Skip to content

Commit 372da06

Browse files
kimsaucejpipkin1
andauthored
DOCS-362 - Log Search Behavior Insights refactor (#4869)
* Log Search Behavior Insights refactor * Update docs/get-started/ai-machine-learning.md Co-authored-by: John Pipkin (Sumo Logic) <[email protected]> * fixed index cards * fix search index * syntax error * Move 'Lookup Tables' in index --------- Co-authored-by: John Pipkin (Sumo Logic) <[email protected]>
1 parent 985f8c5 commit 372da06

File tree

30 files changed

+152
-115
lines changed

30 files changed

+152
-115
lines changed

blog-service/2021/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -566,7 +566,7 @@ Update - The [alert variable](/docs/alerts/monitors/alert-variables) `Results
566566
---
567567
## April 7, 2021 (Search)
568568

569-
Update - The LogReduce operator now provides an [optimize option](/docs/search/logreduce) that provides up to 10x speedup over classic LogReduce on datasets with hundreds of thousands of logs.
569+
Update - The LogReduce operator now provides an [optimize option](/docs/search/behavior-insights/logreduce) that provides up to 10x speedup over classic LogReduce on datasets with hundreds of thousands of logs.
570570

571571
---
572572
## April 6, 2021 (Dashboard)

cid-redirects.json

Lines changed: 43 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -370,8 +370,8 @@
370370
"/05Search/Anomaly-Detection/Anomalies-Page/Drill-Down-into-Events": "/docs/dashboards/drill-down-to-discover-root-causes",
371371
"/05Search/Behavior_Insights": "/docs/search/behavior-insights",
372372
"/05Search/Behavior_Insights/LogExplain": "/docs/search/behavior-insights/logexplain",
373-
"/05Search/Behavior_Insights/LogReduce_Keys": "/docs/search/behavior-insights/logreduce-keys",
374-
"/05Search/Behavior_Insights/LogReduce_Values": "/docs/search/behavior-insights/logreduce-values",
373+
"/05Search/Behavior_Insights/LogReduce_Keys": "/docs/search/behavior-insights/logreduce/logreduce-keys",
374+
"/05Search/Behavior_Insights/LogReduce_Values": "/docs/search/behavior-insights/logreduce/logreduce-values",
375375
"/05Search/Get-Started-with-Search": "/docs/search/get-started-with-search",
376376
"/05Search/Get-Started-with-Search/How-to-Build-a-Search": "/docs/search/get-started-with-search/build-search",
377377
"/05Search/Get-Started-with-Search/How-to-Build-a-Search/Best-Practices%3A-Search-Rules-to-Live-By": "/docs/search/get-started-with-search/build-search/best-practices-search",
@@ -435,17 +435,17 @@
435435
"/05Search/Live-Tail/Live-Tail-Show-in-Search": "/docs/search/live-tail/live-tail-show-in-search",
436436
"/05Search/Live-Tail/Multiple-Live-Tails": "/docs/search/live-tail/multiple-live-tails",
437437
"/05Search/Live-Tail/Troubleshooting-Live-Tail": "/docs/search/live-tail/troubleshooting-live-tail",
438-
"/05Search/LogCompare": "/docs/search/logcompare",
439-
"/05Search/LogCompare/About-LogCompare": "/docs/search/logcompare",
440-
"/05Search/LogCompare/Create-a-LogCompare-Email-Alert": "/docs/search/logcompare",
441-
"/05Search/LogCompare/LogCompare-Syntax": "/docs/search/logcompare",
442-
"/05Search/LogCompare/Run-LogCompare": "/docs/search/logcompare",
443-
"/05Search/LogCompare/Understand-LogCompare-Results": "/docs/search/logcompare",
