You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: blog-cse/2025-05-09-content.md
-4Lines changed: 0 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,10 +21,6 @@ This release includes:
21
21
22
22
Changes are enumerated below.
23
23
24
-
:::warning attention
25
-
We are currently aware of a synchronization issue with updated and new rules not appearing with the specified changes and are working to address the issue ASAP.
26
-
:::
27
-
28
24
### Rules
29
25
-[New] OUTLIER-S00033 AWS DynamoDB Outlier in PutItem Events from User
30
26
-[Disabled by Default] This rule detects an unusual amount of PutItem events to a DynamoDB resource within an hour time period (DynamoDB data events are required). Verify the user is authorized to modify the DynamoDB tables and instances. This rule is disabled by default due to potential volume of signals, before enabling consider excluding authorized users via match lists, and adjust floor value and model sensitivity as needed.
We're excited to introduce the new Bitwarden app for Sumo Logic. This app enables threat detection and identification of high-risk events such as vault exports or SSO deactivation, supporting continuous monitoring and accelerating incident response for credential and secret management workflows. [Learn more](/docs/integrations/saas-cloud/bitwarden).
Copy file name to clipboardExpand all lines: docs/integrations/microsoft-azure/azure-container-instances.md
+24-88Lines changed: 24 additions & 88 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,100 +24,15 @@ For more information on supported dimensions, refer to the [Azure documentation]
24
24
## Setup
25
25
26
26
* Set up application logs collection using fluent-bit sidecar container using the [http output plugin](https://docs.fluentbit.io/manual/1.5/pipeline/outputs/http) and the [tail input plugin](https://docs.fluentbit.io/manual/1.5/pipeline/inputs/tail). You must explicitly enable fluent-bit collection for each container group which you want to monitor.
27
-
*Set up metrics collection using Azure Metrics Source.
27
+
*Metrics collection using our [Azure Metrics Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source).
28
28
29
29
:::note
30
30
Sumo Logic Metrics source is currently in Beta, to participate, contact your Sumo Logic account executive.
31
31
:::
32
-
33
-
### Configure field in field schema
34
-
35
-
1.[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data > Logs > Fields**. <br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select **Configuration**, and then under **Logs** select **Fields**. You can also click the **Go To...** menu at the top of the screen and select **Fields**.
36
-
1. Search for the following fields:
37
-
-`tenant_name`. This field is tagged at the collector level. You can get the tenant name using the instructions [here](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tenant-management-read-tenant-name#get-your-tenant-name).
38
-
-`location`. The region to which the resource name belongs to.
39
-
-`subscription_id`. ID associated with a subscription where the resource is present.
40
-
-`resource_group`. The resource group name where the Azure resource is present.
41
-
-`provider_name`. Azure resource provider name (for example, Microsoft.Network).
42
-
-`resource_type`. Azure resource type (for example, storage accounts).
43
-
-`resource_name`. The name of the resource (for example, storage account name).
44
-
-`service_type`. Type of the service that can be accessed with a Azure resource.
45
-
-`service_name`. Services that can be accessed with an Azure resource (for example, in Azure Container Instances service is Subscriptions).
46
-
1. Create the fields if they are not present. Refer to [Manage fields](/docs/manage/fields/#manage-fields).
47
-
48
-
### Configure field extraction rules
49
-
50
-
Create the following Field Extraction Rule(s) (FER) for Azure Storage by following the instructions in [Create a Field Extraction Rule](/docs/manage/field-extractions/create-field-extraction-rule/).
To set up the Azure Metrics source in Sumo Logic, refer to [Azure Metrics Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source).
121
36
122
37
### Configure logs collection
123
38
@@ -170,6 +85,18 @@ import AppInstallNoDataSourceV2 from '../../reuse/apps/app-install-index-apps-v2
170
85
171
86
<AppInstallNoDataSourceV2/>
172
87
88
+
As part of the app installation process, the following fields will be created by default:
89
+
90
+
-`tenant_name`. This field is tagged at the collector level. You can get the tenant name using the instructions [here](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tenant-management-read-tenant-name#get-your-tenant-name).
91
+
-`location`. The region to which the resource name belongs to.
92
+
-`subscription_id`. ID associated with a subscription where the resource is present.
93
+
-`resource_group`. The resource group name where the Azure resource is present.
94
+
-`provider_name`. Azure resource provider name (for example, Microsoft.Network).
95
+
-`resource_type`. Azure resource type (for example, storage accounts).
96
+
-`resource_name`. The name of the resource (for example, storage account name).
97
+
-`service_type`. Type of the service that can be accessed with a Azure resource.
98
+
-`service_name`. Services that can be accessed with an Azure resource (for example, in Azure Container Instances the service is Subscriptions).
99
+
173
100
## Viewing the Azure Container Instances dashboards
174
101
175
102
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
@@ -180,7 +107,7 @@ import ViewDashboards from '../../reuse/apps/view-dashboards.md';
180
107
181
108
The **Azure Container Instance - Error Logs** dashboard provides detailed information on the container activity. This dashboard also provides comprehensive overview of Total Errors, Top 10 Errors bar chart, Log Level Error distribution, Error Trend by Container, and Recent Container Logs.
|`Azure Container Instances - Memory Usage`| This alert is triggered when memory usage is greater than 20 MB. Also warning alert is triggered when the memory usage exceeds 15 MB. | Data volume > 20MB | Data volume < = 20MB |
151
+
|`Azure Container Instances - CPU Usage`| This alert is triggered when CPU usage is greater than 100 milicore. Also warning alert is triggered when the CPU usage exceeds 90 millicore. | millicores > 100 | millicores < = 100 |
152
+
217
153
## Troubleshooting
218
154
219
155
### HTTP Logs and Metrics Source used by Azure Functions
0 commit comments