Log shown in Raw Data Tap, but missing from Active View
I have a HPUX and Cisco device sending syslog to Sentinel Log Manager.
The Log Manager is sending the log to Sentinel RD via Sentinel Link.
The issue is:
On the Sentinel RD, I use the "Open Raw Data Tap" on Novell Sentinel Link collector, all the logs that are sent from Sentinel Log Manager are received on Sentinel RD. That's fine.
But, When I use the "Open Active View" on Novell Sentinel Link collector, certain events are not shown in the active view, some events are shown.(I am using Public ALL filter(1=1) active view).
I verify this using Historical Queries, the events are not there also.
Any idea what could be wrong?
|