444-
"/05Search/LogReduce": "/docs/search/logreduce/logreduce-operator",
445-
"/05Search/LogReduce/01-LogReduce-Operator": "/docs/search/logreduce/logreduce-operator",
446-
"/05Search/LogReduce/Detect-Patterns-with-LogReduce": "/docs/search/logreduce/detect-patterns-with-logreduce",
447-
"/05Search/LogReduce/Influence-the-LogReduce-Outcome": "/docs/search/logreduce/influence-the-logreduce-outcome",
448-
"/05Search/LogReduce/Understand-the-LogReduce-Relevance-Column": "/docs/search/logreduce/understand-the-logreduce-relevance-column",
438+
"/05Search/LogCompare": "/docs/search/behavior-insights/logcompare",
439+
"/05Search/LogCompare/About-LogCompare": "/docs/search/behavior-insights/logcompare",
440+
"/05Search/LogCompare/Create-a-LogCompare-Email-Alert": "/docs/search/behavior-insights/logcompare",
441+
"/05Search/LogCompare/LogCompare-Syntax": "/docs/search/behavior-insights/logcompare",
442+
"/05Search/LogCompare/Run-LogCompare": "/docs/search/behavior-insights/logcompare",
443+
"/05Search/LogCompare/Understand-LogCompare-Results": "/docs/search/behavior-insights/logcompare",
444+
"/05Search/LogReduce": "/docs/search/behavior-insights/logreduce/logreduce-operator",
445+
"/05Search/LogReduce/01-LogReduce-Operator": "/docs/search/behavior-insights/logreduce/logreduce-operator",
446+
"/05Search/LogReduce/Detect-Patterns-with-LogReduce": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
447+
"/05Search/LogReduce/Influence-the-LogReduce-Outcome": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
448+
"/05Search/LogReduce/Understand-the-LogReduce-Relevance-Column": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
449449
"/05Search/Lookup_Tables": "/docs/search/lookup-tables",
450450
"/05Search/Lookup_Tables/01_Create_a_Lookup_Table0": "/docs/search/lookup-tables/create-lookup-table",
451451
"/05Search/Lookup_Tables/01_Create_a_Lookup_Table": "/docs/search/lookup-tables/create-lookup-table",
@@ -1703,7 +1703,7 @@
17031703
"/cid/10450": "/docs/alerts/webhook-connections/microsoft-teams",
17041704
"/cid/1046": "/docs/alerts/webhook-connections/pagerduty",
17051705
"/cid/1047": "/docs/alerts/webhook-connections/datadog",
1706-
"/cid/1048": "/docs/search/logcompare",
1706+
"/cid/1048": "/docs/search/behavior-insights/logcompare",
17071707
"/cid/1049": "/docs/get-started",
17081708
"/cid/1050": "/docs/integrations/amazon-aws/s3-audit",
17091709
"/cid/1051": "/docs/integrations/amazon-aws/vpc-flow-logs",
@@ -1720,8 +1720,8 @@
17201720
"/cid/1061": "/release-notes-collector",
17211721
"/cid/1062": "/docs/alerts/webhook-connections",
17221722
"/cid/1063": "/docs/alerts/webhook-connections/aws-lambda",
1723-
"/cid/1064": "/docs/search/logreduce/logreduce-operator",
1724-
"/cid/1065": "/docs/search/logreduce/logreduce-operator",
1723+
"/cid/1064": "/docs/search/behavior-insights/logreduce/logreduce-operator",
1724+
"/cid/1065": "/docs/search/behavior-insights/logreduce/logreduce-operator",
17251725
"/cid/1066": "/docs/send-data/hosted-collectors/cloud-syslog-source",
17261726
"/cid/1067": "/docs/search/live-tail/live-tail-cli",
17271727
"/cid/1068": "/docs/search/live-tail/about-live-tail",
@@ -1877,7 +1877,7 @@
18771877
"/cid/2005": "/docs/search/get-started-with-search",
18781878
