Sources of events are displayed in the table under Source status → List of event sources. One page can display up to 250 sources. You can sort the table by clicking the column heading of the relevant parameter and selecting Ascending or Descending.
You can use the Search field to search for event sources. The search is performed using regular expressions (RE2). You can also filter the table by the Status or Monitoring policy columns by clicking the heading of the relevant column and selecting the values that you want to display.
If necessary, you can configure the interval for updating data in the table. Available update periods: 1 minute, 5 minutes, 15 minutes, 30 minutes, 1 hour. The default value is No refresh. You may need to configure the update period to track changes made to the list of sources.
Viewing information about event sources
In the Source status → List of event sources section, information about event sources is displayed in the following columns:
If the status is red, an event of the Monitoring type generated. The monitoring event is generated in the tenant that owns the event source and is sent to the storage of the Main tenant (the storage must already be deployed in the Main tenant). If you have access to the tenant of the event source and do not have access to the Main tenant, you can still search for monitoring events in the storage of the Main tenant; the monitoring events of the tenants available to you will be displayed for you. You can also configure notifications to be sent to an arbitrary email address.
The table can be filtered by status.
You can rename an event source in the table of event sources by hovering over its name and clicking the pencil icon. The name can contain no more than 128 Unicode characters.
If you want to filter the list of event sources by applied monitoring policies, click the name of this column and select one or more monitoring policies. If necessary, you can find policies in the list using the Search field.
You can view information about all monitoring policies assigned to an event source by clicking the row of the source. This opens a window that displays the settings of monitoring policies, as well as the status of the source according to each policy. If several monitoring policies are assigned to the source, the red status in the table of sources in this window lets you identify the policy that was triggered. You can also see which policies are enabled and which are disabled, and when the disabled policies will be enabled again.
Managing event sources
You can select one or more event sources by selecting the check boxes in the first column of the table. You can select multiple event sources at once for performing group operations by selecting the check box in the heading of the first column and selecting Select all or Select all in page. The Select all in page option applies only to event sources displayed in the list: if only 500 out of 1500 sources are displayed in the list, then group actions to download, enable or disable policies, or delete event sources are applied only to the selected 500 sources. If you want to perform an action on all sources in the table, select Select all.
If you select sources of events, the following buttons become available:
This button becomes available after you change the monitoring policies assigned to event sources.
If you want to delete all event sources, but some time has passed since the table was last refreshed, sources added during this time may not be displayed in the table, but they will be deleted regardless.
If you delete more than 100,000 event sources to which a filter or search was applied, only the first 100,000 event sources will be deleted. You can select all filtered event sources again and delete them, and then repeat this until you have deleted all event sources that you intended to delete. You can delete over 100,000 event sources if no filters or searches are applied to them by selecting sources using the Select all button.
The Stream
field is downloaded only if a monitoring policy has been assigned to the event source; in that case, the unit of measurement taken from the policy is specified in the downloaded file. If no policy is assigned an empty Stream
field is the expected behavior.
.
Downloading event source information to a CSV file
You can download information about one or more event sources and the monitoring policies applied to them to a CSV file in UTF-8 encoding. If multiple monitoring policies are applied to a source, in the file for that source, each monitoring policy and its parameters starts on a new line. For each monitoring policy applied to a source, the following parameters are exported to the file: Status, Name, Monitoring policy, Lower limit, Upper limit, Stream, Tenant.
To download event source information to a CSV file:
In the lower left part of the table, you can find the number of selected sources and the total number of sources in the table. You can select up to 150,000 event sources.
You can select several event sources by clicking the check box in the heading of the first column selecting one of the following options:
Depending on the size of your browser window, the CSV button may be found in the additional menu that you can open by clicking on the icon with the three dots .
A new event source export task is created in the task manager.
When the file is ready, the Status column of the task displays the Completed status.
The CSV file with event source information is downloaded in accordance with your browser settings. The default file name is event-source-list.csv.
Viewing the dynamics of incoming events
You can examine the dynamics of events received from a source over the last seven days, taking into account the applied monitoring policies, in one of the following ways:
You can view the graph for a single event source in the KUMA web console in the Source status → List of event sources section by clicking the arrow icon in the row of the relevant event source. The graph of incoming events is displayed under the row of the source.
The data in the graph is displayed as follows:
In the upper left corner above the graph, the number of days is displayed, and in the upper right corner, the data display period is displayed. You can click the Events for <number> days button to go to the Events section and view the list of events for the selected source.
If you want to view the number of events at a specific time, hover over a point on the graph. A tooltip is displayed with the average, maximum, and minimum event count at a specific date and time.
You can also plot a chart of incoming events based on graphs for several event sources, for example, if you need to compare the activity of event sources of the same type that should behave in a similar way, but in fact behave in different ways.
To plot a chart based on graphs for multiple event sources:
You can plot a chart for up to 5 event sources at the same time.
Depending on the size of your browser window, the Chart button may be found in the additional menu that you can open by clicking on the icon with the three dots .
The displayed Chart pane contains a chart of incoming events for all selected sources as well as a table that displays the current number of events, the maximum number of events, and the average number of events for each source, calculated based on the data from the chart. You can compare how the data for the selected sources relates to each other over time.
The data in the chart is displayed as follows:
In the upper right corner above the chart, the data display period is displayed.
You can hover over the chart to view the average number of events for each source at a specific time.