<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Logs Troubleshooting Map in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/ta-p/302260</link>
    <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H2&gt;Logs Troubleshooting Map&lt;/H2&gt;
&lt;DIV&gt;
&lt;DIV class="my0ZUv6nH8oejAX131NWgg== oVethiVm5MuNiCg8jf1KhA==" data-line-index="6"&gt;
&lt;DIV class="my0ZUv6nH8oejAX131NWgg== oVethiVm5MuNiCg8jf1KhA==" data-line-index="6"&gt;
&lt;DIV class="my0ZUv6nH8oejAX131NWgg== oVethiVm5MuNiCg8jf1KhA==" data-line-index="20"&gt;
&lt;DIV&gt;
&lt;P&gt;A decision-tree guide for troubleshooting log ingestion, source health, delays, volume, parsing, correlation, and alerting issues in Dynatrace.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;First time here?&lt;/STRONG&gt; Find your symptom in the table below and jump directly to the right section. No need to read top to bottom.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;H2 class="text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr" data-sourcepos="13:1-13:23;674-696"&gt;How to use this map&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Find your symptom&lt;/H3&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;What you are seeing&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Go to&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Logs that worked before have suddenly stopped&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-1a" target="_blank" rel="noopener noreferrer"&gt;Step 1A&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;A source has never appeared in Dynatrace&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-1b" target="_blank" rel="noopener noreferrer"&gt;Step 1B&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;A source is visible but not ingesting records&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-1c" target="_blank" rel="noopener noreferrer"&gt;Step 1C&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Log Monitoring is enabled but still no logs&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-1d" target="_blank" rel="noopener noreferrer"&gt;Step 1D&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;One ingestion method is affected (API, K8s, Azure, etc.)&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-2" target="_blank" rel="noopener noreferrer"&gt;Step 2&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Logs arrive late or only partially&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-3" target="_blank" rel="noopener noreferrer"&gt;Step 3&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Log volume increased or decreased unexpectedly&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-4" target="_blank" rel="noopener noreferrer"&gt;Step 4&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Logs are visible but content, attributes, or timestamps are wrong&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-5" target="_blank" rel="noopener noreferrer"&gt;Step 5&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;A log metric or event is not triggering&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-6" target="_blank" rel="noopener noreferrer"&gt;Step 6&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Trace link missing from a log record&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-7" target="_blank" rel="noopener noreferrer"&gt;Step 7&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Dynatrace Managed cluster shows a log warning&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://assistant.d1.dynatrace.com/assistant#step-8" target="_blank" rel="noopener noreferrer"&gt;Step 8&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 1A&amp;nbsp; Logs that previously worked have stopped&amp;nbsp;&lt;/H2&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Start here first:&lt;/STRONG&gt; Open &lt;STRONG&gt;Dashboards → Log module self-monitoring&lt;/STRONG&gt; and check the &lt;STRONG&gt;Currently active issues&lt;/STRONG&gt; panel. The platform may have already identified the cause via a self-monitoring event (SFM event). Act on that before changing any configuration.&lt;/P&gt;
&lt;P&gt;SFM events are available at &lt;STRONG&gt;OneAgent 1.339+ / SaaS 1.340+&lt;/STRONG&gt;. Earlier versions require opt-in via the Settings API see &lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/logs/lma-log-ingestion/lma-log-ingestion-via-oa/lma-log-agent-sfm" target="_blank" rel="noopener noreferrer"&gt;Monitor log source health with SFM events&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/My-logs-went-silent-where-do-I-start/ta-p/303793" target="_blank" rel="noopener noreferrer"&gt;My logs went silent&amp;nbsp; where do I start?