"/cid/2006": "/docs/search/search-query-language/search-operators/manually-cast-data-string-number",
18791879
"/cid/2008": "/docs/send-data/installed-collectors/linux",
1880-
"/cid/2009": "/docs/search/logcompare",
1880+
"/cid/2009": "/docs/search/behavior-insights/logcompare",
18811881
"/cid/2010": "/docs/search/search-query-language/search-operators/if",
18821882
"/cid/2011": "/docs/get-started/help",
18831883
"/cid/2012": "/docs/manage/security/enable-support-account",
@@ -1888,15 +1888,15 @@
18881888
"/cid/2017": "/docs/manage/users-roles/users/delete-user",
18891889
"/cid/2018": "/docs/send-data/installed-collectors/windows",
18901890
"/cid/2019": "/docs/integrations/pci-compliance/linux",
1891-
"/cid/2021": "/docs/search/logreduce/detect-patterns-with-logreduce",
1891+
"/cid/2021": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
18921892
"/cid/2022": "/docs/send-data/installed-collectors",
18931893
"/cid/2023": "/docs/send-data/collection/edit-collector",
18941894
"/cid/2024": "/docs/search/get-started-with-search/search-basics/export-search-results",
18951895
"/cid/2026": "/",
18961896
"/cid/2027": "/docs/search/get-started-with-search/build-search/keyword-search-expressions",
18971897
"/cid/2028": "/docs/search/get-started-with-search",
18981898
"/cid/2030": "/docs/search/search-query-language/group-aggregate-operators",
1899-
"/cid/2032": "/docs/search/logreduce/influence-the-logreduce-outcome",
1899+
"/cid/2032": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
19001900
"/cid/2033": "/docs/get-started",
19011901
"/cid/2036": "/docs/integrations/hosts-operating-systems/linux",
19021902
"/cid/2038": "/docs/search/search-query-language/math-expressions",
@@ -1911,20 +1911,20 @@
19111911
"/cid/2047": "/docs/search/get-started-with-search/search-basics/pause-cancel-search",
19121912
"/cid/2049": "/docs/send-data/installed-collectors/sources/remote-file-source/prerequisites-windows-remote-file-collection",
19131913
"/cid/2050": "/docs/get-started",
1914-
"/cid/2057": "/docs/search/logcompare",
1914+
"/cid/2057": "/docs/search/behavior-insights/logcompare",
19151915
"/cid/2058": "/docs/alerts/scheduled-searches/create-email-alert",
19161916
"/cid/2059": "/docs/search/get-started-with-search/search-basics/save-search",
1917-
"/cid/2060": "/docs/search/logcompare",
1917+
"/cid/2060": "/docs/search/behavior-insights/logcompare",
19181918
"/cid/2064": "/docs/search/search-cheat-sheets/general-search-examples",
19191919
"/cid/2066": "/docs/search/get-started-with-search/search-basics/search-surrounding-messages",
19201920
"/cid/2068": "/docs/integrations/saas-cloud/fastly",
19211921
"/cid/2069": "/docs/integrations/app-development/gitlab",
19221922
"/cid/2070": "/docs/search/search-query-language/search-operators/sort",
19231923
"/cid/2071": "/docs/send-data/collection/start-stop-collector-using-scripts",
19241924
"/cid/2072": "/docs/search/get-started-with-search/suggested-searches",
1925-
"/cid/2073": "/docs/search/logcompare",
1926-
"/cid/2074": "/docs/search/logreduce/logreduce-operator",
1927-
"/cid/2075": "/docs/search/logreduce/logreduce-operator",
1925+
"/cid/2073": "/docs/search/behavior-insights/logcompare",
1926+
"/cid/2074": "/docs/search/behavior-insights/logreduce/logreduce-operator",
1927+
