Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions cid-redirects.json
Original file line number Diff line number Diff line change
Expand Up @@ -409,7 +409,8 @@
"/05Search/Get-Started-with-Search/How-to-Build-a-Search/What-Data-Do-I-Have": "/docs/search/get-started-with-search/build-search",
"/05Search/Get-Started-with-Search/How-to-Build-a-Search/Write-Efficient-Search-Queries": "/docs/search/get-started-with-search/build-search",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page": "/docs/search/get-started-with-search/search-page",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page/Add-a-Saved-Search-to-Favorites": "/docs/search/get-started-with-search/search-page/add-saved-search-to-favorites",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page/Add-a-Saved-Search-to-Favorites": "/docs/search/get-started-with-search/search-basics/save-search#add-a-saved-search-to-favorites",
"/docs/search/get-started-with-search/search-page/add-saved-search-to-favorites": "/docs/search/get-started-with-search/search-basics/save-search#add-a-saved-search-to-favorites",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page/Field-Browser": "/docs/search/get-started-with-search/search-page/field-browser",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page/Field-Browser/Search-from-the-Field-Browser": "/docs/search/get-started-with-search/search-page/field-browser/search-from-field-browser",
"/05Search/Get-Started-with-Search/How-to-Use-the-Search-Page/Field-Browser/Show-and-Hide-Fields-in-the-Field-Browser": "/docs/search/get-started-with-search/search-page/field-browser/show-hide-fields-in-field-browser",
Expand All @@ -436,6 +437,7 @@
"/05Search/Get-Started-with-Search/Search-Basics/Save-a-Search": "/docs/search/get-started-with-search/search-basics/save-search",
"/05Search/Get-Started-with-Search/Search-Basics/Search-Surrounding-Messages": "/docs/search/get-started-with-search/search-basics/search-surrounding-messages",
"/05Search/Get-Started-with-Search/Search-Basics/Share-a-Link-to-a-Search": "/docs/search/get-started-with-search/search-basics/share-link-to-search",
"/docs/search/get-started-with-search/search-basics/share-message-link": "/docs/search/get-started-with-search/search-basics/share-link-to-search#share-a-link-to-a-specific-message",
"/05Search/Get-Started-with-Search/Search-Basics/Time-Range-Expressions": "/docs/search/get-started-with-search/search-basics/time-range-expressions",
"/05Search/Get-Started-with-Search/Search-Basics/View_Traces_from_Search_Results": "/docs/search/get-started-with-search/search-basics/view-traces-search-results",
"/05Search/Get-Started-with-Search/Search-Basics/View-Search-Results-for-JSON-Logs": "/docs/search/get-started-with-search/search-basics/view-search-results-json-logs",
Expand Down Expand Up @@ -5239,7 +5241,7 @@
"/Manage/Ingestion_and_Volume/Enable_and_Manage_the_Data_Volume_Index": "/docs/manage/ingestion-volume/data-volume-index",
"/Manage/Ingestion_and_Volume/Metrics_Ingest_Data_Volume_Index": "/docs/manage/ingestion-volume/data-volume-index/metrics-data-volume-index",
"/Observability_Solution/Kubernetes_Solution/14Link_a_dashboard_to_Explore": "/docs/dashboards/explore-view",
"/Search/Library/Favorites": "/docs/search/get-started-with-search/search-page/add-saved-search-to-favorites",
"/Search/Library/Favorites": "/docs/search/get-started-with-search/search-basics/save-search#add-a-saved-search-to-favorites",
"/Send-Data/Data-Types/Active-Directory": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/microsoft-azure-ad-inventory-source",
"/Send-Data/Data_Types/MySQL": "/docs/integrations/databases/mysql",
"/Send-Data/Data_Types/VMware": "/docs/integrations/containers-orchestration/vmware",
Expand Down
2 changes: 1 addition & 1 deletion docs/get-started/library.md
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ In the future, any apps that you install in this published folder will be automa

Keep track of content you use regularly with Favorites, or content that you want to keep handy. Just click the star icon for your saved search, dashboard, installed app, or folder, and it will be saved to **Favorites** in the left nav for easy access.

You can also [favorite saved searches](/docs/search/get-started-with-search/search-page/add-saved-search-to-favorites) from the **Search** page, and favorite dashboards from the **Dashboards** page.
You can also [favorite saved searches](/docs/search/get-started-with-search/search-basics/save-search#add-a-saved-search-to-favorites) from the **Search** page, and favorite dashboards from the **Dashboards** page.

