Viewing logs

Article:HOWTO55385  |  Created: 2011-06-29  |  Updated: 2011-12-16  |  Article URL http://www.symantec.com/docs/HOWTO55385
Article Type
How To


Subject


Viewing logs

You can generate a list of events to view from your logs that are based on a collection of filter settings that you select. Each log type and content type have a default filter configuration that you can use as-is or modify. You can also create and save new filter configurations. These new filters can be based on the default filter or on an existing filter that you created previously. If you save the filter configuration, you can generate the same log view at a later date without having to configure the settings each time. You can delete your customized filter configurations if you no longer need them.

Note:

If database errors occur when you view the logs that include a large amount of data, you might want to change the database timeout parameters.

If you get CGI or terminated process errors, you might want to change other timeout parameters.

See Changing timeout parameters for reviewing reports and logs.

Because logs contain some information that is collected at intervals, you can refresh your log views. To configure the log refresh rate, display the log and select from the Auto-Refresh list box at the top right on that log's view.

Note:

If you view log data by using specific dates, the data stays the same when you click Auto-Refresh.

Reports and logs always display in the language that the management server was installed with. To display these when you use a remote Symantec Endpoint Protection Manager console or browser, you must have the appropriate font installed on the computer that you use.

See About logs.

See Saving and deleting custom logs by using filters.

To view a log

  1. In the main window, click Monitors.

  2. On the Logs tab, from the Log type list box, select the type of log that you want to view.

  3. For some types of logs, a Log content list box appears. If it appears, select the log content that you want to view.

  4. In the Use a saved filter list box, select a saved filter or leave the value Default.

  5. Select a time from the Time range list box or leave the default value. If you select Set specific dates, then set the date or dates and time from which you want to display entries.

  6. Click Advanced Settings to limit the number of entries you display.

    You can also set any other available Advanced Settings for the type of log that you selected.

    Note:

    The filter option fields that accept wildcard characters and search for matches are not case-sensitive. The ASCII asterisk character is the only asterisk character that can be used as a wildcard character.

  7. After you have the view configuration that you want, click View Log.

    The log view appears in the same window.


Legacy ID



v7522439_v59371754


Article URL http://www.symantec.com/docs/HOWTO55385


Terms of use for this information are found in Legal Notices