Skip to content

Commit deb61d4

Browse files
committed
Real-time sched search deprecation
1 parent 21f6c03 commit deb61d4

File tree

5 files changed

+34
-23
lines changed

5 files changed

+34
-23
lines changed

docs/alerts/difference-from-scheduled-searches.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ Scheduled Searches address two primary use cases:
1616

1717
## Monitors
1818

19-
Monitors are specifically designed for the first use case: alerting. They offer additional capabilities such as auto-resolution and support for multiple notification channels. Any Scheduled Searches created for alerting purposes can be moved to Monitors, including [real-time Scheduled Searches](/docs/alerts/scheduled-searches/create-real-time-alert).
19+
Monitors are specifically designed for the first use case: alerting. They offer additional capabilities such as auto-resolution and support for multiple notification channels. Any Scheduled Searches created for alerting purposes can be moved to Monitors.
2020

2121
## Feature differences
2222

docs/alerts/scheduled-searches/create-real-time-alert.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
---
22
id: create-real-time-alert
3-
title: Create a Scheduled Search Real-Time Alert
3+
title: Manage Real-Time Scheduled Search Alerts (Deprecated)
44
description: Real-time alerts notify you of error conditions right when they occur.
55
---
66

77
:::warning Solution Deprecated
8-
The ability to create new real-time alert scheduled searches has been deprecated. While you can no longer create new real-time alerts, existing real-time alerts will continue to function as before. [Learn more](/docs/alerts/scheduled-searches/deprecation).
8+
Real-Time Scheduled Searches will be deprecated on May 15, 2025. Existing searches will be automatically converted to [15-minute scheduled search frequency windows](/docs/alerts/scheduled-searches/schedule-search/#step-2-set-run-frequency) unless your account was explicitly excluded. If you need real-time alerts, we recommend transitioning to [Monitors](/docs/alerts/monitors/overview).
99
:::
1010

1111
Real-time alerts are scheduled searches that run nearly continuously. This means that you're informed in real time when error conditions exist.

docs/alerts/scheduled-searches/deprecation.md

Lines changed: 28 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -3,34 +3,45 @@ id: deprecation
33
title: Deprecation of Real-Time Scheduled Searches
44
---
55

6-
As part of our ongoing evaluation of the Sumo Logic service, we have decided to deprecate [Real-Time Scheduled Searches](/docs/alerts/scheduled-searches/create-real-time-alert). In particular, we will remove the option to create new Real-Time Scheduled Searches on **May 29, 2024**. Existing Real-Time Scheduled Searches will continue to function until **May 15, 2025**. We believe many use cases for Real-Time Scheduled Searches can be met by [Monitors](/docs/alerts/monitors/overview). Any remaining use cases can be met by executing these searches at 15m intervals. These options are discussed below.
6+
:::warning Deprecation Notice
7+
Real-Time Scheduled Searches will be deprecated on **May 15, 2025**. As of **May 29, 2024**, creating new Real-Time Scheduled Searches is no longer supported. Existing Real-Time Searches will continue to function until the deprecation date, at which point they will automatically convert to 15-minute schedules. See below for full details.
8+
:::
79

8-
In 2020, Sumo Logic released Monitors, which provided a new framework to trigger alerts on both metrics and log data in real time and send notifications. Real-Time Scheduled Searches provided a much more limited version of this functionality, but has continued to exist in the Sumo Logic Platform.
10+
As part of our ongoing platform improvements, we are deprecating [Real-Time Scheduled Searches](/docs/alerts/scheduled-searches/create-real-time-alert). While this functionality has supported real-time alerting for many years, our modern alerting framework, [Monitors](/docs/alerts/monitors/overview), offers a more powerful and flexible experience for real-time and scheduled alerts.
911

10-
## Why is this happening?
11-
12-
Monitors provide the same functionality as a Real-Time Scheduled Search, but offer a number of additional features and significant enhancements such as:
12+
## Deprecation timeline
1313

14-
* [Multiple Trigger Conditions](/docs/alerts/monitors/create-monitor/#step-1-set-trigger-conditions) (Critical, Warning, Missing Data)
15-
* [Alert Grouping](/docs/alerts/monitors/alert-grouping/)
16-
* [Playbook Support](/docs/alerts/monitors/alert-response/#alert-details)
17-
* [Integration into our Alert Response Page](/docs/alerts/monitors/alert-response/)
18-
* [AI-Driven Alerting](/release-notes-service/2024/12/31/#march-12-2024-alerts)
14+
| Date | Change |
15+
|:-----|:-------|
16+
| **May 29, 2024** | Creation of new Real-Time Scheduled Searches was disabled across all Sumo Logic accounts |
17+
| **May 15, 2025** | All remaining Real-Time Searches will automatically convert to 15-minute schedules (except for a small number of customers with exceptions). Each conversion will be recorded via audit log. Real-Time frequency will no longer be editable. |
1918

