Skip to main content
Version: 6.1

Sources

Source Parameters

To add or modify a source:

  1. Click the add button next to the Source List heading, or select an existing source from the list
  2. Complete the required Name field. Its value is automatically converted to lowercase
  3. Use the Enable toggle to specify whether the source participates in event selection
  4. In Pattern, enter one wildcard pattern, for example, auditd*. Multiple comma-separated patterns are not supported for a single source
  5. Click Save to apply the changes, or Cancel to close the form without saving

A list of indexes matching the pattern is displayed under Pattern. This list shows which physical source indexes the correlator includes when selecting events.

Event Samples

A view button is available next to the pattern and each matching index. It opens the Alias Event Samples dialog containing actual events received through the alias. The number of samples stored for each alias is controlled by the ingest.event_sample_size cluster setting (default: 10).