Searching the message log


Search is the default tab that is displayed when you click Messages and it displays a table of all received messages in reverse-chronological order (newer messages are displayed at the top of the table). You can use the Messages > Search tab to perform the following actions:

  • Filter messages
  • Search for a phrase in the filtered messages
  • View indexed keywords
  • Add new keywords
  • Define parse rules to add new keywords
  • Monitor the keyword process statistics
  • Analyze received messages
  • Create and send a new syslog message

To refresh the Messages Search tab and view newer messages, click Search.

The Messages > Search tab displays a table with the following information:

Column name

Description

Time

Date and time (with respect to the BMC Defender Server platform server time) of the event and time elapsed since the event occurred

Address

IP address and name of the device that generated the message

To view the Device Information tab, click the IP address link (accessed also by navigating to Messages > Catalogs > Devices > deviceAddress > Device info).

Facility

Syslog facility of the message

Message

Severity and content of the message

To view detailed information about a message, click the Details link at the end of the message. The Message Detail tab is displayed with the following information:

Field name

Description

From IP address

IP address and name of the device that generated the message

To view the Device Information tab, click the IP address link (accessed also by navigating to Messages > Catalogs > Devices > deviceAddress > Device info).

Message Time

Time at which the message was received

Click the time link to open the All Messages For Selected Time tab that displays all the messages received in the specified time. 

Message Facility

Facility of the message

To view all messages with a specific facility, click the facility link. 

Message Severity

Severity of the message

To view all messages with a specific severity, click the severity link.

Message Content

Text in the message

Word Count

Number of words and characters in the message

To know the exact position of a word in the message, click Word Positions.

Matched Threads

Displays correlation threads that matched the message

To view all messages with a specific thread, click the thread link.

Matched Users

Displays the users that match the message

Message Offset


Open New Ticket For This Message

Displays the AddNew button to create a ticket for the selected message

  1. To create a ticket for the selected message, click AddNew.
  2. On the Open New Ticket tab, modify the following options:
    • Assigned To User—Select a user to assign the ticket to. The default is Admin.
    • Ticket Severity—

      Select one of the following severities:

      • debug
      • info
      • notice
      • warning
      • error
      • critical
      • alert
      • emergency

      For more information about severity codes, see Severity-codes-and-their-meaning.

      The default is info.
    • Ticket Text—Enter the text to be displayed in the ticket.
    • Ticket Comment—Enter a comment to be displayed under the ticket text.

The new ticket is displayed on the Tickets Opened tab.

You can configure a message's text color and background color on the Messages > Config> Colors tab.

Where to go from here

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*