Forum Discussion

Stuart_Weenig's avatar
9 months ago
Solved

Data from logs

First there was LogSources, which sounded great until I heard what their goal was.

Then there was Logs Query Tracking, which also sounded like it would meet my need perfectly until I saw that the only metrics that came back were log count and anomaly count.

Is there anything coming that will let me pull numbers out of my logs? I have several logs that occur very regularly that contain numbers. I’ve easily built parsing into my saved queries that pulls out these numbers into individual columns. When will i be able to create a log-datasource that will let me put in a log query with parsing and map the parsed columns to datapoints (like any other datasource)?

  • Hi @Stuart Weenig,

    Thanks for the question.  Metric extraction from log messages into an LM datapoint is on the roadmap and planned for 2024.  There are many dependencies and complexities that go into this solution, so it will take a little bit of time to make sure we get it right. 

    I would love to get your feedback as we get closer to the UX testing phase, if that’s something you’d be up to.

    Thanks,

    David

3 Replies

  • Hi @Stuart Weenig,

    Thanks for the question.  Metric extraction from log messages into an LM datapoint is on the roadmap and planned for 2024.  There are many dependencies and complexities that go into this solution, so it will take a little bit of time to make sure we get it right. 

    I would love to get your feedback as we get closer to the UX testing phase, if that’s something you’d be up to.

    Thanks,

    David

  • This would be huge for us as well...we’ve hand coded several DS’s to grab metrics from logs… for a few of them, we’ve had to write the event manually as well to match it to the parser.  We do also have many #/5 minute types of Frequency metrics for spotting things like failed authentication attempts to flag brute force and password spray attacks.

  • Yep, i’m up for that. Was hoping that’s what saved queries would have provided and was let down. Was hoping that’s what logsources would have provided and was let down.