Store, manage, view, and report on log data.
Data received by ELM is organized into storage pools, each composed of storage devices. A retention time is associated with each storage pool and the data is retained in the pool for the period specified. Government, industry, and corporate regulations require that logs be stored for different time periods.
You can set up search and integrity-check jobs on the ELM. Each job accesses stored logs and retrieves or checks data defined in the job. You can then view the results and export the information.
To configure an ELM, you must know:
Sources that are storing logs on the ELM
Required storage pools and their data retention times
Storage devices that are needed to store the data
Generally, you know the sources that store logs on the ELM and the storage pools that are needed. What is unknown is the needed storage devices that store the data. The best approach to addressing this uncertainty is:
Make a conservative estimate of the storage requirements.
Note
ELM storage pools require 10 percent of the allocated space for mirroring overhead. Consider this overhead when calculating required space.
Configure ELM storage devices to meet the estimated requirements.
Review logs on the ELM for a short period.
Use ELM storage statistics to change the storage device configurations to accommodate the actual data storage requirements.