&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Covers: OneAgent Log Module unhealthy · Kubernetes Log Module unhealthy · ActiveGate health issue · SFM event reference · source coverage check · module restart behaviour&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 1B&amp;nbsp; Source has never appeared in Dynatrace&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-missing-logs-in-Log-module/ta-p/300209" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting missing logs in Log module&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Covers: path and permission checks · security rules · custom source configuration · SFM &lt;CODE&gt;log_source.status&lt;/CODE&gt; query · global Log Monitoring toggle · &lt;CODE&gt;app log content access&lt;/CODE&gt; flag&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 1C&amp;nbsp; Source is visible but not ingesting records&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Log-source-not-detected-or-not-ingested-Troubleshoot-source/ta-p/303792" target="_blank" rel="noopener noreferrer"&gt;Log source not detected or not ingested: Troubleshoot source discovery and ingest-rule coverage&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Covers: Sources tab · ingest-rule coverage · matcher vs source name · active and inherited rule review · unique-record validation&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 1D&amp;nbsp; Log Monitoring is enabled but logs are still missing&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Work through these in order:&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Situation&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Initial setup&amp;nbsp; never produced records on this host&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Enable-Log-Visibility-in-Dynatrace/ta-p/242716" target="_blank" rel="noopener noreferrer"&gt;Enable Log Visibility in Dynatrace&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Enabled and monitored but records aren't visible&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Why-are-logs-still-missing-after-enabling-Log-monitoring/ta-p/296402" target="_blank" rel="noopener noreferrer"&gt;Why are logs still missing after enabling Log Monitoring?&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Security rules may be blocking the path&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Missing-Log-Files-Due-to-OneAgent-Log-Monitoring/ta-p/302252" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting Missing Log Files Due to OneAgent Log Monitoring Security Rules&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Server-side prerequisites (Logs Classic)&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/What-might-prevent-logs-from-appearing-on-the-server/ta-p/231456" target="_blank" rel="noopener noreferrer"&gt;What might prevent logs from appearing on the server?&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;F5 Distributed Cloud WAAP intercepting communication&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Logs-Not-Being-Ingested-Due-to-F5-Distributed-Cloud-WAAP/ta-p/302352" target="_blank" rel="noopener noreferrer"&gt;Logs Not Being Ingested Due to F5 Distributed Cloud WAAP&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 2&amp;nbsp; One ingestion method is affected&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Select the ingestion method:&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Method&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;OneAgent&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Use Steps 1A–1D above&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;REST API&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-log-Ingestion-via-API-POST-ingest-logs/ta-p/286608" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting Log Ingestion via API&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Ingest source with static enrichment&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-for-Ingest-sources-that-send-data-along-static/ta-p/303479" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting for Ingest sources that send data along static enrichment&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Fluent Bit&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-logs-ingested-via-Fluent-Bit/ta-p/283718" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting Logs Ingested via Fluent Bit&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;FluentD&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Multi-Language-Log-Ingest-for-Dynatrace-via-FluentD/ta-p/268157" target="_blank" rel="noopener noreferrer"&gt;Multi-Language Log Ingest for Dynatrace via FluentD&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Kubernetes / OpenShift&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Kubernetes-logs-in-Log-module/ta-p/300204" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting Kubernetes logs in Log module&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;·&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Logs-Ingest-on-K8s-with-Dynatrace/ta-p/285827" target="_blank" rel="noopener noreferrer"&gt;Logs Ingest on Kubernetes with Dynatrace&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Azure Log Forwarder&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Azure-Log-Forwarder-Troubleshooting/ta-p/243797" target="_blank" rel="noopener noreferrer"&gt;Azure Log Forwarder Troubleshooting&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Azure Native Integration&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Fixing-Missing-Azure-Resource-Logs-Troubleshooting-Guide-for/ta-p/285463" target="_blank" rel="noopener noreferrer"&gt;Fixing Missing Azure Resource Logs: Azure Native Integration&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Azure cross-tenant subscription&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/How-can-I-get-logs-from-an-Azure-subscription-in-another-Azure/ta-p/229424" target="_blank" rel="noopener noreferrer"&gt;How can I get logs from an Azure subscription in another Azure tenant?