Documentation forSecurity Event Manager

Analyze historical data in SEM

The historical data search engine can locate any event data that passes through a particular SEM Manager instance. You can use the historical data search to conduct custom searches, investigate your search results and event data, and then act on your findings.

You can still access historical data in the Flash console under Explore > nDepth, but the latest updates are now available in the HTML5 SEM Events Console.

Learn how to build a search query here.

Use historical search to do the following:

  • Search normalized event data.
  • View, explore, and search significant event activity. Historical search summarizes event activity in a selectable table or list view that you can use to easily select and investigate areas of interest.
  • Use the custom time picker to set a specific date and time range.
  • Conduct custom searches. You can also create complex searches with the intuitive search builder.
  • Export your search results to a spreadsheet file in CSV format.

To view historical events:

  1. In the SEM HTML5 console, click the Events tab, and then click Analyze historical data.

  2. Results appear in the Events - History table based on your selected filter. The chart provides a graphical representation of the number of events throughout the query time span.

    Records appear in a table or list view. To change the view, select an option from the More drop-down list.

    If no results appear, place your mouse pointer in the search builder box, and then press Enter.

  3. Refine your search results with the custom time picker.

    You can select a quick pick, or set a specific date and time range.

  4. Refine you search even further by dragging your mouse pointer over a section of the histogram.

  5. Select a single event in the table to find additional information in the Event Details pane. Use the search box to identify and highlight specifig data.

    Learn how to create search queries here, and export your results here.