There is a limit of 20 favorite items per user.

Expand Down
2 changes: 1 addition & 1 deletion docs/get-started/quickstart.md
Original file line number Diff line number Diff line change
Expand Up @@ -126,7 +126,7 @@ See [Sumo Logic OpenTelemetry Collector](/docs/send-data/opentelemetry-collector

Once your data is available in Sumo, you and your colleagues can search your logs and metrics to identify unusual conditions or errors that could indicate a problem. You do this by creating queries and parsing the resulting messages.

You can start a log search, metrics search, or live tail from the Sumo Home page by clicking the respective icon. For walkthrough instructions on how to create a query and parse the messages, see [About Search Basics](/docs/search/get-started-with-search/search-basics/about-search-basics/).
You can start a log search, metrics search, or live tail from the Sumo Home page by clicking the respective icon. For walkthrough instructions on how to create a query and parse the messages, see [Run Your First Sumo Logic Search Query](/docs/search/get-started-with-search/search-basics/about-search-basics/).

## Step 3: Monitor and troubleshoot your environment

Expand Down
4 changes: 2 additions & 2 deletions docs/observability/reliability-management-slo/create-slo.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,11 +86,11 @@ You can use Terraform to manage SLOs with the [`sumologic_slo`](https://registry
</tr>
<tr>
<td>For <strong>Ratio-based</strong> definitions, which calculate successful or unsuccessful events against total events:<ol><li>Specify Total Events query.</li>
<li>Search logs selecting and entering a log query. See [About Search Basics](/docs/search/get-started-with-search/search-basics/about-search-basics) for more information.</li>
<li>Search logs selecting and entering a log query. See [Run Your First Sumo Logic Search Query](/docs/search/get-started-with-search/search-basics/about-search-basics) for more information.</li>
<li>For <strong>Use values from</strong>, select the numeric value available for that query to pull data from.</li>
<li>Then configure the <strong>Total Events</strong>, including a query and values. You can copy and paste the previous query, perhaps with filters removed to get the total.</li></ol></td>
<td>For <strong>Threshold-based</strong> definitions, which calculate against success criteria:<ol><li>Select <strong>Successful</strong> or <strong>Unsuccessful Events</strong> to measure.</li>
<li>Search logs selecting and entering a log query. See [About Search Basics](/docs/search/get-started-with-search/search-basics/about-search-basics) for more information.</li>
<li>Search logs selecting and entering a log query. See [Run Your First Sumo Logic Search Query](/docs/search/get-started-with-search/search-basics/about-search-basics) for more information.</li>
<li>For <strong>Use values from</strong>, it always uses the Metric value.</li>
<li>For <strong>Success Criteria</strong> for <strong>Avg</strong>, <strong>Min</strong>, <strong>Max</strong>, or <strong>Sum</strong> of the selected signal type (such as latency), which must be <strong>greater than</strong>, <strong>greater than or equal to</strong>, <strong>less than</strong>, or <strong>less than equal to</strong> an amount you enter (positive or negative number).</li></ol></td>
</tr>
Expand Down
2 changes: 1 addition & 1 deletion docs/observability/reliability-management-slo/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,7 @@ The heart of an SLO is the queries used for the SLI query types, including metri

#### General information

For general information on querying metrics and logs, see [Introduction to Metrics](/docs/metrics/introduction) and [About Search Basics](/docs/search/get-started-with-search/search-basics/about-search-basics).
For general information on querying metrics and logs, see [Introduction to Metrics](/docs/metrics/introduction) and [Run Your First Sumo Logic Search Query](/docs/search/get-started-with-search/search-basics/about-search-basics).

A preview runs the query in real-time to help test and refine results, with a time range to see broader results as needed.

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
---
id: about-build-search
title: Discover What Data You Have in Sumo Logic
sidebar_label: Discover Your Data
description: Identify what source categories, source hosts, and source names exist in your Sumo Logic environment before you write a search query.
---

Before you can write a useful search, you need to know what data is available in your environment. Use these simple queries to discover your existing source categories, source hosts, and source names, along with an approximate data volume for each.

## What data do I have?

It can be hard to create a search query if you do not know what data you have in your Sumo Logic environment.

