In Log Search, users can create queries and visualizations to better understand how Armor bills against log usage. Users will want to review usage for both Agent and non-Agent log types.
Query for Armor Agent Log Types
To query Armor Agent log types:
- In AMP, go to the Log Search screen.
- Click on Discover.
- Use the Change Index Pattern dropdown to view all customer accounts under your Partner account.
- Click the View drop down, and change the Index Pattern to (Account ID)_partner.
- Below the Search bar, click the link for +Add Filter
- Field = tenant.id
- Operator = is
- Value = (Partner Customer Account ID)
- Below the Search bar, click the link for +Add Filter
- Filter #1
- Field = tags
- Operator = is one of
- Values = armor agent, oslogs
- Type *armor_agent* and hit enter
- Type *oslogs* and hit enter
- Hit Save
- Filter #2
- Field = tags
- Operator = is one of
- Values = windows, linux
- Type *windows* and hit enter
- Type *linux* and hit enter
- Hit Save
- Hit the Refresh button
- Filter #1
Visualization for Armor Log Types
To create a visualization for Armor Agent log types:
- Click on Visualize
- In the New Visualization pop up, select the Data Table visualization option.
- Choose a source.
- Below the Search bar, click the link for +Add Filter
- Filter #1
- Field = tags
- Operator = is one of
- Values = armor agent, oslogs
- Type *armor_agent* and hit enter
- Type *oslogs* and hit enter
- Hit Save
- Filter #2
- Field = tags
- Operator = is one of
- Values = windows, linux
- Type *windows* and hit enter
- Type *linux* and hit enter
- Hit Save
- Hit the Refresh button
- Filter #1
- In the Data tab, expand the Metric configuration
- In the Aggregation dropdown, select Sum
- In the Field dropdown, enter message_size
- Under Buckets, click Add
- Select Split rows
- In the Aggregation dropdown, select Terms
- In the Field dropdown, select external_id
- Add another Bucket by clicking Add
- Select Split rows
- In the Sub aggregation, select Terms
- In the Field dropdown, select winevent.log.source
- Select Split rows
- Hit Update