Here is our setup:
We have a rolling 7 day database (keeps last 7 days) of syslog messages from about 12 servers. The number of messages for 7 days ranges from 750,000 to 1,250,000.
If there is an event somewhere in the 7 days we have to do the following:
1) open up Console
2) select the appropriate event view (Syslog - server overview)
3) wait for the query to finish (10-20 sec) - this results in several thousand pages
4) edit the view and select a narrow time range around the event time in question
5) wait for the query to finish (10-20 sec) - this results in a handful of pages
6) do our analyses
My question is: can this be done with only one query -> can the time range of the view be edited BEFORE the query.
We are new to this software application so any ideas or suggestions of a better or different process would also be welcome.
Thank you,
dfg


