Appearance
Log Patterns
Thousands of log lines are usually a few dozen messages with different numbers in them. Patterns groups them, so instead of scrolling you see:
~5,221 payment declined for order * (card ending *) error
~3,441 worker * picked up job * after * debugOpen Explore on a logs or events Stream and switch the list to Patterns. It follows the search and time range above it.
Reading a pattern
- The template: the fixed words, with the parts that vary shown as
*. Numbers, IDs, UUIDs, IP addresses, URLs, emails and timestamps always vary. - Volume: roughly how many matching lines were in the whole range, and its share of them.
- Severity: the levels its lines were logged at.
- Trend: how its volume moved across the range, so a pattern that just started (or just stopped) stands out.
- Examples: a few real lines. Click a pattern to see them.
Acting on a pattern
| Search | Show exactly the lines in this pattern. |
| Exclude | Hide this pattern from the search, to find what's left. |
| Create Monitor | Alert when this pattern's volume crosses a threshold. See Telemetry Monitors. |
Tuning
Patterns are found in a sample of the lines matching your search (5,000 by default, up to 20,000), drawn from across the whole time range rather than just the newest lines, so a burst at the end can't hide what happened earlier. Each part of the range counts for its real volume, which is how the estimates and trends are worked out. Merge decides how alike lines must be to share a pattern: lower merges more.
API
POST /v1/telemetry/patterns with the Stream, signal (logs or events), time range and search returns the patterns with their counts, estimated volume, levels, trend and examples.