<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Maintaining Insight on</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/</link><description>Recent content in Maintaining Insight on</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 14 Apr 2026 08:15:03 +0000</lastBuildDate><atom:link href="https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/index.xml" rel="self" type="application/rss+xml"/><item><title>Working with alerts</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/iag_alerts_wrap/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/iag_alerts_wrap/</guid><description>&lt;h2 id="viewing-alerts">Viewing alerts&lt;/h2>
&lt;p>Generated alerts are displayed on the Audit Store Dashboards. View and acknowledge the alerts from the alerting dashboard by navigating to &lt;strong>OpenSearch Plugins&lt;/strong> &amp;gt; &lt;strong>Alerting&lt;/strong> &amp;gt; &lt;strong>Alerts&lt;/strong>. The alerting dashboard is shown in the following figure.&lt;/p>
&lt;p>&lt;img src="https://docs.protegrity.com/10.2/docs/images/log_alert_view.jpg" alt="" title="Viewing Alerts">&lt;/p>
&lt;p>Destinations for alerts are moved to channels in Notifications. For more information about working with Monitors, Alerts, and Notifications, refer to the section &lt;strong>Monitors&lt;/strong> in &lt;a href="https://opensearch.org/docs/2.18/dashboards/">https://opensearch.org/docs/2.18/dashboards/&lt;/a>.&lt;/p>
&lt;h2 id="creating-notifications">Creating notifications&lt;/h2>
&lt;p>Create notification channels to receive alerts as per individual requirements. The alerts are sent to the destination specified in the channel.&lt;/p></description></item><item><title>Index lifecycle management (ILM)</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/plug_logs_ilm/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/plug_logs_ilm/</guid><description>&lt;p>In the earlier versions of the ESA, the UI for &lt;strong>Index Lifecycle Management&lt;/strong> was named as &lt;strong>Information Lifecycle Management&lt;/strong>.&lt;/p>
&lt;p>The following figure shows the ILM system components and the workflow.&lt;/p>
&lt;p>&lt;img src="https://docs.protegrity.com/10.2/docs/images/plug_ilm.png" alt="" title="ILM System Components and Workflow">&lt;/p>
&lt;p>The ILM log repository is divided into the following parts:&lt;/p>
&lt;ul>
&lt;li>Active logs that may be required for immediate reporting. These logs are accessed regularly for high frequency reporting.&lt;/li>
&lt;li>Logs that are pushed to Short Term Archive (STA). These logs are accessed occasionally for moderate reporting frequency.&lt;/li>
&lt;li>Logs that are pushed to Long Term Archive (LTA). These logs are accessed rarely for low reporting frequency. The logs are stored where they can be backed up by the backup mechanism used by the enterprise.&lt;/li>
&lt;/ul>
&lt;p>The ILM feature in Protegrity Analytics is used to archive the log entries from the index. The logs generated for the ILM operations appear on this page. Only logs generated by ILM operation on the ESA v9.2.0.0 and above appear on the page after upgrading to the latest version of the ESA. For ILM logs generated on an earlier version of the ESA, navigate to &lt;strong>Audit Store &amp;gt; Dashboard &amp;gt; Open in new tab&lt;/strong>, select &lt;strong>Discover&lt;/strong> from the menu, select the time period, and search for the ILM logs using keywords for the &lt;em>additional_info.procedure&lt;/em> field, such as, &lt;em>export&lt;/em>, &lt;em>process_post_export_log&lt;/em>, or &lt;em>scroll_index_for_export&lt;/em>.&lt;/p></description></item><item><title>Viewing policy reports</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_report_view_reports/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_report_view_reports/</guid><description>&lt;p>If a report is present where policies were not modified, then a breach might have occurred. These instances can be further analyzed to find and patch security issues. A new policy report is generated when this reporting agent is first installed on the ESA. This ensures that the initial state of all the policies on all the data stores in the ESA. A user can then use the Protegrity Analytics to list all the reports that were saved over time and select the required reports.&lt;/p></description></item><item><title>Verifying signatures</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_sig_wrap/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_sig_wrap/</guid><description>&lt;p>The log entries having checksums are identified. These entries are then processed using the signature key and the checksum received in the log entry from the protector is checked. If both the checksum values match, then the log entry has not been tampered with. If a mismatch is found, then it might be possible that the log entry was tampered or there is an issue receiving logs from a protector. These can be viewed on the &lt;strong>Discover&lt;/strong> screen by using the following search criteria.&lt;/p></description></item><item><title>Using the scheduler</title><link>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_cron_wrapper/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/aog/audit_store_maintenance/log_cron_wrapper/</guid><description>&lt;p>To view the list of tasks that are scheduled, from the Analytics screen, navigate to &lt;strong>Scheduler&lt;/strong> &amp;gt; &lt;strong>Tasks&lt;/strong>. The &lt;strong>viewer&lt;/strong> role user or a user with the &lt;strong>viewer&lt;/strong> role can only view logs and history related to the Scheduler. You need admin rights to create or modify schedules.&lt;/p>
&lt;p>The following tasks are available by default:&lt;/p>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Task&lt;/th>
 &lt;th>Description&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;strong>Export Troubleshooting Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for exporting logs from the troubleshooting index.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Export Policy Log Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for exporting logs from the policy index.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Export Protectors Status Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for exporting logs from the protector status index.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Delete Miscellaneous Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for deleting old versions of the miscellaneous index that are rolled over.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Delete DSG Error Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for deleting old versions of the DSG error index that are rolled over.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Delete DSG Usage Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for deleting old versions of the DSG usage matrix index that are rolled over.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Delete DSG Transaction Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for deleting old versions of the DSG transaction matrix index that are rolled over.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Signature Verification&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for performing signature verification of log entries.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Export Audit Indices&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for exporting logs from the audit index.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Rollover Index&lt;/strong>&lt;/td>
 &lt;td>Scheduled task for performing an index rollover.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;blockquote>
&lt;p>Ensure that the scheduled tasks are disabled on all the nodes before upgrading the ESA.&lt;/p></description></item></channel></rss>