Search Views

The Search Views option provides you with the interface that presents the top search views.

Accessing Search Views

  1. Go to Search from the navigation bar.

../_images/LP_KB_SV_Search_SearchViews.png

Accessing Search Views from the Search Interface

  1. From the Search Views section at the bottom-right corner of the page, you can:

    1. See all the search views: Select the All Search Views link at the bottom.

    LogPoint redirects you to the Search Views page. It contains a list of all the recently created search views.

    ../_images/LP_KB_SV_MainPage.png

    Search Views

    1. See the search results for a single search view: Click the search view.

    LogPoint redirects you the Search Views Interface. Refer to The Search Views Interface for more details.

Note

You can also filter your search by entering the desired keyword in the filter section.

The Search Views Interface

You can access the Search Views Interface page in two different ways.

  • By clicking a particular search view from the Search >> Search Views panel.

  • By clicking a particular search view from the list of Search Views from Settings >> Knowledge Base from the navigation bar and Search Views.

The Search Views Interface is divided into three sections, the Query Bar, the Result Panel, and the Top-10 Panel.

Query Bar

The Query Bar along with the Repo selector and Time range appears at the top of Search Views Interface.

../_images/LP_KB_SV_SVInterface_Query.png

Search Views Interface

Result Panel

The Result Panel displays the details of the selected Search View.

../_images/LP_KB_SV_SVInterface_ResultPanel.png

Search Views Interface

Top-10 Panel

The Top-10 Panel displays ten most frequently searched logs for a number of fields.

../_images/LP_KB_SV_SVInterface_Top10Panel.png

Top-10 Panel

Note

  • You can increase the width of the Top-10 panel by dragging the pointer towards the Result Panel. It gives you a comprehensive view of the Top-10 search results.

../_images/LP_KB_SV_SVInterface_PanelExpansion.png

Top-10 Panel Expanded

  • Click Back to Search Views at the bottom-right corner to redirect to the Search Views List Page.

Adding a Search View

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

../_images/LP_KB_SV_Add.png

Search Views

  1. Click Add to open the Add Search View panel.

../_images/LP_KB_SV_AddPanel.png

Add Search View Panel

  1. Provide a Name and a Description.

  2. Select the fields to be used and click Add. These fields appear on the Search Views Interface.

    Note

    • You can only add the Normalized Fields in a Search View.

    • You can re-order the fields using the arrow keys in the Actions column.

  3. Select the fields to Show on Top 10 List.

  4. Click Submit.

Editing a Search View

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

  2. Click the Name of the view to edit.

../_images/LP_KB_SV_Edit.png

Editing a Search View

  1. Update the information.

  2. Click Submit.

Sharing Search Views

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

  2. Click the Click to Share icon in the Actions column for the view.

    ../_images/LP_KB_SV_Actions_Share.png

    Search Views

    1. To share multiple Search Views, select the concerned views. Click the More drop-down menu and choose Share Selected With Other Users.

    ../_images/LP_KB_SV_ShareSelected.png

    Search Views

    1. To share all the Search Views, click the More drop-down menu and choose Share Selected With All Users.

    ../_images/LP_KB_SV_ShareAll.png

    Search Views

Note

Follow the same method to Unshare search views.

Cloning Search Views

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

  2. Click the Clone icon in the Actions column for the view.

    ../_images/LP_KB_SV_Actions_Clone.png

    Search Views

    1. To clone multiple Search Views, select the concerned views. Click the More drop-down menu and choose Clone Selected.

    ../_images/LP_KB_SV_CloneSelected.png

    Search Views

    1. To clone all the Search Views, click the More drop-down menu and choose Clone All.

    ../_images/LP_KB_SV_CloneAll.png

    Search Views

  3. Enter a new Name for the cloned Search View.

  4. Check the Replace Existing? checkbox to replace an existing view with the same name.

  5. Click Clone.

Deleting Search Views

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

  2. Click the Delete icon in the Actions column for the view.

    ../_images/LP_KB_SV_Actions_Delete.png

    Search Views

    1. To delete multiple Search Views, select the concerned views. Click the More drop-down menu and choose Delete Selected.

    ../_images/LP_KB_SV_DeleteSelected.png

    Search Views

    1. To delete all the Search Views, click the More drop-down menu and choose Delete All.

    ../_images/LP_KB_SV_DeleteAll.png

    Search Views

  3. A delete confirmation dialog box appears on the screen. Click Yes to proceed.

Note

Clone, Information, and Use are the only actions available for the Shared Search Views.

Using a Search View

  1. Go to Settings >> Knowledge Base from the navigation bar and click Search Views.

  2. Click the Use icon in the Actions column of the concerned view.

../_images/LP_KB_SV_Actions_Use.png

Search Views

  1. LogPoint redirects you to the Search Views Interface. Here, you can manage all the information of the selected Search View.

    ../_images/LP_KB_SV_SVInterface.png

    Search Views Interface

    • The Query Bar appears at the top of the Search Views Interface. By default, the query results in the selection of all the field components.

    ../_images/LP_KB_SV_SVInterface_QueryBar.png

    Search Views Interface

    For example:

    action=* col_type=* device_ip=* log_ts=* sig_id=*
    

    Note

    • LogPoint suggests some system fields in an auto-suggest box if you type any letter(s) followed by the space bar.

    • Use only the simple queries. LogPoint uses query validation to restrict the usage of aggregators, rex, norm, and rename commands.

    • Use the Repo selector to specify the repos to extract the logs. By default, all the repos are selected.

    ../_images/LP_KB_SV_SVInterface_RepoSelect.png

    Search Views Interface

    • Specify the Time range to fetch the logs. By default, Last 10 minutes is selected.

    ../_images/LP_KB_SV_SVInterface_TimeRange.png

    Search Views Interface

    • Limit Results to a specific number of logs per page. The default value is set to 25.

../_images/LP_KB_SV_SVInterface_LimitRslt.png

Search Views Interface

Using Drill-down in Search Views

Click the search result in the Result Panel or the Top-10 Panel to perform drill-down. The selected data appends to the query and is visible in the Query Bar.

For example,

Before drill-down:

action=* col_type=* device_ip=* log_ts=* sig_id=* norm_id=*
../_images/LP_KB_SV_SVInterface_BeforeDrilldown.png

Search Views Interface Before Drilldown

After drill-down on action=”reporting speed”:

action="reporting speed" action=* col_type=* device_ip=* log_ts=* sig_id=* norm_id=*
../_images/LP_KB_SV_SVInterface_AfterDrilldown.png

Search Views Interface After Drilldown

Using Negation in Search Views

You can Negate the fields in the query to refine the search results from both the Top-10 Panel and the Result Panel. Press the command key (for Mac) or the Ctrl key (for Windows) and click the field component to carry out the negation.

For example,

Before negating:

action=* col_type=* device_ip=* log_ts=* sig_id=* norm_id=*
../_images/LP_KB_SV_SVInterface_BeforeNegating.png

Before Negation

After negating on action=”denied”:

action= "denied" action=* col_type=* device_ip=* log_ts=* sig_id=* norm_id=*
../_images/LP_KB_SV_SVInterface_AfterNegating.png

After Negation

Note

  • You can administer the Search Views for the remote LogPoints from the Distributed LogPoint drop-down menu on the Header Bar inside the Settings menu.

  • In the Data Privacy Module enabled systems, users with the Can Request Access privilege can only view the values in the encrypted form. These encrypted values cannot be requested for decryption.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support