Created on 10-13-2016 06:19 AM Edited on 05-26-2022 07:38 AM By Anonymous
Description
Why are there different # of events shown in Dashboard versus the corresponding event search?
The difference is due to the way dashboards are populated versus historical searches.
1) Data in dashboards are from summarized data that AO keeps local to speed up generation and display.
2) We keep summarized data that are in 5 minutes buckets. These are then rolled up into 1 hour buckets.
3) For the a dashboard that shows the last 1 hour, it would display the summary of data from the last 12 5-minute buckets.
Example: If it is currently 1:57 PM, the buckets summarized would be from 12:55 to 1:55pm. Any event that has come in between 1:56:00 to 1:57:59 would NOT be included in the summary.
1) The events are pulled from the eventdb, not any local store of information.
2) Historical searches will include every event within the time frame set as the criteria for the search.
1) The events are pulled from the event cache, before they are written to the eventdb.
2) Historical searches will include every event within the time frame set as the criteria for the search.
1) if "Run Now", then data is pulled from summarized data, if there is as corresponding dashboard, otherwise from event cache.
2) otherwise, the events are pulled from the eventdb, like historical searches.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.