You can use the following simple queries to identify possible values for your existing Source Categories, Source Names, and Source Hosts. You can also approximate data volume for each of the possible values using these queries.

We discourage the use of `*`, as it does not provide much value, but in this exception, it is an easy way to identify all messages received in the last 5 minutes, and provide an approximate volume for each.

For Source Categories: `* | count_frequent(_sourceCategory)`

For Source Hosts: `* | count_frequent(_sourceHost)`

For Source Names: `* | count_frequent(_sourceName)`

Once you know what data you have, see [Best Practices for Log Search](best-practices-search.md) for rules on writing queries that filter that data efficiently.
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
---
id: best-practices-search
title: Best Practices for Searches
title: Best Practices for Log Search
sidebar_label: Best Practices
description: Use these easy to follow rules to get the most out of your Sumo Logic searches.
---

Use these easy-to-follow rules to get the most out of your Sumo Logic searches.

## Be specific with search scope

At a minimum, all searches should use one or more [metadata](../search-basics/built-in-metadata.md) tags in the scope, for example:  `_sourceCategory`, `_source`, `_sourceName`, `_sourceHost`, or `_collector`.
At a minimum, all searches should use one or more [metadata](../search-basics/built-in-metadata.md) tags in the scope, for example: `_sourceCategory`, `_source`, `_sourceName`, `_sourceHost`, or `_collector`.

If possible, also use one or more keywords to limit the scope.

Expand All @@ -20,7 +21,7 @@ Use the smallest [time range](set-time-range.md) required for your use case. Whe

Whenever possible, use keyword searches and fields already extracted using [Field Extraction Rules](/docs/manage/field-extractions) (FERs) to filter data instead of using the [where](/docs/search/search-query-language/search-operators/where) operator. If it is not possible to only use a keyword or pre-extracted field, use both a keyword search AND the where clause.

**Best approach:** Field Extraction Rule field AND keyword
**Recommended:** Field Extraction Rule field AND keyword

```sumo
_sourceCategory=foo and fielda=valuea
Expand Down Expand Up @@ -48,7 +49,7 @@ _sourceCategory=foo

When filtering data, make the result set you are working with as small as possible before conducting [aggregate](/docs/search/search-query-language/group-aggregate-operators) operations like sum, min, max, and average. According to [Be specific with search scope](#be-specificwith-search-scope), keywords and metadata in your search scope are the priority. If you must use a `where` clause, refer to [Use fields extracted by FERs and avoid the where operator](#use-fields-extracted-by-fers-and-avoid-thewhere-operator).

**Best approach:**
**Recommended:**

```sumo
_sourceCategory=Prod/User/Eventlog user="john"
Expand Down Expand Up @@ -77,7 +78,7 @@ If you need to use parse regex, avoid the use of expensive operations like `.*`.
52.87.131.109 - - [2016-09-12 20:13:52.870 +0000] "GET /blog/index.php HTTP/1.1" 304 8932
```

```sumo title="Best approach"
```sumo title="Recommended"
| parse regex "(?<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s"
```

Expand All @@ -89,15 +90,15 @@ If you need to use parse regex, avoid the use of expensive operations like `.*`.

Sumo provides two index-based search optimization features: partitions and scheduled views. When you run a search against an partition or scheduled view, search results are returned more quickly and efficiently because the search is run against a smaller data set. For more information, see [Optimize Search Performance](../../optimize-search-performance.md).

## Use Search Parameters
## Use search parameters

If your search contains filtering criteria that could change each time the search is executed, take advantage of [Search Templates](search-templates.md). Search templates make it easier for less expert users to obtain search results, and also reduces the risk that such users will run expensive searches.

## Aggregate before a lookup

Whenever possible, you should aggregate data prior to doing a [lookup](/docs/search/search-query-language/search-operators/lookup-classic). In some cases, this will significantly reduce the amount of data the lookup is referencing.

**Best approach:**
**Recommended:**

```sumo
| count by client_ip
Expand All @@ -116,7 +117,7 @@ Whenever possible, you should aggregate data prior to doing a [lookup](/docs/sea
For readability, use a soft return in the query field to put each new
pipe-delimited operation on a separate line.

**Best approach:**
**Recommended:**

```sumo
_sourceCategory=Apache/Access and GET
Expand Down
Loading