Sentinel. Collector plugins add the ability to parse raw data from a particular event source. The Scripts frame is used to manage the importing and updating of Collectors (also called “Scripts”) into Sentinel.
Figure 10-6 Scripts frame
Table 10-3 Scripts frame Icons
Add |
Add Scripts (Collectors) to the system. |
|
Delete |
Delete Collectors. |
|
Refresh |
Refreshes the list. |
|
Add Auxiliary Files |
Add Auxiliary Files. For more information, see Add Auxiliary Files |
In Sentinel Control Center, click the Event Source Management in the menu bar and select Live View or Scratch Pad.
Click the Script or Connectors frame. You can import Collectors from here. For more information, see Adding Connectors/Collector Plugins.
This frame displays the list of Devices or Event Sources supported by the existing Collectors in the Central Repository. Each Collector ships with meta-information that describes the list of event source types supported by that Collector – this information is compiled to provide the data in this palette. The supported devices for a particular Collector might not necessarily be the same as the name of the Collector.
Figure 10-7 Event Source Palette
This frame displays names of immediate children nodes of a parent (main) node when you click the parent node. This frame is useful to manage children of nodes which have been contracted in the Graphical View. To perform any action in ESM, right-click a component and select from options listed. For more information, see Section 10.3.3, Right-Click Menu.
Figure 10-8 Children frame
This frame displays the status details of a selected component in the Health Monitor Display frame.
Available status information includes the current state, the number bytes processed, the number of records sent, the number of Sentinel Events sent, and various other status and statistical information.
NOTE:The status information varies based on the type of component that is selected.
Figure 10-9 Status Details frame
The overview frame allows you to quickly move across the graphical view. This is particularly useful when there are a lot of objects in the screen.
Figure 10-10 Overview frame