Logs & Eventsv7.0.20
Four streams, one surface: what your equipment logs, what Windows records, what the IDS flags, and who talked to whom — searchable together, on one time axis.
Logs and Events is the appliance’s unified log surface: syslog from your network equipment, Windows event logs collected by the agent, intrusion-detection (IDS) events, and the flow record itself — one page, one search, one time axis, every line attributed to its device.
The four streams
- Syslog. The appliance is a standard syslog server. Point any device’s logging at the Netmon address and its messages are collected, parsed for facility and severity, matched to the sending device, and stored. For most network equipment this is one configuration line.
- Windows event logs. Agent-monitored hosts ship selected event-log channels continuously. Which logs and which events are collected is controlled per device by its event-log trackers; new agent devices start with sensible defaults (all errors and criticals, plus successful and failed logons).
- IDS events. The appliance’s continuous traffic inspection raises intrusion-detection events — signature hits with source, destination, ports, protocol, and severity — from the same always-on stream that feeds the packet analyzer. Coverage is around the clock, not just while someone is watching.
- NetFlow. The flow record — the conversations from the appliance’s continuous inspection and from any flow export it receives — is browsable here as a stream like the others. It is the one stream hidden by default, purely because of its volume: a busy network produces orders of magnitude more flow rows than log lines. Toggle it on when a question needs it; the other three streams are shown out of the box. (Pointing a Cisco device’s flow export at the appliance is covered in the Cisco IOS & IOS-XE configuration guide.)
Working the page
The toolbar is the whole method: pick the stream, pick the time range, filter by device or tag, and search. Severity chips color each row, and the table pages through history rather than truncating it. The questions this page answers daily:
- What did this device say around 03:12? — filter to the device, set the window, read in context.
- Who else logged this string this week? — search the text across all devices, full width.
- What errors did the domain controllers throw since the patch window? — tag filter + severity + time range.
Log lines reference the device that produced them, so a row is always one step from that device’s dashboard — and the device dashboard’s Recent Events card is one step back here, pre-filtered.
Exclusion filters
Some noise is permanent: the chatty service nobody will ever fix, the benign event that arrives four hundred times a day. For those, the page supports exclusion filters — persistent rules, stored on the appliance, that keep matching entries from surfacing.
Right-click the offending entry and choose Exclude Event: the filter dialog opens pre-seeded from that row, and you choose which of its attributes must match (the source, the event identifier, a message fragment — per stream) and give the filter a label. From then on, matching entries stay below the surface. Your active filters live in the page’s filter pane, where each can be toggled off temporarily, edited, or deleted — so a filter is never a silent black hole; the pane is the inventory of everything you have chosen not to see.
Exclusion filters shape the view, not the record: excluded entries are still collected, still counted against retention, and still visible to alert triggers. Suppressing an event from the page does not suppress the alert built on it — which is the safe default.
Logs as alert fuel
The three log streams can be alerted on directly: “more than N occurrences at or above this severity in M minutes”, “any event matching this text from these devices”, and similar conditions are exactly what the modern alert triggers evaluate (see Alerting; the flow stream is not an alert class — traffic conditions surface through the device-status alerts instead). When you find yourself re-running the same search each morning, that search wants to be an alert.
Log volume is the largest variable in the appliance’s storage budget. The retention controls in Data Maintenance govern how far back this page can reach — a noisy device that logs every connection can consume in days what a quiet fleet produces in months, so tune what devices send as deliberately as what Netmon keeps.