20-
Furthermore, Monitors will continue to be the focus area for our Product and Engineering Teams for features and enhancements regarding alerting.
19+
## Why is this happening?
2120

22-
## What is happening?
21+
[Monitors](/docs/alerts/monitors/overview) support real-time alerting on both logs and metrics, and offer significant advantages over Scheduled Searches, including:
2322

24-
After **May 29, 2024**, it will no longer be possible to create a new Scheduled Search with a frequency of Real-Time. We recommend you create a Monitor to address this use case. Note that this does not have any effect on the creation of new Scheduled Searches with other frequencies of 15 Minutes, Hourly, Daily, Weekly, or a specific Cron schedule for example.
23+
* [Multiple trigger conditions](/docs/alerts/monitors/create-monitor/#step-1-set-trigger-conditions) (Critical, Warning, Missing Data)
24+
* [Alert grouping](/docs/alerts/monitors/alert-grouping/)
25+
* [Playbook support](/docs/alerts/monitors/alert-response/#alert-details)
26+
* [AI-driven alerting](/release-notes-service/2024/12/31/#march-12-2024-alerts)
27+
* [Integration with the Alert Response page](/docs/alerts/monitors/alert-response/)
2528

26-
Real-Time Scheduled Searches that were created up until **May 29, 2024** will continue to function without any interruption for 1 year until **May 15, 2025**, and any edits to those schedules will still be supported until the next year. Please note, however, that if the frequency of an existing Real-Time Scheduled search is modified to a different parameter, it will not be able to be changed back to Real-Time.
29+
Monitors are the primary focus for our Product and Engineering Teams for alerting features and enhancements.
2730

2831
## What do I need to do?
2932

30-
Before **May 15, 2025**, please migrate any Real-Time Scheduled Searches to either Monitors or reduce their frequency to the minimum of 15m or another suitable time range. Any Real-Time Scheduled Searches that remain after the deprecation date will automatically be converted to 15m schedules. For each automatic conversion, there will be a corresponding audit log for this activity written to your Sumo Logic instance.
33+
Before **May 15, 2025**, we recommend:
34+
35+
* If you need real-time alerting, recreate your Real-Time Scheduled Searches as [Monitors](/docs/alerts/monitors/overview).
36+
:::note Can I import a Scheduled Search into a Monitor?
37+
No. Scheduled Searches and Monitors use different JSON structures. You’ll need to recreate the search logic manually in the [Monitor creation UI](/docs/alerts/monitors/create-monitor/).
38+
:::
39+
* If real-time execution isn’t required, you can manually update your Scheduled Search to run every 15 minutes or longer.
3140

32-
### Can I import a scheduled search into a monitor?
41+
After the deprecation date, all remaining Real-Time Scheduled Searches will be automatically updated to run at 15-minute intervals. An audit log entry will be generated for each conversion.
3342

34-
No. Because the JSON formatting of Scheduled Searches differs from monitors, you'll need to create a monitor manually from the Search UI for your real-time use cases.
43+
:::note
44+
If you edit an existing Real-Time Scheduled Search and change the frequency, you will not be able to revert it back to Real-Time.
45+
:::
3546

3647
If you have any questions, please reach out to your account team or open a [Support ticket](https://support.sumologic.com/support/s/).

docs/alerts/scheduled-searches/index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,8 @@ A _Scheduled Search_ is a standard [Log Search](/docs/search) that you save and
2323
</div>
2424
<div className="box smallbox card">
2525
<div className="container">
26-
<a href="/docs/alerts/scheduled-searches/create-real-time-alert"><img src={useBaseUrl('img/icons/general/calendar.png')} alt="icon" width="40"/><h4>Create a Scheduled Search Real-Time Alert</h4></a>
27-
<p>Learn how to create an alert to get notified in real-time when error conditions exist.</p>
26+
<a href="/docs/alerts/scheduled-searches/create-real-time-alert"><img src={useBaseUrl('img/icons/general/calendar.png')} alt="icon" width="40"/><h4>Manage Real-Time Scheduled Search Alerts (Deprecated) </h4></a>
27+
<p>Learn how to manage existing alerts to get notified in real-time when error conditions exist.</p>
2828
</div>
2929
</div>
3030
<div className="box smallbox card">

docs/search/subqueries.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ In a subquery, the parent query contains the main body of the query while the c
1515
* **Parent query**. Depends on the input from a child query or queries to finish its execution.
1616

1717
:::note Limitations
18-
Subqueries are not supported in auto refresh dashboards, real-time Scheduled Searches, Field Extraction Rules, and Scheduled Views.
18+
Subqueries are not supported in auto refresh dashboards, Field Extraction Rules, and Scheduled Views.
1919
:::
2020

2121
## Syntax

0 commit comments

Comments
 (0)