Sawmill Reference Guide
Sawmill Reference Guide
Enterprise Analytics
Analysing multiple different log formats from many devices and application
programs can be a real headache, and a big investment in time and money for
any organisation. Sawmill Analytics answers all of these problems with a single
solution: Sawmill. With its open architecture of format plug-ins (currently
almost 1,100) Sawmill can concurrently analyse and report on multiple
projects of different formats and independent sources, providing highly
attractive reports that can be drilled, filtered and interrogated on the fly, and
with user-definable alerts
This unrivalled flexibility has resulted in Sawmill being selected as the analytics
solution of choice by literally tens of thousands of users, including major
international companies, financial institutions and banks, security vendors
and service providers, small businesses, self-employed persons, consultants,
government departments, web design houses, law enforcement agencies and
educational establishments in almost every country of the world.
1 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
Sawmill architecture
Sawmill is multi-discipline multi-tasking software. A single copy can concurrently analyse and report
on many different and separate tasks, providing business management and security intelligence data
to all interested parties throughout an organisation using nothing more than a standard modern
browser for access (provided permission is granted). The benefits of fast accurate data correctly
shared to the right people brings major benefits for business efficiency and security.
2 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
What host platforms are supported
The downloadable trial version contains binaries for Linux, Windows and Macintosh, plus encrypted
source code for compiling to other platforms. Hardware specifications for the Sawmill server are
dependent on the size of the log files and the ‘live data’ retention period, plus the pattern and type of
use (live reports, static reports, report requests and request frequency etc.). Memory should be 2GB
for each processor core, but more memory is always a bonus. Good processor platforms for Sawmill
are Intel or AMD, with Windows and Solaris on Intel/ AMD also very good. Sawmill is also installable
in a virtual machine environment
Sawmill versions
• Sawmill Lite see feature comparison table here:
• Sawmill Professional http://www.sawmill.co.uk/matrix.php
• Sawmill Enterprise
3 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
What host services does Sawmill need
Sawmill is a free standing program requiring only the services of an operating system. It even
includes its own web server, but can use an external web server for publication if preferred
What is a Report
Log files consist of fields of data. The Sawmill plug-in will interpret and convert the majority of the
fields into report pages - one for each field, including computed fields such as geo-location or session
information. A report page may contain one or more elements such as a line graph, bar chart, pie
diagram, and/or table of data depending on the type of data being presented by Sawmill (Sawmill
makes this initial decision). A Report is the collective name for all the individual report pages and
dashboards
What is a Dashboard
A Dashboard is normally the default report in Sawmill and consists of a group of report pages
combined on a single screen. The user can determine how a dashboard is constructed (i.e. what
report pages it contains) so that the most important data is collectively displayed on a single screen
for immediate assimilation and action by the user. A Report can have multiple dashboards
Static Reports
Sawmill can also produce static html reports for viewing only, saving processing power etc.
Custom Reports
Custom reports can be created and log streams correlated (combined) where possible to create
derived reports of very high value.
Real-world names/headers/titles
External metadata tags and labels can be imported into the reports during report generation to make
the resulting reports far more readable and understandable.
Alerts
Sawmill can generate alerts based on content or events identified in the log file
4 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
SAWMILL LICENSING
What is a Plug-in
A plug-in is a log filter that parses and normalises the incoming log data into the Sawmill internal
format for input to the database. There are almost 1100 plug-ins in Sawmill, each one developed for
a specific log or event format to extract the usable data from the log.
New Plug-ins
New plug-ins are created by Sawmill Analytics when a new log or event format is encountered or the
original vendor of a system or application program modifies his logging strategy. The creation of a
new plug-in can take anything from 1 day to 1 week depending on the complexity of the format.
Skilled sysadmins may also be able to develop their own custom plug-ins
5 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
What is a Profile
A log files is imported and the reports generated under the control of a Profile, and each Profile will
only import logs of a single format type. Sawmill Professional and Sawmill Enterprise can run
multiple different Profiles concurrently, accessing and importing logs of different formats from
different locations. For Professional and Enterprise editions Profiles are available in the following
pack sizes: 1, 5, 10, 25, 50, 100, 500, 1000. Sawmill Lite can only have a single Profile and import
logs from a single source.
Creating a Profile
To create a Profile the user can use the ‘profile wizard’. This guides the user through the process of
creating a Profile by requiring answers to five simple questions: 1. are the logs are local or remote,
2. define the path to the logs, 3. internal or external database, 4. define the fields required in the
report, 5. give the Profile a name. On completion the user can run the Profile manually, or set up a
schedule to run the Profile on a regular basis.
OPERATIONAL CONSIDERATIONS
6 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk
Sawmill Customisation Rights
Customization rights are granted by the Sawmill EULA (End User License Agreement) and as
summarised below. The EULA should be consulted at all times when modification of the user
interface is being considered. A copy of the EULA is always available on request.
• Sawmill Lite - does not allow customization of the user interface
• Sawmill Professional - allows the text attributes (colour, fonts etc.) to be modified. Two areas
of the user interface are also made available for the placement of ‘white label’ logos or other
graphic items.
• Sawmill Enterprise - allows the total customization of almost everything on the user interface,
attributes, placement, and content. Everything except the Sawmill logo and Copyright notice
Important note: the Sawmill logo and the copyright notice must never be changed, moved, modified or obscured
without the prior written permission of Sawmill Analytics. Any attempt to do this will invalidate the customer’s
license to use the software as defined in the Sawmill EULA.
7 SAWMILL ANALYTICS Swindon UK tel: +44 (0)845 250 4470 [email protected] www.sawmill.co.uk