Fleet Insights

Available:LogScale Collector Insights Availability v1.207.0

This feature is available as of the Falcon LogScale 1.207.0 to cloud customers and is being enabled gradually on a ring by ring basis, so will not be available to all users at first.

The Fleet Insights page provides real-time monitoring and analytics for the Falcon LogScale Collector deployment across your environment.

Widgets for Usage, Performance Monitoring and Errors

The insights page uses pre-configured Falcon LogScale widgets to display data.

The data displayed in the widgets can be aggregated using the aggregate by values and or filtered using filters to refine the data or to gain in depth information. When aggregations are applied the errors are displayed in tabular widget.

Depending on the content and the type of widget you can view different data, the widgets on the insights page offer:

Time Controls
  • Time zone selector (defaults to Copenhagen +02:00)

  • Shared time toggle

  • Last 1d quick select option

  • Live data streaming toggle

  • Apply button for time-based changes

Performance Monitoring
  • All graphs share consistent time axis for correlation

  • Percentile measurements (50th, 75th, 99th, 99.9th) provide detailed performance distribution

  • Real-time updates when "Live" mode is enabled

  • Helps identify resource constraints and optimization opportunities

Usage
  • Monitor collector performance in real-time

  • Identify and troubleshoot issues with specific collectors

  • Track data ingestion patterns and anomalies

  • Ensure proper functioning of the LogScale collection infrastructure

This dashboard is essential for maintaining the health and performance of your Falcon LogScale Collector instances.

Insight Widgets
  • Table: Widgets

    Widget Description Content
    Ingest volume Time Chart widget with the total bytes of uncompressed data ingested over time.
    • Y-axis displays volume metrics

    • X-axis shows timeline

    • Blue line indicates total ingest volume

    No ingest (No aggregations) Single Value widget. Displays total count of collectors that are not ingesting data.
    (Aggregation applied) Table widget with the number of collectors with no ingest within the specified time period that.
    • Allows sorting and filtering of affected collectors

    • Shows detailed table view with columns:

      • hostname: Identifier for each collector

      • count: Number of no-ingest incidents

    Errored collectors

    Time Chart widget with a list of the total number of collectors that have been in an error state over time.

    • Shows number of collectors experiencing errors

    • Bar graph format for easy visualization

    • Helps identify problematic collectors

    Errors (No aggregations)Single Value widget.

    Displays total error count

    (Aggregation applied) Table widget with the total list of errors
    • Provides detailed error information in tabular format:

      • hostname: Affected collector identifier

      • count: Number of errors

      • lastSeen: Timestamp of most recent error

      • errorMessage: Detailed error description

    • Enables quick identification of problematic collectors and specific error conditions

    Online Collectors Bar Chart widget with the number of collectors online overtime.
    • Stacked bar graph showing currently active collectors

    • Color-coded by collector instance

    • Y-axis shows count of online collectors

    • Legend identifies individual collector hostnames

    • Real-time status monitoring

    Offline collectors (No aggregations applied) Single Value widget. Displays total count of offline collectors
    (Aggregation applied) Table widget with the total list of errors. Tabular view of inactive collectors with columns:
    • hostname: Collector identifier

    • count: Number of offline incidents

    • lastSeen: Time since last contact

    • Pagination support (1, 2, 3 page navigation)

    • Sortable columns for easy monitoring

    Ingest by source Table widget with the quantity of data ingested for each source.
    • Detailed table view with columns:

      • sourceName: The name of the data source

      • hostname: Associated collector

      • size: Data volume

      • batches: Processing batch count

      • events: Event count

    • Expandable rows for additional details

    Disk Usage Time Chart widget with the disk usage per collector over time in percentiles.

    • Multi-line graph showing disk usage per collector

    • Color-coded lines for different collectors

    • Percentage-based Y-axis (0-100%)

    • Legend with collector hostnames

    • Long-term usage trending

    Memory Usage Time Chart widget with the memory usage in bytes per collector over time.
    • Graph tracking memory consumption

    • Y-axis measured in MB (0-650M shown)

    • Multiple percentile lines for detailed analysis

    • Helps identify memory-related issues and trends

    • Monitors collector memory performance

    CPU Usage

    A Time Chart widget with the maximum usage in bytes per collector over time.

    • Graph displaying CPU utilization percentage

    • Y-axis shows 0-100% utilization

    • Multiple percentile measurements

    • Helps identify processing bottlenecks

    • Useful for capacity planning and performance monitoring