The graphical view of ESM is the default view in Event Source Management. In the graphical view, you can view the status of a Collector and access the configuration settings of Collectors and Collector related objects as a graph of connected nodes.
Figure 11 Graphical View
By default, the Health Monitor Display frame displays in the graphical view. The data can be displayed in seven different layouts. The default layout in graph is the “Hierarchic Left to Right” layout. You can change between these layouts by selecting the layout format from the drop-down list in the toolbar.
Figure 12 Layout Selection
HINT:Click in the graphical ESM view and use “+” or “-” to zoom in or zoom out. Alternatively, use the mouse wheel to zoom in and zoom out.
In the graphical view, the lines connecting the components are color-coded to indicate data flow.
Green Line: Indicates that data is flowing between the components.
Grey Line: Indicates that the connection is not live and there is no data flow.
Blue dashed Line: Indicates the logical relation of event source servers to their associated Collector Managers and event sources.
The following terminology is used for nodes:
Parent Node: A node from which child nodes originate
Immediate Children: The sub-nodes that are logically and functionally linked to a parent node.
Collapsed/Expanded nodes: To improve the manageability and performance of the graphical display, Sentinel automatically contracts any node with 20 or more immediate children. This is especially useful for Connectors such as Syslog or Novell Audit that have the ability to automatically configure a large number of event sources.
HINT:Collapsed nodes are identified by a “-” sign on the node and expanded nodes are identified by a “+” sign.
Double-click a node to expand or collapse it.
In a collapsed state, a node displays the number of immediate children next to the node; for example, WMI Connector (3) [Collector name (Number of immediate children)]. The Children panel of a contracted node shows the immediate children of that node, each of which can be managed in the same way as nodes in the tabular ESM view.
NOTE:An event source server node does not have a “+” or “-” after its name even if it contains children.
Double-clicking a parent node changes the state from collapsed to expanded and vice versa. Double-clicking a node with no children displays the status details for that node. If an additional node is added to an expanded parent with over 20 children, the node is automatically collapsed. If an additional node is added to a manually expanded parent with over 20 children the node not automatically collapsed.
The parent node can take several minutes to expand if the parent node has a large enough number of child nodes to potentially cause the UI to become unresponsive; an alert message displays on the user interface to warn you about the delay in response. Click
to continue.Figure 13 Expand Selected Node Prompt
If you choose not to show this message again, the preferences are saved on that machine and any user logging into Sentinel from that machine does not get an alert again.
For trademark and copyright information, see Legal Notices.