&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Google Cloud&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Google-Cloud-Monitor-Troubleshooting/ta-p/243796" target="_blank" rel="noopener noreferrer"&gt;Google Cloud Monitor Troubleshooting&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Syslog general&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Syslog-Ingestion-Troubleshooting/ta-p/264112" target="_blank" rel="noopener noreferrer"&gt;Syslog Ingestion Troubleshooting&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Syslog&amp;nbsp; via ActiveGate&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Syslog-Ingestion-via-ActiveGate-Troubleshooting-Guide/ta-p/282718" target="_blank" rel="noopener noreferrer"&gt;Syslog Ingestion via ActiveGate Troubleshooting Guide&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Syslog&amp;nbsp; non-standard format&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Syslog-Ingestion-When-Standards-Aren-t-Strictly/ta-p/288555" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting Syslog Ingestion When Standards Aren't Strictly Followed&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;OpenTelemetry&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://docs.dynatrace.com/docs/ingest-from/opentelemetry/collector/resiliency" target="_blank" rel="noopener noreferrer"&gt;OpenTelemetry Collector resiliency&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;ActiveGate extension&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Logs-Not-Arriving-from-ActiveGate-Extensions-Log/ta-p/298979" target="_blank" rel="noopener noreferrer"&gt;Logs Not Arriving from ActiveGate Extensions: Log Persistence Full&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 3 Logs are delayed or only partially arriving&amp;nbsp;&lt;/H2&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Situation&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Records arrive late (including expected ~90s Kubernetes baseline)&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-log-ingest-delay-in-Log-module/ta-p/300190" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting log ingest delay in Log module&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ingest endpoint returns&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;HTTP 429&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Dynatrace-does-not-ingest-logs-HTTP-429/ta-p/230512" target="_blank" rel="noopener noreferrer"&gt;Dynatrace does not ingest logs: HTTP 429&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ActiveGate extension buffer or persistence full&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Logs-Not-Arriving-from-ActiveGate-Extensions-Log/ta-p/298979" target="_blank" rel="noopener noreferrer"&gt;Logs Not Arriving from ActiveGate Extensions: Log Persistence Full&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Multiple sources via one ActiveGate affected&lt;/TD&gt;
&lt;TD&gt;Check&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Ingest components health&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in Log module self-monitoring dashboard →&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.dynatrace.com/docs/ingest-from/setup-on-k8s/guides/deployment-and-configuration/resource-management/ag-resource-limits" target="_blank" rel="noopener noreferrer"&gt;ActiveGate sizing for Kubernetes&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 4 Log volume changed unexpectedly&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Both volume spikes and drops use the same starting article.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-Log-volume-spiked-suddenly-where-is-it-coming/ta-p/303794" target="_blank" rel="noopener noreferrer"&gt;Log volume spiked overnight where is it coming from?&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Covers: Top log producers · OpenPipeline self-monitoring metrics · ingest-rule scope review · volume decrease investigation · preventive alerting&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 5 Logs are visible but incorrect&amp;nbsp;&lt;/H2&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Symptom&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;JSON stays in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;content&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;expected attributes not extracted&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-JSON-parsing-in-Log-module/ta-p/300189" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting JSON parsing in Log module&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Multiline records split incorrectly&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-log-boundary-detection-in-Log-module/ta-p/300208" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting log boundary detection in Log module&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Gaps, duplicates, or missing records after rotation&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-log-rotation-issues-in-Log-Module/ta-p/300207" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting log rotation issues in Log Module&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Content trimmed · attributes missing · timestamp corrected (&lt;CODE&gt;dt.ingest.warnings&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;present)&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/What-do-log-ingest-warnings-on-my-records-mean-dt-ingest/ta-p/303795" target="_blank" rel="noopener noreferrer"&gt;What do log ingest warnings on my records mean?