Your connected event sources and environment systems produce data in the form of raw logs. Log Search takes every log of raw, collected data and automatically sorts them into Log Sets for you. Once you apply a search to a log, a log set, or multiple log sets, you can do multiple things including:
- Search logs for specific terms with a Search Language.
- Build your own query to group by a field or calculate specific items.
- View logs in Visual Search.
- Create tags and Alerts on your log data.
- Export data to share with stakeholders.
Log View Options
When looking at the log entries, you can make reading logs easier by viewing log data in JSON format. Click Entries or Table to change views.
All normalized log entries can be queried either by searching for a string or by searching for a keyword=value pair.
While in Table View, you can quickly create a query based on a selected key, filter by column, or click on source_user and enter a username to search by, and run calculations.
Searching Your Data
InsightIDR allows users different ways of searching their data, including Regex, String, KeyValue, or Keyword search. See Use a Search Language for more information.
Or, you can build queries off of the provided Example Queries.
You can also build a query in Table View:
- While in Table view, select the keyword that you want to query on.
- Select an operator and enter a key value.
- Click Search.
- You can now search within your query.
You can export parseable logs to share with stakeholders at your convenience. When viewing the log entries table, select Export to CSV.
You will see a confirmation message appear. Your CSV file will be available in the Report Archive under the "Entries Export" tab.