Skip to content

Commit 62f2886

Browse files
committed
Log Search Behavior Insights refactor
1 parent 96c5963 commit 62f2886

File tree

30 files changed

+103
-98
lines changed

30 files changed

+103
-98
lines changed

blog-service/2021/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -566,7 +566,7 @@ Update - The [alert variable](/docs/alerts/monitors/alert-variables) `Results
566566
---
567567
## April 7, 2021 (Search)
568568

569-
Update - The LogReduce operator now provides an [optimize option](/docs/search/logreduce) that provides up to 10x speedup over classic LogReduce on datasets with hundreds of thousands of logs.
569+
Update - The LogReduce operator now provides an [optimize option](/docs/search/behavior-insights/logreduce) that provides up to 10x speedup over classic LogReduce on datasets with hundreds of thousands of logs.
570570

571571
---
572572
## April 6, 2021 (Dashboard)

cid-redirects.json

Lines changed: 43 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -370,8 +370,8 @@
370370
"/05Search/Anomaly-Detection/Anomalies-Page/Drill-Down-into-Events": "/docs/dashboards/drill-down-to-discover-root-causes",
371371
"/05Search/Behavior_Insights": "/docs/search/behavior-insights",
372372
"/05Search/Behavior_Insights/LogExplain": "/docs/search/behavior-insights/logexplain",
373-
"/05Search/Behavior_Insights/LogReduce_Keys": "/docs/search/behavior-insights/logreduce-keys",
374-
"/05Search/Behavior_Insights/LogReduce_Values": "/docs/search/behavior-insights/logreduce-values",
373+
"/05Search/Behavior_Insights/LogReduce_Keys": "/docs/search/behavior-insights/logreduce/logreduce-keys",
374+
"/05Search/Behavior_Insights/LogReduce_Values": "/docs/search/behavior-insights/logreduce/logreduce-values",
375375
"/05Search/Get-Started-with-Search": "/docs/search/get-started-with-search",
376376
"/05Search/Get-Started-with-Search/How-to-Build-a-Search": "/docs/search/get-started-with-search/build-search",
377377
"/05Search/Get-Started-with-Search/How-to-Build-a-Search/Best-Practices%3A-Search-Rules-to-Live-By": "/docs/search/get-started-with-search/build-search/best-practices-search",
@@ -435,17 +435,17 @@
435435
"/05Search/Live-Tail/Live-Tail-Show-in-Search": "/docs/search/live-tail/live-tail-show-in-search",
436436
"/05Search/Live-Tail/Multiple-Live-Tails": "/docs/search/live-tail/multiple-live-tails",
437437
"/05Search/Live-Tail/Troubleshooting-Live-Tail": "/docs/search/live-tail/troubleshooting-live-tail",
438-
"/05Search/LogCompare": "/docs/search/logcompare",
439-
"/05Search/LogCompare/About-LogCompare": "/docs/search/logcompare",
440-
"/05Search/LogCompare/Create-a-LogCompare-Email-Alert": "/docs/search/logcompare",
441-
"/05Search/LogCompare/LogCompare-Syntax": "/docs/search/logcompare",
442-
"/05Search/LogCompare/Run-LogCompare": "/docs/search/logcompare",
443-
"/05Search/LogCompare/Understand-LogCompare-Results": "/docs/search/logcompare",
444-
"/05Search/LogReduce": "/docs/search/logreduce/logreduce-operator",
445-
"/05Search/LogReduce/01-LogReduce-Operator": "/docs/search/logreduce/logreduce-operator",
446-
"/05Search/LogReduce/Detect-Patterns-with-LogReduce": "/docs/search/logreduce/detect-patterns-with-logreduce",
447-
"/05Search/LogReduce/Influence-the-LogReduce-Outcome": "/docs/search/logreduce/influence-the-logreduce-outcome",
448-
"/05Search/LogReduce/Understand-the-LogReduce-Relevance-Column": "/docs/search/logreduce/understand-the-logreduce-relevance-column",
438+
"/05Search/LogCompare": "/docs/search/behavior-insights/logcompare",
439+
"/05Search/LogCompare/About-LogCompare": "/docs/search/behavior-insights/logcompare",
440+
"/05Search/LogCompare/Create-a-LogCompare-Email-Alert": "/docs/search/behavior-insights/logcompare",
441+
"/05Search/LogCompare/LogCompare-Syntax": "/docs/search/behavior-insights/logcompare",
442+
"/05Search/LogCompare/Run-LogCompare": "/docs/search/behavior-insights/logcompare",
443+
"/05Search/LogCompare/Understand-LogCompare-Results": "/docs/search/behavior-insights/logcompare",
