Managing Collector feeds
The
pulls data from components.You can manage the connections between Analyzer and Collectors on the Administration > Data flow settings > Analyzer & Collectors management page of the
by using the following options:- Monitor the flow of traffic data into the Analyzer on the Status tab:
The Status tab
- Configure the Maximum Wait Time on the Analyzer settings tab.
A configurable delay period called Maximum Wait Time defines out of sync. For example, if you set the Maximum Wait Time to 15 minutes, a Collector feed that is more than 15 minutes behind other Collectors is considered out of sync. Additionally, stops pulling data from all s for a maximum of 15 minutes before dropping the delinquent feed and starting to pull data again through other feeds.
The Maximum Wait Time is also used to determine how much historical data is pulled from s after a period of unavailability has ended. components can retain up to 2 hours of historical data.
- Manage the list of associated Collector feeds on the Collector feeds settings tab.
Collector feeds settings tab
To add a Collector feed on the Analyzer
- On the , open the Administration > Data flow settings > Analyzer & Collectors management page.
- Switch to the Collectors feeds settings tab.
- On the Action menu, click Add.
- In the Name and Description text boxes, type a meaningful name and description to identify the
The name and description identify the component throughout the system. that you want to feed data from. - In the IP/DNS name box, type the name or IP address (IPv4 only) of the .
- In the Port box, type the port number used to access the component.
- Fill in the Username on Collector and Password on Collector boxes with valid credentials to access the component.
- To accept the Collector's default certificate, select the Allow self-signed certificate check box.
- To permit this to handle alerts generated by this , select the Accept Alerts from Collector check box.
- To set the priority of this , in the Priority section, click High or Low. The does not reject data (via sampling) from high-priority feeds.
- Do one of the following:
- To feed all traffic that this component collects to the , select Capture all traffic from the Collector.
- To feed only a specific subset of traffic that this component collects to the
To compose an expression using the Expression Builder, click Build a filter expression. , add a filter expression to identify the traffic that you want to capture.
- Click Save.
Result
The new
feed appears in the list of Collector feeds. An icon in the Connection column shows the status of the connection to the :– Connected
– Not connected, trying to reconnect
– Unknown status (for feeds that are turned off)
To turn the feed on immediately, click ON in the row for the Real User Collector.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*