"/cid/2075": "/docs/search/behavior-insights/logreduce/logreduce-operator",
19281928
"/cid/2076": "/docs/get-started",
19291929
"/cid/2077": "/docs/get-started",
19301930
"/cid/2078": "/docs/search/search-query-language/search-operators/if",
@@ -2089,7 +2089,7 @@
20892089
"/cid/4412": "/docs/integrations/saas-cloud/crowdstrike-fdr-host-inventory",
20902090
"/cid/44122": "/docs/integrations/saas-cloud/crowdstrike-spotlight",
20912091
"/cid/44123": "/docs/integrations/saas-cloud/crowdstrike-falcon-filevantage",
2092-
"/cid/4020": "/docs/search/logreduce",
2092+
"/cid/4020": "/docs/search/behavior-insights/logreduce",
20932093
"/cid/4021": "/docs/search/search-query-language/search-operators/accum",
20942094
"/cid/40001": "/docs/search/search-query-language/search-operators/as",
20952095
"/cid/40002": "/docs/search/search-query-language/search-operators/asn-lookup",
@@ -2285,7 +2285,7 @@
22852285
"/cid/5134": "/docs/dashboards/panels",
22862286
"/cid/5135": "/docs/dashboards/drill-down-to-discover-root-causes",
22872287
"/cid/5136": "/docs/get-started/library",
2288-
"/cid/5138": "/docs/search/logreduce/influence-the-logreduce-outcome",
2288+
"/cid/5138": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
22892289
"/cid/5139": "/docs/send-data/collection/edit-source",
22902290
"/cid/5140": "/docs/get-started/library",
22912291
"/cid/5143": "/docs/manage/users-roles/roles/create-manage-roles",
@@ -2423,7 +2423,7 @@
24232423
"/cid/5334": "/docs/search/get-started-with-search/suggested-searches/microsoft-iis-parser",
24242424
"/cid/5335": "/docs/search",
24252425
"/cid/5336": "/docs/send-data/collection/search-for-a-collector-or-source",
2426-
"/cid/5339": "/docs/search/logreduce",
2426+
"/cid/5339": "/docs/search/behavior-insights/logreduce",
24272427
"/cid/5340": "/docs/integrations/sumo-apps/security-analytics",
24282428
"/cid/5341": "/docs/integrations/sumo-apps/security-analytics",
24292429
"/cid/5342": "/docs/alerts/webhook-connections/servicenow",
@@ -2439,7 +2439,7 @@
24392439
"/cid/5356": "/docs/dashboards/panels/modify-chart",
24402440
"/cid/5368": "/docs/dashboards/panels/single-value-charts",
24412441
"/cid/5375": "/",
2442-
"/cid/5377": "/docs/search/logreduce/understand-the-logreduce-relevance-column",
2442+
"/cid/5377": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
24432443
"/cid/5378": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/aws-cloudtrail",
24442444
"/cid/5379": "/docs/integrations/amazon-aws/elastic-load-balancing",
24452445
"/cid/5380": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/aws-cloudtrail",
@@ -2478,7 +2478,7 @@
24782478
"/cid/5444": "/docs/integrations/web-servers/varnish",
24792479
"/cid/5445": "/docs/integrations/web-servers/varnish",
24802480
"/cid/5446": "/docs/integrations/containers-orchestration/vmware-legacy",
2481-
"/cid/5448": "/docs/search/logreduce/detect-patterns-with-logreduce",
2481+
"/cid/5448": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
24822482
"/cid/5449": "/docs/integrations/containers-orchestration/vmware-legacy",
24832483
"/cid/5450": "/",
24842484
"/cid/5454": "/docs/manage/security/create-allowlist-ip-cidr-addresses",
@@ -2687,8 +2687,8 @@
26872687
"/cid/23411": "/docs/integrations/saas-cloud/sophos",
26882688