444+
"/05Search/LogReduce": "/docs/search/behavior-insights/logreduce/logreduce-operator",
445+
"/05Search/LogReduce/01-LogReduce-Operator": "/docs/search/behavior-insights/logreduce/logreduce-operator",
446+
"/05Search/LogReduce/Detect-Patterns-with-LogReduce": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
447+
"/05Search/LogReduce/Influence-the-LogReduce-Outcome": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
448+
"/05Search/LogReduce/Understand-the-LogReduce-Relevance-Column": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
449449
"/05Search/Lookup_Tables": "/docs/search/lookup-tables",
450450
"/05Search/Lookup_Tables/01_Create_a_Lookup_Table0": "/docs/search/lookup-tables/create-lookup-table",
451451
"/05Search/Lookup_Tables/01_Create_a_Lookup_Table": "/docs/search/lookup-tables/create-lookup-table",
@@ -1700,7 +1700,7 @@
17001700
"/cid/10450": "/docs/alerts/webhook-connections/microsoft-teams",
17011701
"/cid/1046": "/docs/alerts/webhook-connections/pagerduty",
17021702
"/cid/1047": "/docs/alerts/webhook-connections/datadog",
1703-
"/cid/1048": "/docs/search/logcompare",
1703+
"/cid/1048": "/docs/search/behavior-insights/logcompare",
17041704
"/cid/1049": "/docs/get-started",
17051705
"/cid/1050": "/docs/integrations/amazon-aws/s3-audit",
17061706
"/cid/1051": "/docs/integrations/amazon-aws/vpc-flow-logs",
@@ -1717,8 +1717,8 @@
17171717
"/cid/1061": "/release-notes-collector",
17181718
"/cid/1062": "/docs/alerts/webhook-connections",
17191719
"/cid/1063": "/docs/alerts/webhook-connections/aws-lambda",
1720-
"/cid/1064": "/docs/search/logreduce/logreduce-operator",
1721-
"/cid/1065": "/docs/search/logreduce/logreduce-operator",
1720+
"/cid/1064": "/docs/search/behavior-insights/logreduce/logreduce-operator",
1721+
"/cid/1065": "/docs/search/behavior-insights/logreduce/logreduce-operator",
17221722
"/cid/1066": "/docs/send-data/hosted-collectors/cloud-syslog-source",
17231723
"/cid/1067": "/docs/search/live-tail/live-tail-cli",
17241724
"/cid/1068": "/docs/search/live-tail/about-live-tail",
@@ -1874,7 +1874,7 @@
18741874
"/cid/2005": "/docs/search/get-started-with-search",
18751875
"/cid/2006": "/docs/search/search-query-language/search-operators/manually-cast-data-string-number",
18761876
"/cid/2008": "/docs/send-data/installed-collectors/linux",
1877-
"/cid/2009": "/docs/search/logcompare",
1877+
"/cid/2009": "/docs/search/behavior-insights/logcompare",
18781878
"/cid/2010": "/docs/search/search-query-language/search-operators/if",
18791879
"/cid/2011": "/docs/get-started/help",
18801880
"/cid/2012": "/docs/manage/security/enable-support-account",
@@ -1885,15 +1885,15 @@
18851885
"/cid/2017": "/docs/manage/users-roles/users/delete-user",
18861886
"/cid/2018": "/docs/send-data/installed-collectors/windows",
18871887
"/cid/2019": "/docs/integrations/pci-compliance/linux",
1888-
"/cid/2021": "/docs/search/logreduce/detect-patterns-with-logreduce",
1888+
"/cid/2021": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
18891889
"/cid/2022": "/docs/send-data/installed-collectors",
18901890
"/cid/2023": "/docs/send-data/collection/edit-collector",
18911891
"/cid/2024": "/docs/search/get-started-with-search/search-basics/export-search-results",
18921892
"/cid/2026": "/",
18931893
"/cid/2027": "/docs/search/get-started-with-search/build-search/keyword-search-expressions",
18941894
"/cid/2028": "/docs/search/get-started-with-search",
18951895
"/cid/2030": "/docs/search/search-query-language/group-aggregate-operators",
1896-
"/cid/2032": "/docs/search/logreduce/influence-the-logreduce-outcome",
1896+
"/cid/2032": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
18971897
"/cid/2033": "/docs/get-started",
18981898
"/cid/2036": "/docs/integrations/hosts-operating-systems/linux",
18991899
"/cid/2038": "/docs/search/search-query-language/math-expressions",
@@ -1908,20 +1908,20 @@
19081908
"/cid/2047": "/docs/search/get-started-with-search/search-basics/pause-cancel-search",
