How to load older logs or archives in EventLog Analyzer

How to load older logs or archives in EventLog Analyzer

Objective  

EventLog Analyzer stores the logs collected as live data in Elasticsearch and simultaneously as archives for long term usage. This document guide users on accessing older log data by loading archive files in EventLog Analyzer for analysis and reporting.

Prerequisite  

  • Admin access to the EventLog Analyzer web console.
  • Ensure sufficient disk space is available to load the required archive files. Loading archives temporarily expands data in Elasticsearch and may require additional storage.

Steps to follow

  1. In EventLog Analyzer, go to Settings → Admin Settings → Data Storage → Archive.
  2. This page displays a list of all available archive files.
  3. Under Select Devices, choose the device for which you want to load older logs.
  4. Use the Click to choose date range option at the top-right corner to select the period for which you need older logs.


  5. Once the device and date range are selected, the archive list will be filtered accordingly.
  6. You can choose to load all archive files or load only a specific log format. For example, if you want to load only MSSQL logs for the selected Widnows device, simply select the respective checkbox and click Load Archive.


  7. It is recommended to load a smaller set of data at a time. Loading very large archives may slow down the system. Before proceeding, review the displayed file size and approximate loading time.
  8. The status of the archive file will be updated as Loaded once the loading process is completed.

Tips

  • Loading large archive files may take additional time depending on disk performance and available system resources.
  • Set the archive retention period based on your internal compliance or storage policy.
  • Configure the loaded retention period to control how long loaded archive data remains searchable in Elasticsearch.
  • Only the required log types should be loaded to improve performance and reduce system overhead.
  • Configure separate archive retention policy based on the requirement. 
 

                  New to ADSelfService Plus?

                    • Related Articles

                    • Troubleshooting: Disk space issues in EventLog Analyzer

                      Issue description EventLog Analyzer server might run out of storage due to misconfiguration and other known factors. This article offers troubleshooting steps to resolve when your disk or drive where the application is installed is full and help you ...
                    • How does EventLog Analyzer store the collected data

                      Objective This document provides details on how EventLog Analyzer stores the collected event logs or data. Prerequisites Understanding of the duration of log management needed by the organization. Understanding of the duration of logs searched by ...
                    • How to Delete Old Logs or Data in EventLog Analyzer

                      Objective This article helps you manage and delete old log data in EventLog Analyzer using retention and archival settings. It explains how to automatically or manually remove outdated logs to optimize storage and maintain disk usage. Prerequisites ...
                    • Unable to start EventLog Analyzer

                      Issue description This issue occurs when the EventLog Analyzer service fails to start, or when users are unable to access the web client through the browser (typically on ports 8400 or 8445). Users may experience one or more of the following ...
                    • How to collect historic logs from Windows devices in EventLog Analyzer

                      Objective When a Windows device is onboarded in EventLog Analyzer, log collection starts from the moment of onboarding. To retrieve Windows event logs generated before the onboarding, you can use the following methods: Historic log collection: Can be ...