Search raw log messages using nDepth search in SEM
If the nDepth log retention option is enabled, you can use nDepth to view and search your original, non-normalized log messages in the SEM console. For details, see About nDepth log retention.
To view and search original log messages using nDepth
Open the SEM console. See Log in to the SEM web console for steps.
Log in as an administrator or an auditor.
On the SEM menu bar, navigate to Explore > nDepth.
- On the far right of the search box, move the switch from Events to Log Messages.
This switch only appears if SEM is configured to store original log messages.
Construct an nDepth search as you would for normalized alerts:
Drag Refine Fields components into the search box.
Switch the search method from Drag & Drop Mode to Text Input Mode on the left of the search box, and then enter your search conditions in plain text.
See Search normalized data using nDepth search in SEM for help.