This section contains information about the features available in version 1.0.00 of the BMC TrueSight IT Data Analytics product:
Create data collectors (using appropriate data patterns) to collect and index various kinds of machine data generated from a variety of data sources, such as applications, servers, websites, network devices, and security devices. You can collect data both locally and remotely, for one-time or continuous monitoring. After this data is collected, it is available for troubleshooting, root-cause analysis, incident investigations, application monitoring, network monitoring, security compliance, business insights, and other such uses.
For more information about data collectors, see Managing data collectors.
Search real-time and historical data using the product user interface.
Use the asterisk (*) as a wildcard character either as a substitute for words before or after a substring.
Use search commands to analyze your data in various ways:
The search bar offers type-ahead search suggestions based on a history of your search queries and displays a list of suggestions that match the last few words of the search query you are typing.
For more information, see Search tab and Search commands.
Discover insights or find answers to your questions by analyzing your data in various ways. Use the timeline and summarization charts to see data trends and discover spikes or anomalies. Click the charts to drill down into the search results and focus on meaningful data. Click fields or raw data in your search results to add it to your search criteria and perform further analysis of your data. Pin important search results that you want to investigate later by clicking the star icon next to the search result. View your search results with different levels of detail and for different time ranges.
Add meaning to your data by specifying fields (while creating data patterns) that must be extracted from your data and by adding tags (while creating data collectors) to add to your search criteria and enhance your search results.
For more information, see Searching the data.
Integrate with external systems such as BMC ProactiveNet Performance Management to directly get event data and perform root cause analysis. You can perform in-depth analysis on events by using the context available from these systems. You can create notifications and custom views to monitor these events, and log events into the external system for any abnormalities found.
For more information about collecting and monitoring events from supported external systems, see Integrating.
The workspace keeps a record of all search queries that you run. Use the workspace to organize your thoughts and capture insights discovered in the course of troubleshooting. You can create multiple workspaces for every task and perform various functions such as marking search queries as favorites, adding notes to the workspace, and so on. You can easily share the steps you used for troubleshooting a problem with others and turn them into best practices. You can run search queries for the original time context or the relative time context from the workspace.
For more information about using the workspace, see Managing workspaces.
Create views to display charts that summarize your search results and enable you to discover trends and characteristics in your data at a glance. You can create views to show multiple charts that enable you to monitor data for different purposes. You can use various views to monitor data and discover relationships between various events or seemingly unrelated activity.
For more information about adding views, see Managing views.
Use the timeline chart to view your data on a timeline and see data trends, rate of data occurrence, frequency of conditions, spikes, and anomalies. You can click the bars in the chart to drill down into the search results and focus on meaningful data.
Use the summarization chart to summarize top values or depict key information and gain a deeper understanding of your data.
For more information, see Using the Timeline and Summarization charts.
While monitoring your data, turn searches into automatically triggered notifications in the form of email messages, or log events into other systems such as BMC ProactiveNet Performance Management and BMC Event Manager. You can attach PDF reports that include search results and charts that summarize the results. You can create notifications based on specified conditions, event thresholds, and time schedules.
For more information about generating notifications, see Managing notifications.
Save your search query if you want to investigate or monitor search results for an extended period of time and locate events or abnormalities. You can build visual representations of search results by creating custom views, or create real-time alerts or notifications based on certain conditions. You can also import or export saved searches into a zipped file by using content packs.
For more information about creating and using saved searches, see Managing saved searches.
Export content packs containing a group of related product artifacts such as saved searches, data patterns, and collection profiles in a zipped format that you can share with others. Import content packs shared by others or stored earlier to use the artifacts imported in the process of data collection and search. Content packs are also useful in a multiple-server environment or when you have multiple product instances.
For more information, see Managing content packs.
You can make your data collection process efficient by automating it in the following ways:
The product provides security at various levels:
Data transfer: Security between internal product components and between internal product components and external product components
User authentication and authorization: Data-access control based on user roles and permissions
For more information about overall product security, see Security.
For more information about default communication ports and protocols, see Communication ports and protocols.
To start the installation process, obtain the appropriate installation files from the BMC Software Electronic Product Distribution (EPD) website.