&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ingest source sends static enrichment attributes missing or wrong&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Troubleshooting-for-Ingest-sources-that-send-data-along-static/ta-p/303479" target="_blank" rel="noopener noreferrer"&gt;Troubleshooting for Ingest sources that send data along static enrichment&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Records don't look right in general&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Why-don-t-ingested-logs-look-as-expected/ta-p/230262" target="_blank" rel="noopener noreferrer"&gt;Why don't ingested logs look as expected?&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Attribute key case mismatch warning&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/I-get-an-ingest-warning-about-an-attribute-key-case-mismatch/ta-p/251188" target="_blank" rel="noopener noreferrer"&gt;Ingest warning about an attribute-key case mismatch&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;·&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/How-to-enable-the-attribute-key-mismatch-feature/ta-p/250221" target="_blank" rel="noopener noreferrer"&gt;How to enable the attribute-key mismatch feature&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Case-sensitive query warning (Logs Classic)&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/I-get-a-warning-in-the-Log-Viewer-about-case-sensitive-queries/ta-p/250222" target="_blank" rel="noopener noreferrer"&gt;Case-sensitive query warning in Logs Classic&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Records out of order or under the wrong timestamp&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Timestamps-in-Logs-with-OneAgent-1-313/ta-p/281611" target="_blank" rel="noopener noreferrer"&gt;Timestamps in Logs with OneAgent 1.313+&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;High resource use from log enrichment component&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/High-resource-overhead-issue-related-to-the-Dynatrace-Log/ta-p/268817" target="_blank" rel="noopener noreferrer"&gt;High Resource Overhead from the Log Enrichment Component&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Quick check before parsing investigation:&lt;/STRONG&gt; Run &lt;CODE&gt;fetch logs | filter isNotNull(dt.ingest.warnings) | summarize count(), by:{dt.ingest.warnings, log.source} | limit 100&lt;/CODE&gt;&amp;nbsp; if warnings are present, start with the ingest warnings article, not the parsing article.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 6 Log metric or event is not triggering&amp;nbsp;&lt;/H2&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Situation&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Log-based metric shows no data&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Dynatrace-Log-Monitoring-Metric-Shows-No-Data/ta-p/290822" target="_blank" rel="noopener noreferrer"&gt;Dynatrace Log Monitoring: Metric Shows No Data&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Problem opens against the wrong entity&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/How-to-change-impacted-entity-for-log-based-event-problem/ta-p/274167" target="_blank" rel="noopener noreferrer"&gt;How to Change Impacted Entity for a Log-Based Event or Problem&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 7&amp;nbsp; Trace link missing from a log record&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Why-I-can-t-see-traces-in-Log-view-page-Logs-connected-to-traces/ta-p/209281" target="_blank" rel="noopener noreferrer"&gt;Why I Can't See Traces in Log View Page&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Step 8&amp;nbsp; Dynatrace Managed cluster warnings&amp;nbsp;&lt;/H2&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;Warning message&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;Article&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;Log ingest queue is full&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/quot-Log-ingest-queue-is-full-quot-message-in-Dynatrace-Managed/ta-p/232441" target="_blank" rel="noopener noreferrer"&gt;Log Ingest Queue Is Full: Dynatrace Managed&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;Ingested log data is trimmed&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/quot-Ingested-log-data-is-trimmed-quot-message-in-Dynatrace-Managed/ta-p/230269" target="_blank" rel="noopener noreferrer"&gt;Ingested Log Data Is Trimmed: Dynatrace Managed&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Before contacting Support&lt;/H2&gt;
&lt;P&gt;Collect the following before opening a ticket:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When the issue started and the timezone used&lt;/LI&gt;
&lt;LI&gt;Affected host, host group, cluster, namespace, workload, or source path&lt;/LI&gt;
&lt;LI&gt;Screenshot from the &lt;STRONG&gt;Log module self-monitoring&lt;/STRONG&gt; dashboard&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Currently active issues&lt;/STRONG&gt; panel&lt;/LI&gt;
&lt;LI&gt;SFM event type, severity, and any source or entity context&lt;/LI&gt;
&lt;LI&gt;Source coverage state from the &lt;STRONG&gt;Sources&lt;/STRONG&gt; tab&lt;/LI&gt;
&lt;LI&gt;Active and inherited ingest rules with matchers and scopes&lt;/LI&gt;
