The Graphical view of ESM is the default view in Event Source Management. In Graphical view, you can view the status of a collector and access the configuration settings of Collectors and collector related objects as a graph of connected nodes.
By default, the Health Monitor Display frame opens in the Graphical View. The data can be displayed in seven different layouts. The default layout in graph is the "Hierarchic Left to Right" layout. You can change between these layouts by selecting the layout format from the drop-down list in the Tool Bar.
TIP:
Click in the Graphical ESM view and use "+" or "-"sign to zoom in or zoom out. Alternatively use mouse wheel to zoom in and zoom out.
In the Graphical View, the lines connecting the components are color-coded to indicate data flow.
Green Line: Indicates data is flowing between the components.
Grey Line: Indicates the connection is not live and there is no data flow.
Blue dashed Line: Indicates the logical relation of Event Source Servers to their associated Collector Managers and Event Sources.
The terminology used for nodes are:
Parent Node: A Node from which child nodes originate
Immediate Children: The sub nodes that are logically and functionally linked to a Parent Node.
Collapsed/Expanded nodes: To improve the manageability and performance of the Graphical display, Sentinel automatically contracts any node with 20 or more immediate children. This is especially useful for Connectors such as Syslog or Novell Audit that have the ability to automatically configure a large number of event sources.
TIP:
Collapsed Nodes are identified by a "-" sign on the node and Expanded Nodes by "+" sign.
Double-click a node to expand or collapse.
In collapsed state, a node displays the number of immediate children next to the node; for example, WMI Connector (3) [Collector name (Number of immediate children)]. The "Children" panel of a contracted node shows the immediate children of that node, each of which can be managed in the same way as nodes in the Tabular ESM View.
NOTE: Event Source Server node do not have "+" or "-" sign after its name even if it contains children.
Double-clicking a parent node changes the state from collapsed to expanded and vice versa. Double-clicking a node with no children displays the status details for that node. If an additional node is added to an expanded parent with over 20 children the node is contracted automatically. If an additional node is added to a manually expanded parent with over 20 children the node will not be contracted automatically.
The parent node may take several minutes to expand if the parent node has a large enough number of child nodes to potentially cause the UI to become unresponsive; an alert message displays on the user interface to warn you about the delay in response. Click Yes to continue.
If you chose not to show this message again, the preferences are saved on that machine and any user logging into Sentinel from that machine will not get an alert again.