Collector Metrics

 

Column

Description

Name

Name of the Log Source

Forwarder

Define the current Forwarding connection with the Log Source

Type

Type of the Log Source: Real Time File, Remote File, Syslog, Command output, Hawk Rulebase, Hawk Metrics

Status

Status of the Log Source:

Active: the connection is OK

Err: the connection encountered an error

Idle: the connection never received a message from the source or nothing at all for 24 hours

Inactive: a Log Source is inactive

Collection

Connection parameters

Syslog: protocol/bound port
RT File: File name (no path)
Remote: File path
Cmd: Command
Hawk Rulebase (Rulebase name)
Hawk Metrics

Collected

Total number of collected message for a given period of time

Filtered

Total number of filtered message for a given period of time

To Buffer

Total number of forwarded message for a given period of time

Current (mps)

Current Log Rate

Since UpTime (msg)

Total number of collected messages since Universal Collector microagent is started