Collecting application logs by using collection policies


Save time by using collection policies to reuse configurations that collect logs. Set up filtering rules, parsing rules, and connectors once and use them in multiple collection policies. 

Creating a filter rule is an optional step. You get the option to create filtering rules when you are creating collection policies.

Here is an overview of the process to collect logs:

CollectionProcess.jpg

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*