Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Basic Log filtering in LEM?

$
0
0

For people who are new to LEM and want to do a quick search, the best way is to go to Explore -> nDepth ->Change from Drag & Drop Mode to Text Input -> Type in search query (ex: IP)

 

Default.PNG

 

TextInput.PNG

 

As you become more familiar with how data is normalized and the relevant fields, you can simply drag the fields you need to the query builder and add other fields to further define your query. Although there is a learning curve associated with this work flow, it's extremely powerful once you understand the different fields and how to use them.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>