"/cid/9078": "/docs/manage/users-roles/roles/construct-search-filter-for-role",
26892689
"/cid/915200739": "/docs/observability/sdo/about-sdo",
2690-
"/cid/9201": "/docs/search/behavior-insights/logreduce-keys",
2691-
"/cid/9202": "/docs/search/behavior-insights/logreduce-values",
2690+
"/cid/9201": "/docs/search/behavior-insights/logreduce/logreduce-keys",
2691+
"/cid/9202": "/docs/search/behavior-insights/logreduce/logreduce-values",
26922692
"/cid/9205": "/docs/search/behavior-insights/logexplain",
26932693
"/cid/96734": "/docs/send-data/hosted-collectors/http-source/troubleshooting",
26942694
"/cid/97652": "/docs/integrations/saas-cloud/qualys-vmdr",
@@ -3799,9 +3799,9 @@
37993799
"/Search/Get_Started_with_Search/Search_Basics/Search_Metadata": "/docs/search/get-started-with-search/search-basics",
38003800
"/Search/Library/Apps-in-Sumo-Logic/01-Sumo-Logic-Apps/Data-Volume-App": "/docs/integrations/sumo-apps/data-volume",
38013801
"/Search/Library/Apps-in-Sumo-Logic/01-Sumo-Logic-Apps/Data-Volume-App/Data-Volume-App-Dashboards": "/docs/integrations/sumo-apps/data-volume",
3802-
"/Search/LogCompare": "/docs/search/logcompare",
3803-
"/Search/LogCompare/About_LogCompare": "/docs/search/logcompare",
3804-
"/Search/LogReduce": "/docs/search/logreduce",
3802+
"/Search/LogCompare": "/docs/search/behavior-insights/logcompare",
3803+
"/Search/LogCompare/About_LogCompare": "/docs/search/behavior-insights/logcompare",
3804+
"/Search/LogReduce": "/docs/search/behavior-insights/logreduce",
38053805
"/Query_Language": "/docs/search/search-query-language",
38063806
"/Search/Search_Query_Language": "/docs/search/search-query-language",
38073807
"/Search/Search_Query_Language/Parse_Operators/CSV_Operator": "/docs/search/search-query-language/parse-operators/parse-csv-formatted-logs",
@@ -4186,5 +4186,13 @@
41864186
"/docs/integrations/amazon-aws/aurora-mysql-ulm": "/docs/integrations/amazon-aws/rds",
41874187
"/docs/integrations/amazon-aws/aurora-postgresql-ulm": "/docs/integrations/amazon-aws/rds",
41884188
"/docs/integrations/amazon-aws/elastic-load-balancer-app": "/docs/integrations/amazon-aws/application-load-balancer",
4189-
"/docs/integrations/amazon-aws/elastic-load-balancing-classic": "/docs/integrations/amazon-aws/classic-load-balancer"
4189+
"/docs/integrations/amazon-aws/elastic-load-balancing-classic": "/docs/integrations/amazon-aws/classic-load-balancer",
4190+
"/docs/search/logcompare": "/docs/search/behavior-insights/logcompare",
4191+
"/docs/search/behavior-insights/logreduce-keys": "/docs/search/behavior-insights/logreduce/logreduce-keys",
4192+
"/docs/search/logreduce": "/docs/search/behavior-insights/logreduce",
4193+
"/docs/search/logreduce/logreduce-operator": "/docs/search/behavior-insights/logreduce/logreduce-operator",
4194+
"/docs/search/logreduce/detect-patterns-with-logreduce": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
4195+
"/docs/search/logreduce/influence-the-logreduce-outcome": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
4196+
"/docs/search/logreduce/understand-the-logreduce-relevance-column": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
4197+
"/docs/search/behavior-insights/logreduce-values": "/docs/search/behavior-insights/logreduce/logreduce-values"
41904198
}

