Sources of events are displayed in the table under Source status → List of event sources. One page can display up to 250 sources. You can sort the table by clicking the column header of the relevant setting. Clicking on a source of events opens an incoming data graph.
You can use the Search field to search for event sources. The search is performed using regular expressions (RE2).
If necessary, you can configure the interval for updating data in the table. Available update periods: 1 minute, 5 minutes, 15 minutes, 1 hour. The default value is No refresh. You may need to configure the update period to track changes made to the list of sources.
The following columns are available:
The table can be filtered by this setting.
You can change the name of an event source. The name can contain no more than 128 Unicode characters.
By default, no more than 250 event sources are displayed on the page and are available for selection. If more event sources exist, to be able to select them, you must load additional event sources by clicking the Show next 250 button in the lower part of the window.
Group operations with the Select all option work only with currently displayed event sources. For example, if you click Select all, and only 500 out of 1500 sources are displayed in the list, bulk actions to download, apply or disable policies, or delete sources are applied only to the selected 500 sources.
If you select sources of events, the following buttons become available:
If there is no policy for the selected event source, the Apply policy button is inactive. This button will also be inactive if sources from different tenants are selected, but the user has no available policies in the shared tenant.
In some rare cases, the status of a disabled policy may change from gray to green a few seconds after it is disabled due to overlapping internal processes of KUMA. If this happens, you need to disable the monitoring policy again.