Log Analytics
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Alert if the log "pattern" changes

gschramm
Helper

I've configured openpipeline to move the logs from various applications to dedicated buckets. I've also create metric that is counting the messages per loglevel, host and logsource.

Now I'm struggling with setting up Anomoly dectection to alert the application teams when the log pattern changes, eg. more warnings/criticals than usual > send alert.

The issue seems to be with the setting the scope, it can only handle one timeseries. In one app I get ~600 metrics (loglevel x hosts x logsource).  Removing the log source still results in 50ish splittings. Even just using the loglevel means 4 and thats too inaccurate for alerting.  The app has a two digit number of servers that are loadbalances, so knowing which servers log behalvior is changing is helping the team to quickly go to the right machine.

 

Any help appreciated.

0 REPLIES 0

Featured Posts