docs/alerts/monitors/alert-response-faq.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ Sumo Logic detects and maintains a signature library. It does that by analyzing
6767

6868
There could be cases where the process has still not cataloged a new log message to a signature. As a result, it would get bundled into the "Others" category. This problem should be fixed automatically after some time (when the background process runs).
6969

70-
You can also force run the signature cataloging process manually, by calling the [LogCompare](../../search/logcompare.md) or [LogReduce](/docs/search/logreduce) operators from the Log Search page. 
70+
You can also force run the signature cataloging process manually, by calling the [LogCompare](/docs/search/behavior-insights/logcompare) or [LogReduce](/docs/search/behavior-insights/logreduce) operators from the Log Search page. 
7171

7272
## I don’t see the Dimensional Explanation card for logs-based alert
7373

docs/alerts/monitors/alert-response.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ See [Using tags in alerts](/docs/alerts/monitors/settings/#using-tags-in-alerts)
160160

161161
### Log fluctuations
162162

163-
This card detects different signatures in your log messages using [LogReduce](/docs/search/logreduce) such as errors, exceptions, timeouts, and successes. It compares log signatures trends with a normal baseline period and surfaces noteworthy changes in signatures.
163+
This card detects different signatures in your log messages using [LogReduce](/docs/search/behavior-insights/logreduce) such as errors, exceptions, timeouts, and successes. It compares log signatures trends with a normal baseline period and surfaces noteworthy changes in signatures.
164164

165165
* **New**. Log signatures that were only seen after the Alert was triggered but not one hour prior to the Alert start time.
166166
* **Gone**. Log signatures that are not present after the Alert was created but were present one hour prior to the Alert start time, such as **Transaction Succeeded** or **Success**.

docs/alerts/monitors/overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ Custom variables used inside the Action Payload.
130130
### General
131131

132132
* [Receipt Time](../../search/get-started-with-search/build-search/use-receipt-time.md) is not supported.
133-
* [LogReduce](/docs/search/logreduce/logreduce-operator) / [LogCompare](../../search/logcompare.md) operators are not supported in monitors. If your query contains these operators, you will not be able to create the monitor.
133+
* [LogReduce](/docs/search/behavior-insights/logreduce/logreduce-operator) / [LogCompare](/docs/search/behavior-insights/logcompare) operators are not supported in monitors. If your query contains these operators, you will not be able to create the monitor.
134134
* Monitors only support the [Continuous data tier](/docs/manage/partitions/data-tiers).
135135
* An aggregate Metric Monitor can evaluate up to 15,000 time series. A non-aggregate Metric Monitor can evaluate up to 3,000 time series.
136136
* [Save to Index](../scheduled-searches/save-to-index.md) and [Save to Lookup](../scheduled-searches/save-to-lookup.md) are not supported.

docs/contributing/glossary.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -174,9 +174,9 @@ We also maintain a [DevOps and Security Glossary](https://www.sumologic.com/glos
174174

175175
**[Local Configuration File Management](/docs/send-data/use-json-configure-sources/local-configuration-file-management)**. Local Configuration File Management allows you to set up and manage Sources on an Installed Collector using one or more JSON files.
176176

177-
**[LogCompare](/docs/search/logcompare)**. LogCompare allows you to compare a section of your log messages from one point in time with the same section at another point in time, and display the changes in patterns.
177+
**[LogCompare](/docs/search/behavior-insights/logcompare)**. LogCompare allows you to compare a section of your log messages from one point in time with the same section at another point in time, and display the changes in patterns.
178178

179-
**[LogReduce](/docs/search/logreduce)**. LogReduce uses fuzzy logic to cluster messages together based on string and pattern similarity. Use the LogReduce button and operator to quickly assess activity patterns for things like a range of devices or traffic on a website.
179+
**[LogReduce](/docs/search/behavior-insights/logreduce)**. LogReduce uses fuzzy logic to cluster messages together based on string and pattern similarity. Use the LogReduce button and operator to quickly assess activity patterns for things like a range of devices or traffic on a website.
180180

181181
**[Logs-to-Metrics](/docs/metrics/logs-to-metrics)**. A Sumo Logic feature you can use to extract or create metrics from log data. You can extract metrics that are embedded in logs, or count logs as a metric.
182182

0 commit comments

Comments
 (0)