19091909
"/cid/2049": "/docs/send-data/installed-collectors/sources/remote-file-source/prerequisites-windows-remote-file-collection",
19101910
"/cid/2050": "/docs/get-started",
1911-
"/cid/2057": "/docs/search/logcompare",
1911+
"/cid/2057": "/docs/search/behavior-insights/logcompare",
19121912
"/cid/2058": "/docs/alerts/scheduled-searches/create-email-alert",
19131913
"/cid/2059": "/docs/search/get-started-with-search/search-basics/save-search",
1914-
"/cid/2060": "/docs/search/logcompare",
1914+
"/cid/2060": "/docs/search/behavior-insights/logcompare",
19151915
"/cid/2064": "/docs/search/search-cheat-sheets/general-search-examples",
19161916
"/cid/2066": "/docs/search/get-started-with-search/search-basics/search-surrounding-messages",
19171917
"/cid/2068": "/docs/integrations/saas-cloud/fastly",
19181918
"/cid/2069": "/docs/integrations/app-development/gitlab",
19191919
"/cid/2070": "/docs/search/search-query-language/search-operators/sort",
19201920
"/cid/2071": "/docs/send-data/collection/start-stop-collector-using-scripts",
19211921
"/cid/2072": "/docs/search/get-started-with-search/suggested-searches",
1922-
"/cid/2073": "/docs/search/logcompare",
1923-
"/cid/2074": "/docs/search/logreduce/logreduce-operator",
1924-
"/cid/2075": "/docs/search/logreduce/logreduce-operator",
1922+
"/cid/2073": "/docs/search/behavior-insights/logcompare",
1923+
"/cid/2074": "/docs/search/behavior-insights/logreduce/logreduce-operator",
1924+
"/cid/2075": "/docs/search/behavior-insights/logreduce/logreduce-operator",
19251925
"/cid/2076": "/docs/get-started",
19261926
"/cid/2077": "/docs/get-started",
19271927
"/cid/2078": "/docs/search/search-query-language/search-operators/if",
@@ -2086,7 +2086,7 @@
20862086
"/cid/4412": "/docs/integrations/saas-cloud/crowdstrike-fdr-host-inventory",
20872087
"/cid/44122": "/docs/integrations/saas-cloud/crowdstrike-spotlight",
20882088
"/cid/44123": "/docs/integrations/saas-cloud/crowdstrike-falcon-filevantage",
2089-
"/cid/4020": "/docs/search/logreduce",
2089+
"/cid/4020": "/docs/search/behavior-insights/logreduce",
20902090
"/cid/4021": "/docs/search/search-query-language/search-operators/accum",
20912091
"/cid/40001": "/docs/search/search-query-language/search-operators/as",
20922092
"/cid/40002": "/docs/search/search-query-language/search-operators/asn-lookup",
@@ -2282,7 +2282,7 @@
22822282
"/cid/5134": "/docs/dashboards/panels",
22832283
"/cid/5135": "/docs/dashboards/drill-down-to-discover-root-causes",
22842284
"/cid/5136": "/docs/get-started/library",
2285-
"/cid/5138": "/docs/search/logreduce/influence-the-logreduce-outcome",
2285+
"/cid/5138": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
22862286
"/cid/5139": "/docs/send-data/collection/edit-source",
22872287
"/cid/5140": "/docs/get-started/library",
22882288
"/cid/5143": "/docs/manage/users-roles/roles/create-manage-roles",
@@ -2420,7 +2420,7 @@
24202420
"/cid/5334": "/docs/search/get-started-with-search/suggested-searches/microsoft-iis-parser",
24212421
"/cid/5335": "/docs/search",
24222422
"/cid/5336": "/docs/send-data/collection/search-for-a-collector-or-source",
2423-
"/cid/5339": "/docs/search/logreduce",
2423+
"/cid/5339": "/docs/search/behavior-insights/logreduce",
24242424
"/cid/5340": "/docs/integrations/sumo-apps/security-analytics",
24252425
"/cid/5341": "/docs/integrations/sumo-apps/security-analytics",
24262426
"/cid/5342": "/docs/alerts/webhook-connections/servicenow",
@@ -2436,7 +2436,7 @@
24362436
"/cid/5356": "/docs/dashboards/panels/modify-chart",
24372437
"/cid/5368": "/docs/dashboards/panels/single-value-charts",
24382438
"/cid/5375": "/",
2439-
"/cid/5377": "/docs/search/logreduce/understand-the-logreduce-relevance-column",
2439+
"/cid/5377": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
24402440
"/cid/5378": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/aws-cloudtrail",
24412441
"/cid/5379": "/docs/integrations/amazon-aws/elastic-load-balancing",
24422442