&lt;LI&gt;Sanitised sample record and result of a unique-record search&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;dt.ingest.warnings&lt;/CODE&gt; DQL result (if records are visible but incorrect)&lt;/LI&gt;
&lt;LI&gt;Recent changes&amp;nbsp; application, permissions, deployment, or Dynatrace configuration&lt;/LI&gt;
&lt;LI&gt;OneAgent, ActiveGate, Operator, or collector version&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Do not include credentials, access tokens, personal data, or unmasked log content.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H2&gt;Further Reading&lt;/H2&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/logs/lma-log-ingestion/lma-log-ingestion-via-oa/lma-log-agent-sfm" target="_blank" rel="noopener noreferrer"&gt;Monitor log source health with SFM events&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/logs/lma-troubleshooting/lma-ingest-warnings" target="_blank" rel="noopener noreferrer"&gt;Log ingestion warnings reference&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/docs/platform/openpipeline/reference/self-monitoring-metrics" target="_blank" rel="noopener noreferrer"&gt;OpenPipeline self-monitoring metrics&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.dynatrace.com/news/blog/modern-log-management-resilience-and-self-service-upgrades-for-log-ingestion/" target="_blank" rel="noopener noreferrer"&gt;Improve log ingest health with smarter log management&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 09 Sep 2026 10:50:21 GMT</pubDate>
    <dc:creator>noel_david</dc:creator>
    <dc:date>2026-09-09T10:50:21Z</dc:date>
    <item>
      <title>Logs Troubleshooting Map</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/ta-p/302260</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Short description of which part of the Dynatrace platform the article refers to and what kind of problem it will help resolve/ task it will describe.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Problem&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Provide a precise description of the problem/ task to be described. Use anonymized screenshots, and include text for&amp;nbsp;important messages, errors, or information that will help the customer find this article when searching.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Troubleshooting steps&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted as necessary.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what troubleshooting steps should be taken to ensure the problem matches this article.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Resolution&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted for articles that guide customers on ticket creation.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain the solution or all possible solutions resulting from the troubleshooting steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section. Customers need a way to respond or follow up if they have questions.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what to do if the article did not help.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Note that there are multiple options available, including:&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Opening a support ticket&lt;/STRONG&gt; - be as specific as possible about the information the customer should include in the ticket.&amp;nbsp;&lt;/EM&gt; If this article did not help, please open a support ticket, mention that this article was used and provide the following in the ticket:
&lt;UL&gt;
&lt;LI&gt;link to XYZ&lt;/LI&gt;
&lt;LI&gt;screenshot of XYZ&lt;/LI&gt;
&lt;LI&gt;information about XYZ&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Suggesting Product Idea&lt;/STRONG&gt; - encourage the customer to suggest/ vote for a Product Idea explaining their business use case.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Explain this will change in the future&lt;/STRONG&gt; - explain that this behaviour will change in a future release. (No product idea / support ticket needed)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Alternatives -&lt;/STRONG&gt;&amp;nbsp;any other actions or links to other articles that could move the customer forward.&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*If it exists, link this article to the relevant troubleshooting map using the following guideline&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;More articles can be found on the &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/" target="_self"&gt;XXX Troubleshooting Map&lt;/A&gt;&lt;/H3&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 09 Sep 2026 10:50:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/ta-p/302260</guid>
      <dc:creator>noel_david</dc:creator>
      <dc:date>2026-09-09T10:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Troubleshooting Map</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/tac-p/302548#M1169</link>
      <description>&lt;P&gt;Hi, nice summary, thank you!&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.dynatrace.com/html/@9BD876A77FEF3D5EF4BC972CF8A97CB1/images/emoticons/take_my_money.png" alt=":take_my_money:" title=":take_my_money:" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 11:38:20 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/tac-p/302548#M1169</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-07-29T11:38:20Z</dc:date>
    </item>
  </channel>
</rss>

