Configuring the LX Appliance to Analyze Data

It is good practice to set up the LX appliance that replays archived data as you would a production appliance.

Specifically, to obtain the maximum benefit of replaying archived log data, ensure that you have all of the appropriate components and system settings configured in your Replay Appliance.

Consider configuring at least the following:

Alerts Configure alerts to send SNMP events or email notification of specific occurrences found in the data in the replay session.
Note: System Alerts (Message Volume and Ratio-Based) might produce skewed results because the data is being sent all at once rather than over the time period which it was originally sent. It is good practice to use message-based alerts instead.
Reports Configure reports to analyze the data in the replay session.
Search Filters Configure search filters to run reports and searches on specific log data.
Devices Ensure that you have all applicable devices configured.
Full Text Indexing Consider turning on full-text indexing on all data (parsed and unparsed; unparsed data is log data that is not associated with a supported log source).
PIX/ASA Messages Enable if the archived data contains PIX/ASA messages (if you enable PIX/ASA Messages and you do not have PIX/ASA messages in the replay session, it does not impact the appliance).
Message Routing Enable only if you need to forward log data to another device.
Data Retention Configure how long to retain the data from the replay session on the destination LX appliance (retention time is counted from the time the log data was generated by the original log source).

To speed up the setup process, use the Import/Export tool. For example, you can import components such as search filters and reports from any LX appliance. You must manually set system settings such as global retention settings and full-text indexing. For more information on importing and exporting components from one appliance to another, see Import/Export of Entities Between Appliances.