"/cid/5380": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/aws-cloudtrail",
@@ -2475,7 +2475,7 @@
24752475
"/cid/5444": "/docs/integrations/web-servers/varnish",
24762476
"/cid/5445": "/docs/integrations/web-servers/varnish",
24772477
"/cid/5446": "/docs/integrations/containers-orchestration/vmware-legacy",
2478-
"/cid/5448": "/docs/search/logreduce/detect-patterns-with-logreduce",
2478+
"/cid/5448": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
24792479
"/cid/5449": "/docs/integrations/containers-orchestration/vmware-legacy",
24802480
"/cid/5450": "/",
24812481
"/cid/5454": "/docs/manage/security/create-allowlist-ip-cidr-addresses",
@@ -2684,8 +2684,8 @@
26842684
"/cid/23411": "/docs/integrations/saas-cloud/sophos",
26852685
"/cid/9078": "/docs/manage/users-roles/roles/construct-search-filter-for-role",
26862686
"/cid/915200739": "/docs/observability/sdo/about-sdo",
2687-
"/cid/9201": "/docs/search/behavior-insights/logreduce-keys",
2688-
"/cid/9202": "/docs/search/behavior-insights/logreduce-values",
2687+
"/cid/9201": "/docs/search/behavior-insights/logreduce/logreduce-keys",
2688+
"/cid/9202": "/docs/search/behavior-insights/logreduce/logreduce-values",
26892689
"/cid/9205": "/docs/search/behavior-insights/logexplain",
26902690
"/cid/96734": "/docs/send-data/hosted-collectors/http-source/troubleshooting",
26912691
"/cid/97652": "/docs/integrations/saas-cloud/qualys-vmdr",
@@ -3796,9 +3796,9 @@
37963796
"/Search/Get_Started_with_Search/Search_Basics/Search_Metadata": "/docs/search/get-started-with-search/search-basics",
37973797
"/Search/Library/Apps-in-Sumo-Logic/01-Sumo-Logic-Apps/Data-Volume-App": "/docs/integrations/sumo-apps/data-volume",
37983798
"/Search/Library/Apps-in-Sumo-Logic/01-Sumo-Logic-Apps/Data-Volume-App/Data-Volume-App-Dashboards": "/docs/integrations/sumo-apps/data-volume",
3799-
"/Search/LogCompare": "/docs/search/logcompare",
3800-
"/Search/LogCompare/About_LogCompare": "/docs/search/logcompare",
3801-
"/Search/LogReduce": "/docs/search/logreduce",
3799+
"/Search/LogCompare": "/docs/search/behavior-insights/logcompare",
3800+
"/Search/LogCompare/About_LogCompare": "/docs/search/behavior-insights/logcompare",
3801+
"/Search/LogReduce": "/docs/search/behavior-insights/logreduce",
38023802
"/Query_Language": "/docs/search/search-query-language",
38033803
"/Search/Search_Query_Language": "/docs/search/search-query-language",
38043804
"/Search/Search_Query_Language/Parse_Operators/CSV_Operator": "/docs/search/search-query-language/parse-operators/parse-csv-formatted-logs",
@@ -4183,5 +4183,13 @@
41834183
"/docs/integrations/amazon-aws/aurora-mysql-ulm": "/docs/integrations/amazon-aws/rds",
41844184
"/docs/integrations/amazon-aws/aurora-postgresql-ulm": "/docs/integrations/amazon-aws/rds",
41854185
"/docs/integrations/amazon-aws/elastic-load-balancer-app": "/docs/integrations/amazon-aws/application-load-balancer",
4186-
"/docs/integrations/amazon-aws/elastic-load-balancing-classic": "/docs/integrations/amazon-aws/classic-load-balancer"
4186+
"/docs/integrations/amazon-aws/elastic-load-balancing-classic": "/docs/integrations/amazon-aws/classic-load-balancer",
4187+
"/docs/search/logcompare": "/docs/search/behavior-insights/logcompare",
4188+
"/docs/search/behavior-insights/logreduce-keys": "/docs/search/behavior-insights/logreduce/logreduce-keys",
4189+
"/docs/search/logreduce": "/docs/search/behavior-insights/logreduce",
4190+
"/docs/search/logreduce/logreduce-operator": "/docs/search/behavior-insights/logreduce/logreduce-operator",
4191+
"/docs/search/logreduce/detect-patterns-with-logreduce": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
4192+
"/docs/search/logreduce/influence-the-logreduce-outcome": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
4193+
"/docs/search/logreduce/understand-the-logreduce-relevance-column": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
4194+
"/docs/search/behavior-insights/logreduce-values": "/docs/search/behavior-insights/logreduce/logreduce-values"
41874195
}

