In This Article
- Locating Message Volume in the Alert Logic Console
- Making Adjustments
- Additional Information
To find which log sources and messages are contributing most to your log volume, several resources are available to you. This article describes best practices for managing your log volume for Alert Logic® Log Manager™.
Multiple reports and modules are available in the Alert Logic console to track the message counts per log source and the message type that is responsible for the majority of the volume. There are multiple ways to obtain useful information about message volumes:
- Run the Saved View reports from the Alert Logic console to see the message counts per log source and the message type that is responsible for the majority of the volume. There are three related Saved View reports: one showing Messages by Source, one showing Messages by Type, and one showing Messages by Type and Source.
For procedures on viewing and scheduling these reports, refer to the View Log Manager Messages by Source and Type article.
- In the Alert Logic console, on the Log Management dashboard from the Overview main menu tab, review the following modules:
- Received Logs
- Top 10 Message Types
- Review the Top 10 Sources Collecting module, which can be found in the Alert Logic console under Reports > Usage > Log Management.
Once you've determined the source of the majority of your volume, review your collection practices and determine if adjustments can be made to reduce volume without undue compromise with respect to your security and compliance.
For more information and procedures regarding Log Manager policies, refer to our Log Manager Policies documentation.
The following related documentation may be useful when reviewing and updating Log Manager data and settings: