<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article My logs went silent ,where do I start? in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/My-logs-went-silent-where-do-I-start/ta-p/303793</link>
    <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;A structured first-response workflow for when logs that previously worked suddenly stop. Covers component health, SFM events, source verification, ingest-rule coverage, and ActiveGate scope checks.&lt;/P&gt;
&lt;H2&gt;Problem&lt;/H2&gt;
&lt;P&gt;Use this article when logs from a source that previously worked have suddenly stopped arriving in Dynatrace.&lt;/P&gt;
&lt;P&gt;This is a first-response workflow. It does not cover logs that were never visible if the source has never appeared in Dynatrace, start with &lt;A href="https://community.dynatrace.com/t5/tkb/workflowpage/tkb-id/troubleshooting/article-id/1187?prePageCrumb=TkbDashboardPage" target="_blank" rel="noopener noreferrer"&gt;Log source not detected or not ingested: Troubleshoot source discovery and ingest-rule coverage&lt;/A&gt; instead.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Availability note:&lt;/STRONG&gt; The Log module self-monitoring dashboard and SFM events are generally available at &lt;STRONG&gt;OneAgent version 1.339+&lt;/STRONG&gt; and &lt;STRONG&gt;SaaS version 1.340+&lt;/STRONG&gt;. For earlier versions, SFM events require opt-in via the Settings API (&lt;CODE&gt;builtin:logmonitoring.log-sfm-settings&lt;/CODE&gt;). Log Monitoring Classic customers can also opt in. Verify availability for the affected environment before following this workflow.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Troubleshooting steps&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Check the source first.&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the original log file, container output, or upstream system.&lt;/LI&gt;
&lt;LI&gt;Confirm it contains records written after the issue started.&lt;/LI&gt;
&lt;LI&gt;Record the exact source timestamp and timezone of a recent record.&lt;/LI&gt;
&lt;LI&gt;Check whether any of the following changed recently:
&lt;UL&gt;
&lt;LI&gt;File path, file name, or log destination&lt;/LI&gt;
&lt;LI&gt;Application logging configuration&lt;/LI&gt;
&lt;LI&gt;File ownership, permissions, or mount/volume configuration&lt;/LI&gt;
&lt;LI&gt;Encoding, compression, or rotation behaviour&lt;/LI&gt;
&lt;LI&gt;Timestamp format or timezone&lt;/LI&gt;
&lt;LI&gt;Host, container identity, or Kubernetes workload&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If the source itself has stopped writing records, the issue is in the application or logging framework investigate that first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 1: Open the Log module self-monitoring dashboard&lt;/H3&gt;
&lt;P&gt;The &lt;STRONG&gt;Log module self-monitoring&lt;/STRONG&gt; dashboard is the fastest way to see whether Dynatrace has already detected the problem and raised an event.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; From Dynatrace version 1.342+, SFM event tiles will be built into the &lt;STRONG&gt;Log ingest overview&lt;/STRONG&gt; dashboard. Until then, import the dashboard manually&amp;nbsp; see &lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/logs/lma-log-ingestion/lma-log-ingestion-via-oa/lma-log-agent-sfm" target="_blank" rel="noopener noreferrer"&gt;Monitor log source health with SFM events&lt;/A&gt; for the JSON import instructions.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;On the dashboard, look at:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Currently active issues (24 hours)&lt;/STRONG&gt;&amp;nbsp; grouped by severity (&lt;CODE&gt;ERROR&lt;/CODE&gt;, &lt;CODE&gt;WARN&lt;/CODE&gt;, &lt;CODE&gt;INFO&lt;/CODE&gt;) and event type&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Active issues – host-based log modules&lt;/STRONG&gt;&amp;nbsp; start time, event type, affected file path, host, and process entity&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Active issues – Kubernetes log modules&lt;/STRONG&gt;&amp;nbsp;affected container or Kubernetes entity&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If an event is listed for the affected source or host, go to &lt;STRONG&gt;Step 2&lt;/STRONG&gt; to act on it.&lt;/P&gt;
&lt;P&gt;If no event is listed, go to &lt;STRONG&gt;Step 4&lt;/STRONG&gt;.&lt;/P&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 2: Read the SFM event and match it to the remediation below&lt;/H3&gt;
&lt;P&gt;SFM events are stored in Grail. To retrieve them directly:&lt;/P&gt;
&lt;DIV class="dutmcw0"&gt;
&lt;DIV class="dutmcw1"&gt;
&lt;DIV class="_1bzvwaf5q-3-9-0 _1bzvwaf6e-3-9-0 _1bzvwaf2-3-9-0 _1bzvwaf79-3-9-0" data-dt-component="Grid"&gt;
&lt;DIV class="strato-button-label _10kgnsa9-3-9-0 _10kgnsab-3-9-0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;PRE class="dutmcw2"&gt;&lt;CODE&gt;fetch dt.system.events
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;Filter by the affected entity or log source as needed.&lt;/P&gt;
&lt;P&gt;Each event includes context: the affected log source path or host ID, and a condition type. Act only on the condition the event actually reports&amp;nbsp; do not assume a common cause without reading it.&lt;/P&gt;
&lt;H3&gt;SFM event quick-reference&lt;/H3&gt;
&lt;H4&gt;Source status (&lt;CODE&gt;log_source.status&lt;/CODE&gt;&amp;nbsp;INFO)&lt;/H4&gt;
&lt;P&gt;Generated for every known log source. Use &lt;CODE&gt;log.source.file_status&lt;/CODE&gt; and &lt;CODE&gt;log.source.ingest_status&lt;/CODE&gt; to decide what to do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;&lt;CODE&gt;file_status&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;value&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Action&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;OK&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;File is accessible check&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;ingest_status&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and ingest rules&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;Not Exist&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(custom source only)&lt;/TD&gt;
&lt;TD&gt;Check the file path pattern for typos; verify the Log module filesystem access; check&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtuser&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(Linux) or OneAgent service account (Windows) permissions&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;Binary&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;Check for binary content in matched files; adjust the custom log source pattern or enable&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allow binary files&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;if binary content is intentional&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;Sensitive Masking Timeout&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;ingest.masking_timeout&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;below&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;If &lt;CODE&gt;ingest_status&lt;/CODE&gt; is not as expected, review the active and inherited ingest rules:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Rules are evaluated top-to-bottom; the first match wins&lt;/LI&gt;
&lt;LI&gt;The effective rule list concatenates rules from all configuration scopes&lt;/LI&gt;
&lt;LI&gt;The log source &lt;STRONG&gt;matcher&lt;/STRONG&gt; matches the log source &lt;STRONG&gt;name&lt;/STRONG&gt;, not the file path (e.g. &lt;CODE&gt;/path/a.2026.log&lt;/CODE&gt; does not match a source named &lt;CODE&gt;/path/a.#.log&lt;/CODE&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Timestamp events&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Event type&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Severity&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Action&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;timestamp.no_pattern&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;WARNING&lt;/TD&gt;
&lt;TD&gt;Configure a non-standard timestamp format in log monitoring settings, or rely on Log module timestamping; review boundary detection if multiline records are present&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;timestamp.multiple_patterns&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;INFO&lt;/TD&gt;
&lt;TD&gt;No action if expected; configure the timestamp format explicitly if the Log module misidentifies message content as a timestamp&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;timestamp.invalid_timezone&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;ERROR&lt;/TD&gt;
&lt;TD&gt;Correct the timezone configuration in log monitoring settings to match the timezone the source writes in&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Ingest pipeline events&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Event type&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Severity&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Action&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;ingest.access_flag&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;WARNING&lt;/TD&gt;
&lt;TD&gt;Run&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;oneagentctl --set-app-log-content-access=true&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the affected host; for a new deployment, enable the flag during installation&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;ingest.masking_timeout&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;ERROR&lt;/TD&gt;
&lt;TD&gt;Review masking rules for the source&amp;nbsp; the most likely cause is an inefficient regular expression; ingestion resumes after correcting the configuration or restarting the Log module&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;ingest.log_source_blocked&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;WARNING&lt;/TD&gt;
&lt;TD&gt;Review OneAgent security rules and adjust them to permit access to the blocked path&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Data loss events&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Event type family&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Severity&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Action&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;data_loss.network&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;ERROR/WARNING&lt;/TD&gt;
&lt;TD&gt;Review network connectivity between the Log module and its delivery endpoint (Environment ActiveGate or Dynatrace endpoint); check for interruptions during the affected window&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;data_loss.*&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(general)&lt;/TD&gt;
&lt;TD&gt;ERROR/WARNING&lt;/TD&gt;
&lt;TD&gt;Read the full event for the specific condition; do not assume a sub-type without reading it&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Process group events&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Event type&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Severity&lt;/FONT&gt;&lt;/TH&gt;
&lt;TH class="lia-align-center"&gt;&lt;FONT size="2"&gt;Action&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;pgi.multiple_pgis&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;WARNING&lt;/TD&gt;
&lt;TD&gt;Determine if intentional (shared sink log file) or unintentional (PGI transition); refine the custom log source definition or process group configuration if unintentional&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;pgi.lgi_explosion&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;ERROR&lt;/TD&gt;
&lt;TD&gt;Create a custom log source rule with a wildcard pattern covering all log files written by the process group instance&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 3: Apply the remediation and validate&lt;/H3&gt;
&lt;P&gt;After applying the fix:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Write a unique, identifiable test record to the original source.&lt;/LI&gt;
&lt;LI&gt;Record its source timestamp and timezone.&lt;/LI&gt;
&lt;LI&gt;Wait for the next Log module polling cycle.&lt;/LI&gt;
&lt;LI&gt;Check whether the same SFM event is still active on the dashboard.&lt;/LI&gt;
&lt;LI&gt;Search for the test record in the &lt;STRONG&gt;Logs&lt;/STRONG&gt; app, filtered by host, workload, or source.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 4: If no SFM event is active&lt;/H3&gt;
&lt;P&gt;Check source coverage:&lt;/P&gt;
&lt;DIV class="dutmcw0"&gt;
&lt;DIV class="dutmcw1"&gt;
&lt;DIV class="_1bzvwaf5q-3-9-0 _1bzvwaf6e-3-9-0 _1bzvwaf2-3-9-0 _1bzvwaf79-3-9-0" data-dt-component="Grid"&gt;
&lt;DIV class="strato-button-label _10kgnsa9-3-9-0 _10kgnsab-3-9-0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;PRE class="dutmcw2"&gt;&lt;CODE&gt;Settings app &amp;gt; Collect and capture &amp;gt; Log monitoring &amp;gt; Configure log module &amp;gt; Sources
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;Confirm whether the source is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Listed under the expected entity&lt;/LI&gt;
&lt;LI&gt;Covered by an active or inherited ingest rule&lt;/LI&gt;
&lt;LI&gt;Matched by a rule whose scope and matcher correspond to the current source attributes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the source is missing or uncovered, continue with &lt;A href="https://community.dynatrace.com/t5/tkb/workflowpage/tkb-id/troubleshooting/article-id/1187?prePageCrumb=TkbDashboardPage" target="_blank" rel="noopener noreferrer"&gt;Log source not detected or not ingested: Troubleshoot source discovery and ingest-rule coverage&lt;/A&gt;.&lt;/P&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 5: Check for short, unexplained gaps&lt;/H3&gt;
&lt;P&gt;The OneAgent Log module has built-in resilience. A dedicated watchdog process monitors the Log module: if it does not respond within &lt;STRONG&gt;15 minutes&lt;/STRONG&gt;, the watchdog restarts it. Restart retry delays start at 10 seconds and double on each failure, capping at 1 hour. The delay resets after the module runs successfully for 20 minutes. There is no limit on restart attempts.&lt;/P&gt;
&lt;P&gt;Short, isolated ingestion gaps without a persistent SFM event can indicate a module restart cycle. If logs resumed without configuration changes and no event persists, a restart is a likely explanation. No action is required unless the gap is recurring or the SFM dashboard shows persistent issues.&lt;/P&gt;
&lt;HR /&gt;
&lt;H3&gt;Step 6: If an Environment ActiveGate is involved&lt;/H3&gt;
&lt;P&gt;If the affected source uses an Environment ActiveGate and &lt;STRONG&gt;multiple sources on the same ActiveGate&lt;/STRONG&gt; are affected simultaneously:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check ActiveGate connectivity and health&lt;/LI&gt;
&lt;LI&gt;Review resource pressure on the ActiveGate during the incident window&lt;/LI&gt;
&lt;LI&gt;Consult the official sizing guidance: &lt;A href="https://docs.dynatrace.com/docs/ingest-from/setup-on-k8s/guides/deployment-and-configuration/resource-management/ag-resource-limits" target="_blank" rel="noopener noreferrer"&gt;ActiveGate resource management and sizing for Kubernetes&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If only one source through the ActiveGate is affected, continue with source-level investigation.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Opening a support case with below details&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Environment, region, and deployment type (SaaS / Managed)&lt;/LI&gt;
&lt;LI&gt;Affected host, host group, Kubernetes cluster, namespace, workload, or source path&lt;/LI&gt;
&lt;LI&gt;Approximate start time and timezone&lt;/LI&gt;
&lt;LI&gt;Screenshot or export from the Log module self-monitoring dashboard showing active issues&lt;/LI&gt;
&lt;LI&gt;Exact SFM event type, severity, and any source or entity context from the event&lt;/LI&gt;
&lt;LI&gt;Source coverage state from the Sources view&lt;/LI&gt;
&lt;LI&gt;Applicable active and inherited ingest rules with matchers and scopes&lt;/LI&gt;
&lt;LI&gt;Sanitized sample record from the affected source&lt;/LI&gt;
&lt;LI&gt;Confirmation that the original source writes new records&lt;/LI&gt;
&lt;LI&gt;Unique-record test result (found / not found)&lt;/LI&gt;
&lt;LI&gt;Recent changes: application, logging, permissions, path, encoding, rotation, deployment, or Dynatrace configuration&lt;/LI&gt;
&lt;LI&gt;OneAgent, Dynatrace Operator, and Environment ActiveGate versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;BR /&gt;Related reading&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/logs/lma-log-ingestion/lma-log-ingestion-via-oa/lma-log-agent-sfm" target="_blank" rel="noopener noreferrer"&gt;Monitor log source health with SFM events&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/docs/analyze-explore-automate/log-monitoring/lmc-troubleshooting/log-module-self-monitoring-events-classic" target="_blank" rel="noopener noreferrer"&gt;Log module self-monitoring events – Log Monitoring Classic&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.dynatrace.com/t5/tkb/workflowpage/tkb-id/troubleshooting/article-id/1187?prePageCrumb=TkbDashboardPage" target="_blank" rel="noopener noreferrer"&gt;Log source not detected or not ingested&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.dynatrace.com/news/blog/modern-log-management-resilience-and-self-service-upgrades-for-log-ingestion/" target="_blank" rel="noopener noreferrer"&gt;Improve log ingest health with smarter log management&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Logs-Troubleshooting-Map/ta-p/302260" target="_blank" rel="noopener noreferrer"&gt;Dynatrace Logs Troubleshooting Map&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 04 Sep 2026 06:47:48 GMT</pubDate>
    <dc:creator>noel_david</dc:creator>
    <dc:date>2026-09-04T06:47:48Z</dc:date>
    <item>
      <title>My logs went silent ,where do I start?</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/My-logs-went-silent-where-do-I-start/ta-p/303793</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Short description of which part of the Dynatrace platform the article refers to and what kind of problem it will help resolve/ task it will describe.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Problem&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Provide a precise description of the problem/ task to be described. Use anonymized screenshots, and include text for&amp;nbsp;important messages, errors, or information that will help the customer find this article when searching.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Troubleshooting steps&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted as necessary.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what troubleshooting steps should be taken to ensure the problem matches this article.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Resolution&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted for articles that guide customers on case creation.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain the solution or all possible solutions resulting from the troubleshooting steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section. Customers need a way to respond or follow up if they have questions.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what to do if the article didn't help.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Note that there are multiple options available, including:&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Opening a chat or support case&amp;nbsp;&lt;/STRONG&gt;- be as specific as possible about the information the customer should include in the case.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Use the following formula and fill or change the bullet points:&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt; If this article didn't help, &lt;STRONG&gt;create a chat or open a support case&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Mention that you reviewed this article.&lt;/LI&gt;
&lt;LI&gt;Include the following details:
&lt;UL&gt;
&lt;LI&gt;Link to XYZ&lt;/LI&gt;
&lt;LI&gt;Screenshot of XYZ&lt;/LI&gt;
&lt;LI&gt;Information about XYZ&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Suggesting Product Idea&lt;/STRONG&gt; - encourage the customer to suggest/ vote for a Product Idea explaining their business use case.&lt;BR /&gt;&lt;/EM&gt;
&lt;DIV&gt;Please submit a Product Idea with detailed information about your request and use case in the Product Ideas forum. Our Product Management team regularly reviews these suggestions:&lt;/DIV&gt;
&lt;A href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/idb-p/DynatraceProductIdeas" target="_blank" rel="noopener"&gt;https://community.dynatrace.com/t5/Dynatrace-product-ideas/idb-p/DynatraceProductIdeas&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Explain this will change in the future &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;- explain that this behavior will change in a future release. (No product idea / support case needed)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Alternatives -&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;&amp;nbsp;any other actions or links to other articles that could move the customer forward.&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;&lt;BR /&gt;Related reading&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*Link this article to other relevant configuration or troubleshooting guides, including any applicable troubleshooting maps.&lt;BR /&gt;:open_book:&amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;A href="https://community.dynatrace.com/t5/Troubleshooting/" target="_blank" rel="noopener"&gt;XXX Troubleshooting Map&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;:open_book:&amp;nbsp; Link 1&lt;/P&gt;
&lt;P&gt;:open_book:&amp;nbsp; Link 2&lt;/P&gt;
&lt;P&gt;:open_book:&amp;nbsp; Link 3&lt;/P&gt;
&lt;P&gt;:open_book:&amp;nbsp; Link 4&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Sep 2026 06:47:48 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/My-logs-went-silent-where-do-I-start/ta-p/303793</guid>
      <dc:creator>noel_david</dc:creator>
      <dc:date>2026-09-04T06:47:48Z</dc:date>
    </item>
  </channel>
</rss>

