Netmon Docs · Product Guide

Logs & Eventsv7.0.20

Four streams, one surface: what your equipment logs, what Windows records, what the IDS flags, and who talked to whom — searchable together, on one time axis.

Logs and Events is the appliance’s unified log surface: syslog from your network equipment, Windows event logs collected by the agent, intrusion-detection (IDS) events, and the flow record itself — one page, one search, one time axis, every line attributed to its device.

severity ≥ warning FOUR STREAMS ONE SURFACE syslog event log IDS events netflow 03:00 03:12 03:24 03:36 now
Four log streams — syslog, Windows event logs, IDS events, and NetFlow — collected into one searchable, time-ordered surface.

The four streams

Working the page

The toolbar is the whole method: pick the stream, pick the time range, filter by device or tag, and search. Severity chips color each row, and the table pages through history rather than truncating it. The questions this page answers daily:

Log lines reference the device that produced them, so a row is always one step from that device’s dashboard — and the device dashboard’s Recent Events card is one step back here, pre-filtered.

Exclusion filters

Some noise is permanent: the chatty service nobody will ever fix, the benign event that arrives four hundred times a day. For those, the page supports exclusion filters — persistent rules, stored on the appliance, that keep matching entries from surfacing.

Right-click the offending entry and choose Exclude Event: the filter dialog opens pre-seeded from that row, and you choose which of its attributes must match (the source, the event identifier, a message fragment — per stream) and give the filter a label. From then on, matching entries stay below the surface. Your active filters live in the page’s filter pane, where each can be toggled off temporarily, edited, or deleted — so a filter is never a silent black hole; the pane is the inventory of everything you have chosen not to see.

Note

Exclusion filters shape the view, not the record: excluded entries are still collected, still counted against retention, and still visible to alert triggers. Suppressing an event from the page does not suppress the alert built on it — which is the safe default.

Logs as alert fuel

The three log streams can be alerted on directly: “more than N occurrences at or above this severity in M minutes”, “any event matching this text from these devices”, and similar conditions are exactly what the modern alert triggers evaluate (see Alerting; the flow stream is not an alert class — traffic conditions surface through the device-status alerts instead). When you find yourself re-running the same search each morning, that search wants to be an alert.

Note

Log volume is the largest variable in the appliance’s storage budget. The retention controls in Data Maintenance govern how far back this page can reach — a noisy device that logs every connection can consume in days what a quiet fleet produces in months, so tune what devices send as deliberately as what Netmon keeps.