The following article describes how to export large sums of logs, i.e. log quantities greater than the first page of results, from the Alert Logic® console into .csv or .pdf files.
Solution
Note: Long search periods will need to be broken into individual sections such as quarters or months to keep the results below 10,000 lines for export.
- Within the Alert Logic console, navigate to the Log Search page.
Alert Logic Essentials, Professional, or Enterprise customers can find this at the main menu () > Investigate > Search > Log Search.
Alert Logic Cloud Defender or Log Manager customers can find it at Search > Log Search BETA.
- Create your desired log query either by typing logical operators into the search bars or utilizing Search Assistant. Set your desired time frame by clicking on the down arrow next to "last hour." For information on using the Log search bar, see the Search: Log Messages documentation.
- Run the search by clicking Search, and then click the down arrow to the right of Search > Save and Schedule Search.
- A side bar will appear, within which you must name your search and create a schedule for it. Click Save to confirm that your search has been saved.
- Access your newly saved search by clicking on the Saved Searches button at the top right of the page. You can then search for your newly created Saved Search.
- You will see the Name, Description, and Group that the Saved Search resides in, along with the Scheduled Search Result. Click on the schedule to see all previous runs of this search to either view or export the results.
All of your newly saved search results will be exported to a downloadable CSV file.
Comments
2 comments
No longer valid --> Note: OmniBox log search is only available for customers with Alert Logic Cloud Defender or Log Manager entitlements.
PLEASE REMOVE OMNI BOX AND THE WHOLE STATEMENT
Anything referring to the Omnibox can be removed. There is a method that can be done in the Export Mode that can be added to this document.
Please sign in to leave a comment.