Event Log and Alerts

As events occur, messages are categorized by urgency (informational, warning, or error) and recorded in the Event Log. The Event Log can be searched and the type of messages displayed can be selected.

Configuration changes also produce log messages including with the user who performed them as an audit trail.

When an event occurs that requires immediate attention or a critical System Health monitor has been reached, an alert is posted.  

In this topic:

Opening the log and viewing messages

Searching the log and using filters

Viewing and acknowledging alerts

Removing log contents

Opening the Event Log and Viewing Messages

The SANsymphony Event Log consists of a search area and filter, chronological list of messages, and message text area.

When the Event Log is opened, all messages are displayed according to the timestamp with recent messages at the bottom of the list.

The timestamp is the exact time and date of the event. Timestamps are provided in the original time zone where the occurrence happened. The format is YEAR-MO-DAY and 24-hr time.

To open the Event Log and view messages:

  • For a global view of all events:
    1. In the Ribbon>Home tab, click the Event Log button.
    2. The Event Actions tab opens in the Ribbon. Use the tab to select the server and message level to limit the type of messages displayed.
    3. Click a message in the list to view the details at the bottom of the page. (See following table.)
  • For a view of all events for a specific object:
    1. In the DataCore Servers Panel or Hosts Panel, double-click on the object to open the details page.
    2. Click the Events tab.
    3. In the Ribbon, select the server and message level to limit the type of messages displayed.
    4. Click a message in the list to view the details at the bottom of the page.
Message Text Area in the Event Log
Level

Message type. Possible levels include: Info, Warning, Error, and Trace (Information used by DataCore Technical Support for diagnostic purposes).

The message level displayed in the log can be changed in the Ribbon when the log is open.

Source type

The type of message.

Most types are self-explanatory with these exceptions:

  • General - message types that are general in nature and do not fall in any other category listed.
  • Monitors - message types based on the internal system monitors used in the System Health tool.
  • Security - message types regarding users, user roles, and authentication that are security related.
  • Virtual disk sources - message types related to virtual disks created from pass-through disks.

Source types displayed in the log can be filtered in the Event Actions tab in the Ribbon when the log is open.

Source The source of the message. This could be a particular SAN component object or can be service related.

Message text

Displays the entire message which could be longer than the description in the message list.

 

During the collection of support bundle files, logging in the Event log will pause and messages in the Event Log will disappear until the collection is completed, then logging will resume. During support bundle collection, a message in red will be displayed in the Event Log that logging is paused.

Auto Scrolling

Log messages are displayed from oldest (top of the list) to most recent (bottom of the list). When auto scrolling is enabled and the Event Log is opened, a view of the most recent messages at the bottom of the list is provided. When auto scrolling is disabled and the Event Log is opened, the log displays the least recent log messages starting at the top of the log.

To enable or disable auto scrolling:

  • Open the Event Log and in the Ribbon, click Auto Scroll Enabled or Auto Scroll Disabled.

Auto-scrolling is only available in the global Event log.

Searching the Event Log

More specific messages can be located by performing text searches or using the filter.

To perform a text search:

  1. At the top of the Event Log tab, enter the text phrase in the Search box.

    The text string entered will be searched for as entered, including quotes and spaces. The wildcard asterisk character (*) is supported as a character substitute (zero or more characters). The text string is not case sensitive.

  2. The text search will begin from the selected message (highlighted in blue). Click Next or Previous to find the occurrences in the message list.

Filtering

To use filtering features to narrow the scope of displayed messages:

Filtering is only available in the global Event log.

  1. In the Ribbon>Home tab, click Event Log to open the log and then and click Ribbon>Event Actions tab.

  2. In the Level area:
    1. In the Level box, click the arrow to open the drop-down box.
    2. In the list, clear or select the check boxes for the message types to display.
    3. Click OK.
  3. In the Source area:
    1. In the Source type box:
      1. Click the arrow to open the drop-down box.
      2. In the list, clear or select the check boxes for the component types to display.
      3. Click OK.
    2. To search for specific object, in the Source box:
      1. Enter the specific text to search for.
      2. Click Apply.

Settings are not saved when the Event Log is closed.

Viewing and Acknowledging Alerts

An alert is an urgent notification of a high priority event. Alerts are generated by SANsymphony software when an event occurs that requires immediate attention. Alerts can also be user-generated as an action from a task.

When a high priority event is posted in the event log, the alert flag in the right corner of the status bar changes color from grey to red and a balloon message will appear briefly. The alert should be viewed and acted upon immediately.

To view and acknowledge alerts:

  1. In the status bar, click the red flag in the status bar to open the Active Alerts dialog box. The dialog box can also be opened from the Ribbon>Home tab.
  2. Select each message in the list and read the message detail at the bottom of the page. Take appropriate actions based on the alerts.
  3. When all alert messages are no longer needed, click Acknowledge All to remove the alerts and reset the alert flag in the status bar. The events will remain documented in the Event Log.

Removing Log Contents

When the Event Log becomes too long, all currently displayed messages can be removed from the log, including alerts. When the log is "cleaned up" all messages are saved in a log file (.dcsl) in the folder where the program files were installed. The file will begin with "Dcsx_" and have the timestamp appended. For example: Dcsx_2010_10_12_09_24_40.dcsl would be the name of a file when the log was cleaned on October 12, 2010 at 9:24.40 am.

  • The event log is automatically cleaned up when approximately 1,000,000 messages or 2 GB is consumed by the log. At that time, all unacknowledged alerts will be removed and the alert flag in the status bar will be reset.
  • Before cleaning up the log, ensure all log messages and alerts are unnecessary.
  • Ensure that there is always sufficient free space for the Event Log; otherwise, logging will stop. If logging is stopped due to insufficient space on a server (even if a cleanup is performed), in order to create a new log file you must stop and restart the DataCore Server.

To delete log messages:

  1. Open the Event Log and in the Ribbon>Event Actions tab, click Cleanup Log Database.
  2. Click Yes on the confirmation message to continue.