Objective
EventLog Analyzer provides email notifications when unprocessed log files accumulate and form cached records. This helps administrators detect potential issues in log ingestion or processing early, enabling proactive troubleshooting to avoid data loss or performance degradation.
When EventLog Analyzer is unable to process incoming logs quickly enough, those logs are temporarily written into unprocessed log files (<Installation Directory>\ManageEngine\EventLog Analyzer\ES\CachedRecord) for later processing. These files are processed sequentially once the system resources are available. You can configure a limit for the number of such files, and a notification will be sent when this threshold is exceeded.
In a new installation of EventLog Analyzer, the default threshold for unprocessed log files is set to 100. In older builds, the threshold is set based on the total size of the cached records created, typically 50GB.
Prerequisite
- Email server settings must be configured under Settings > System Settings > Notification Settings > Mail Settings.
Steps to follow
Step 1: Navigate to Settings > Admin Settings > Product Settings > Product Notifications.
Step 2: Enable the option Unprocessed Log Files.
Step 3: Click Save to apply the settings.
Tips
Unprocessed log files typically occur in the following scenarios:
1. When there is a delay in log processing due to insufficient resources (RAM or CPU)
2. When there's a sudden spike or fluctuation in the log flow
Always meet the hardware requirements with an additional buffer to handle such situations.
For example, say you are a medium-sized organization, and your environment generates a normal log flow: 1,500 Windows events per second (EPS) and 10,000 syslog messages (in EPS). Please meet the setup and hardware requirements for a high flow so that in the event of a sudden spike, the product can process the logs quicker.
3. When the disk space on the server where EventLog Analyzer is installed falls below 20GB
It is always recommended to install EventLog Analyzer on a dedicated partition (other than the C drive) and allocate the disk space based on the log flow. Refer to the system resources table and meet the disk space requirements accordingly.
Related articles and topics