docs/alerts/monitors/alert-response-faq.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ Sumo Logic detects and maintains a signature library. It does that by analyzing
6767

6868
There could be cases where the process has still not cataloged a new log message to a signature. As a result, it would get bundled into the "Others" category. This problem should be fixed automatically after some time (when the background process runs).
6969

70-
You can also force run the signature cataloging process manually, by calling the [LogCompare](../../search/logcompare.md) or [LogReduce](/docs/search/logreduce) operators from the Log Search page. 
70+
You can also force run the signature cataloging process manually, by calling the [LogCompare](/docs/search/behavior-insights/logcompare) or [LogReduce](/docs/search/behavior-insights/logreduce) operators from the Log Search page. 
7171

7272
## I don’t see the Dimensional Explanation card for logs-based alert
7373

docs/alerts/monitors/alert-response.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ See [Using tags in alerts](/docs/alerts/monitors/settings/#using-tags-in-alerts)
160160

161161
### Log fluctuations
162162

163-
This card detects different signatures in your log messages using [LogReduce](/docs/search/logreduce) such as errors, exceptions, timeouts, and successes. It compares log signatures trends with a normal baseline period and surfaces noteworthy changes in signatures.
163+
This card detects different signatures in your log messages using [LogReduce](/docs/search/behavior-insights/logreduce) such as errors, exceptions, timeouts, and successes. It compares log signatures trends with a normal baseline period and surfaces noteworthy changes in signatures.
164164

165165
* **New**. Log signatures that were only seen after the Alert was triggered but not one hour prior to the Alert start time.
166166
* **Gone**. Log signatures that are not present after the Alert was created but were present one hour prior to the Alert start time, such as **Transaction Succeeded** or **Success**.

docs/alerts/monitors/overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ Custom variables used inside the Action Payload.
130130
### General
131131

132132
* [Receipt Time](../../search/get-started-with-search/build-search/use-receipt-time.md) is not supported.
133-
* [LogReduce](/docs/search/logreduce/logreduce-operator) / [LogCompare](../../search/logcompare.md) operators are not supported in monitors. If your query contains these operators, you will not be able to create the monitor.
133+
* [LogReduce](/docs/search/behavior-insights/logreduce/logreduce-operator) / [LogCompare](/docs/search/behavior-insights/logcompare) operators are not supported in monitors. If your query contains these operators, you will not be able to create the monitor.
134134
* Monitors only support the [Continuous data tier](/docs/manage/partitions/data-tiers).
135135
* An aggregate Metric Monitor can evaluate up to 15,000 time series. A non-aggregate Metric Monitor can evaluate up to 3,000 time series.
136136
* [Save to Index](../scheduled-searches/save-to-index.md) and [Save to Lookup](../scheduled-searches/save-to-lookup.md) are not supported.

docs/contributing/glossary.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -174,9 +174,9 @@ We also maintain a [DevOps and Security Glossary](https://www.sumologic.com/glos
174174

175175
**[Local Configuration File Management](/docs/send-data/use-json-configure-sources/local-configuration-file-management)**. Local Configuration File Management allows you to set up and manage Sources on an Installed Collector using one or more JSON files.
176176

177-
**[LogCompare](/docs/search/logcompare)**. LogCompare allows you to compare a section of your log messages from one point in time with the same section at another point in time, and display the changes in patterns.
177+
**[LogCompare](/docs/search/behavior-insights/logcompare)**. LogCompare allows you to compare a section of your log messages from one point in time with the same section at another point in time, and display the changes in patterns.
178178

179-
**[LogReduce](/docs/search/logreduce)**. LogReduce uses fuzzy logic to cluster messages together based on string and pattern similarity. Use the LogReduce button and operator to quickly assess activity patterns for things like a range of devices or traffic on a website.
179+
**[LogReduce](/docs/search/behavior-insights/logreduce)**. LogReduce uses fuzzy logic to cluster messages together based on string and pattern similarity. Use the LogReduce button and operator to quickly assess activity patterns for things like a range of devices or traffic on a website.
180180

181181
**[Logs-to-Metrics](/docs/metrics/logs-to-metrics)**. A Sumo Logic feature you can use to extract or create metrics from log data. You can extract metrics that are embedded in logs, or count logs as a metric.
182182

0 commit comments

Comments
 (0)