Configuring Data Storage; Data Storage Overview; Raw Data - Novell SENTINEL LOG MANAGER 1.0.0.5 - ADMINISTRATION GUIDE 03-31-2010 Administration Manual

Hide thumbs Also See for SENTINEL LOG MANAGER 1.0.0.5 - ADMINISTRATION GUIDE 03-31-2010:
Table of Contents

Advertisement

Configuring Data Storage

3
®
Novell
Sentinel
Log Manager stores compressed event data on the server file system and then
TM
archives it to a configured location for the long-term storage.
Section 3.1, "Data Storage Overview," on page 21
Section 3.2, "Configuring Data Archiving," on page 27
Section 3.3, "Configuring Data Retention Policies," on page 34
Section 3.4, "Configuring Disk Space Usage," on page 38
Section 3.5, "Verifying and Downloading Raw Data Files," on page 39
Section 3.6, "Viewing Online and Archive Data Capacity," on page 40
Section 3.7, "Using Sequential-Access Storage for Long Term Data Storage," on page 41

3.1 Data Storage Overview

Sentinel Log Manager receives two separate, but similar data streams from the collector managers:
the event data and the raw data. Both types of data on Sentinel Log Manager are moved from the
online, compressed, file-based storage to a user-configured, compressed archive storage location on
a regular basis.
Data files are deleted from the local and archive storage locations on a configured schedule. Raw
data retention is governed by a single raw data retention policy. Event data retention is governed by
a set of event data retention policies. All these policies are configured by the Sentinel Log Manager
administrator.
Section 3.1.1, "Raw Data," on page 21
Section 3.1.2, "Event Data," on page 25
Section 3.1.3, "Archiving," on page 26
Section 3.1.4, "Data Retention," on page 27

3.1.1 Raw Data

Raw data are the unprocessed events that are received by the connector and sent directly to the
Sentinel Log Manager message bus, and then written to the Sentinel Log Manager server. The
original event is not altered, but the following additional information are also sent to the message
bus with each event:
SHA-256 hash of the event
Chaining indicator (which is reset to 0 whenever the Sentinel Log Manager event source is
restarted)
All raw data are sent to the Sentinel Log Manager; there is no filtering on raw data.
3
Configuring Data Storage
21

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel log manager 1.0.0.5

Table of Contents