Security Compliance
SEM - Create a Widget for Monitoring Log Retention
This guide will show you how to build a widget in the new HTML5 console that monitors important retention KPIs
First published date
Last published date
Overview
"How many days worth of log data do I have?"
"How long will my free space last before old data will be overwritten?"
"How much space am I currently using?"
"How much more space do I need to expand the environment or hold a certain timeframe of log data?"
"How many events I am receiving"
These can be answered using the data you can collect in the Widget explained below.
You can also use this guide to see how to get a more detailed report of this kind of information.
Use the SEM Database Maintenance Report to See Retention and Volume of Traffic
And this article can be used to expand the size of the SEM as needed.
Resize a SEM virtual appliance
Product section
Resolution
Adding Widget(s) to SEM HTML5 Dashboard:
- To begin, you'll need to be on the "Dashboard" tab in the HTML5 SEM Web Console.
- To edit and add widgets to the dashboard, click "Edit Dashboard" button on the top right corner. Followed by the "Add widgets" button.
- Select the "New KPI Widget" and click the "Customize" button at the bottom right corner.
- Edit the "Title and Description" and "Refresh" rates for the widget. (See below)
- Click "Add new value" for each indicator you want to include. I'll go over the ones relevant to retention and log partition size here.
- Oldest stored event: It is an important one, as it indicates how many days worth of log data is in your database. If your SEM is over 90% full by default, and this figure isn't high enough, you'll want to consider expanding your disk size. (This indicator is not available in SEM 2019.4)
- Logs/Data used storage is for showing you the amount of data used, likely in Gigabytes. This, with the indicator above, can help you calculate how much disk space is needed for a certain number of days of log storage.
- Logs/Data used storage percentage. This one will show you how close you are to being full of log data. By default, the SEM is configured to get rid of the oldest data once this number gets to 90%.