Reload Archive Logs

Last updated on:

Overview

ManageEngine Log360 Cloud allows reloading log data from archives for analysis. Archived log data often plays a crucial role in forensic analysis by allowing administrators to review past events and identify discrepancies that may indicate security issues. They also serve as evidence in case of data breaches.This page explains how to reload archival logs.

Steps to reload archive logs

  1. Log in to your Log360 Cloud account.
  2. Navigate to the Settings tab.
  3. In the left pane, select Admin.
  4. Under Data Storage, click Reload Archive Logs.
    Reload Historical Logs
    Figure 1: Navigating to Reload Archive Logs
  5. In the Reload Archive Logs page, click Create Request Page.
    Reload Historical Logs
    Figure 2: Creating a new request page
  6. In the Create Reload Request page, fill in the following fields.
  7. Name: Enter a name for the reload request.
    Reload Historical Logs
    Figure 3: Entering a name
  8. Storage Tier: Choose the appropriate storage tier from the drop -down
    Reload Historical Logs
    Figure 4: Selecting a Storage Tier
  9. NOTE Reloading includes both archive logs and overwritten logs from search storage. Maximum of around 15% of the logs from search storage can be reloaded.
    • Default and Custom Storage Tier: By default, all log sources and types are selected.
      • To choose specific log sources, click the icon.
      • In the Select Log Source window, choose the required source and click Add.
        Reload Historical Logs
        Figure 5: Selecting log source(s)
      • You can select specific log type(s) from the the drop-down
        Reload Historical Logs
        Figure 6: Selecting log type(s)
    • Alert Storage Tier: By default, all alert profiles are selected.
      • To choose specific profiles, click the icon.
      • In the Select Alert Profile page, select the desired profiles and click Apply.
      Reload Historical Logs
      Figure 7: Selecting Alert Profile
    • Correlation Storage Tier: By default, all correlation rules are selected.
      • To choose specific rules, click the icon.
      • In the Select Rules page, pick the rules you need and click Apply.
      Reload Historical Logs
      Figure 8: Selecting rules
  10. Time Period: Specify the time range for which logs need to be reloaded and click Apply.
    NOTE By default, the time range picker is limited by the archival retention period or the overwrite duration of search storage logs.
    Reload Historical Logs
    Figure 9: Specifying a time period
  11. Retention Period: Set the number of days for which the reloaded logs should be retained.
    NOTE You can select a maximum storage retention period of 5 days only.
    Reload Historical Logs
    Figure 10: Setting a retention period
  12. Click the Advanced Criteria section to apply filters.
    NOTE Advanced criteria can only be configured for the default and custom storage tier.
    Reload Historical Logs
    Figure 11: Configuring advanced criteria
  13. Click the icon to add additional filter criteria. Use AND when all conditions must be true. Use OR when at least one condition should be true.
  14. To add multiple conditions, click + Add Group and define each group with its own criteria and logical operators.
  15. Click Create to submit the request.
  16. Once created, you will be redirected to the Reload Archive Logs page. From here, you can manage and monitor your requests.
    NOTE Only a maximum of 50 live indexes can be held at one time. If you would still like to create a new request, either delete an existing request or wait for its expiration.
    Reload Historical Logs
    Figure 12: Viewing reload requests
  17. You can click the icon-pause icon to stop indexing temporarily and click icon-play icon to resume indexing.
  18. Hover over a request and click View Reports to see reports for the specific storage tier
  19. NOTE For the Correlation Storage Tier, when archive logs are reloaded, the timeline view in reports will not be available.
    Reload Historical Logs
    Figure 13: Viewing reports
    NOTE Based on your notification settings, you will receive alerts about reloading historical logs via email and SMS.
  20. Click View Details to view all configured request details.
    Reload Historical Logs
    Figure 14: Viewing details of a request
  21. To delete a request. Click the icon next to a request you want to delete.
  22. In the confirmation pop-up, click Yes to delete the request.
    Reload Historical Logs
    Figure 15: Deleting a request