Avatar

Graham Watts

  • Total activity 87
  • Last activity
  • Member since
  • Following 0 users
  • Followed by 1 user
  • Votes 0
  • Subscriptions 58

Activity overview

Latest activity by Graham Watts
  • Avatar

    Graham Watts commented,

    Hey Ravi,Seems like there are 2 options here: Collect the data in Sumo and query it there- Where is the data coming from? If its already in S3 or CloudWatch log groups you can use native Sumo sour...

  • Avatar

    Graham Watts commented,

    Official comment

    Hello Team Romania,We are currently building a Content API that will allow you to create dashboards automatically via API calls.If you don't mind, please vote and comment at the link below so that ...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Felipe,You'll need to use the timeslice operator to create a trend over time, you might try something like the below query to take the average of the effectiveness value in 5 minute increments ...

  • Avatar

    Graham Watts commented,

    Hey Erik,Thanks for the screenshots - you need the "Manage Collectors" permission to see the setup wizard, so it won't show up on the home page if you don't have that capability. Can you ...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Erik,In the new UI, you can get to the Setup Wizard in a few different ways: Manage Data > Collection Home Tab

  • Avatar

    Graham Watts commented,

    Hey Dungar,Can you provide a query that has the dest_ip parsed out?This might be what you're looking for, which I used our Threat Intel App queries to create:_sourceCategory=Apache/Access| parse re...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Dungar,I recommend installing our Threat Intel Quick Analysis App and pointing it at your apache data so you can use all of the pre-built dashboards and searches without having to manually crea...

  • Avatar

    Graham Watts commented,

    Hi Terrence,Are you looking for audit content about you Sumo Logic account? If so, check out the Sumo Logic Audit App.Or are you looking to audit different data?

  • Avatar

    Graham Watts commented,

    Hey David,Agreed, your query seems to be exactly what you need. Let me know if you have any other questions here!

  • Avatar

    Graham Watts commented,

    Hi David, Nice work on that query, below I have posted another query that should get you the same result. You can then schedule the alert as shown in the screenshot:_sourceName="CMS ping"...