Detect related alerts in log data by adding log correlators. The base system includes several log correlators and you can define custom log
correlators.
Before you begin
Role required: evt_mgmt_operator or evt_mgmt_admin
About this task
For information about the types and functions of log correlators, see Identifying relationships in log data by using log correlators.
Procedure
-
Use one of the following methods to add a log correlator.
| Option | Procedure |
|---|
| Add a log correlator for a specific log source |
- Navigate to . The list of existing log correlators opens.
- Click the name of a log correlator. The names appear in the Correlation indicator column.
- Click New.
|
| Add a log correlator that applies either to all log sources or to only those log sources that become active after you define this log correlator |
- Navigate to .
- Click the name of the log source.
The Log correlators related list displays the list of existing log correlators that analyze log data from the selected log source.
- On the Log correlators tab, click New.
|
-
Fill in the Log correlator form.
-
Select Active and then click
Submit.