Hector Aguilar Director, Connector Development May 2006 What is the “Logfu”? Hector Aguilar Director, Connector Development May 2006 © 2006 ArcSight Confidential
What is the “Logfu”? My Kung-Fu is better than your Kung-Fu! My Code-Fu is better than your Code-Fu! . I can analyze logs better than you can. My Logfu is better than your Logfu! © 2006 ArcSight Confidential
What is the Agent “Logfu”? Logfu is an application that reads and parses ArcSight logs to generate a visual representation of the information contained in them Logfu can be used for Manager and Connectors. This presentation will focus on the Connector Logfu The Connector Logfu generates an interactive visual representation of the information contained in the logs This presentation will show how to navigate using Logfu to analyze connector event flow issues © 2006 ArcSight Confidential
© 2006 ArcSight Confidential FAQ About Logfu Who would use Logfu? Logfu can be used by people managing connectors on a daily basis, to analyze connector behavior Why would people use Logfu? When event flow problems happen related to the connector or to the device, it is very useful to have a visual representation of what happened overtime What do you need to run Logfu? You need any agent build Logfu is included with all connector builds and you can analyze logs from older (or newer) connectors © 2006 ArcSight Confidential
© 2006 ArcSight Confidential Starting Logfu Logfu will read the log files contained in the directory where it was run, so to execute it change to the /logs folder and run: C:\Program Files\ArcSightSmartAgents\current\logs>..\bin\arcsight agent logfu -a Logfu will start reading all the agent.log.* files and produce “data” files (data.agent.log.*) with optimized data and indexes that will be used to feed the interactive display © 2006 ArcSight Confidential
© 2006 ArcSight Confidential More about Logfu The “data” files can be used as a “cache” so that the analysis of the log files is done only once for multiple interactive sessions © 2006 ArcSight Confidential
© 2006 ArcSight Confidential More on Agent Logfu… When Logfu is run a second time, it will first check the blah, blah, blah, blah… Ok! Enough with the slides already! We want to see a demo!!!! © 2006 ArcSight Confidential
© 2006 ArcSight Confidential Ok, just one more slide… Things that Logfu can help you analyze Event-flow (Eps/Cache/Manager Throughput) Device database performance Memory consumption Name resolution Device activity (Event count) Errors/Exceptions Any counter logged Ok, so what are we going to see now? © 2006 ArcSight Confidential
© 2006 ArcSight Confidential Demo © 2006 ArcSight Confidential
© 2006 ArcSight Confidential Summary Logfu is a tool to visualize connector logs Can be used for troubleshooting event flow problems or simply analyze connector behavior A couple of suggestions Use Logfu to analyze the logs of your current agents Enter the Logfu contest! © 2006 ArcSight Confidential
© 2006 ArcSight Confidential Questions and Answers Download Slides https://support.arcsight.com More ArcSight Events http://www.arcsight.com Join the User Forum https://forum.arcsight.com © 2006 ArcSight Confidential
Maybe some Q&A? © 2006 ArcSight Confidential