Forum Discussion

MaheshMJ's avatar
2 months ago

Event logs limited to 100 events only

On theevents page in CMA, only the most recent 100 events are visible. Srolling though earlier events is not available. In order to search for earlier events you need to set filters, and even then only 100 events are listed.

In normal day hundreds of thousands of events are generated. It would be helpful if we could just scroll though the events and do deeper dive into events that need attention. Rather than have to guess which filters to apply when troublshooting an issue.

 

 

  • I can't imagine how slow the CMA page would be if you show more than 100 Events there. Remember that you can always export the Events from your current filter to csv file. I just tested - my filter was showing 473K of events, but when I exported them to CSV, the file contained only 250k of events (not sure if this is CATO limit).
    When I need to deep dive into a higher number of events, I usually use the "fields" pane on the left to check e.g. top domains, top src/dst IP, top applications etc. and then filter on what I'm interested about.

    • Nath's avatar
      Nath
      Meteor

      Correct, the 250K export limit is a Cato limit.

  • Yes, many a time I would love a next button to be able to move to the second page, but even then I know it would be quite slow.

    At the moment, the best way is to either a)filter it down even more or b)export your events to S3/Azure Blob storage and use a faster method of searching native within S3/Azure Blob to search the events.

    However, I am aware Cato are going to be making improvements to improve the events page fetch time, particularly when searching a time-frame over 2 weeks.  I think part of the problem is that last year Cato started enriching the events with many more fields, such as 'Network Rule' or 'TLS Inspection Rule' which we weren't previously able to see.  And this is slowing the event fetching down.

    On balance, I am just now happy all these extra fields are exposed to us admins.  We have been asking for it for years (literally 2 years), so a little deterioriation in performance in the interim is fine by me.