Automation in LogScale

Learn how to automate queries, receive notifications, and schedule reports

Path 1

New to Automation?

Start with the concepts

Learn what automation is in LogScale and understand the complete landscape before implementing. Discover the four trigger types (Scheduled Search, Aggregate Alert, Filter Alert, Legacy Alert), explore all available action types (email, webhooks, Slack, OpsGenie, and more), and use the decision guide to choose the right trigger type for your needs. Perfect for those new to automation in LogScale.

  • What is Automation?
  • Triggers Overview: All Four Types
  • Decision Guide: Which Trigger Type to Choose
  • Actions Overview: Complete List
  • How Triggers and Actions Work Together
  • Scheduled PDF Reports Overview
Start Here
Path 2

Ready to Create Triggers?

I understand automation concepts — show me how to create triggers

You understand automation concepts and are ready to create triggers. Follow the complete workflow: choose your trigger type, create and configure triggers with proper time windows and throttling, attach actions, manage and monitor trigger execution, and troubleshoot common issues.

  • Choose Your Trigger Type
  • Create and Configure Triggers
  • Configure Trigger Properties
  • Attach Actions to Triggers
  • Manage and Monitor Triggers
Get Started
Path 3

Ready to Create Actions?

Configure automated responses and integrations

Create and configure actions for your triggers. Learn how to create actions from scratch or templates, configure message templates with variables, test actions before attaching to triggers, manage existing actions, and dive deep into specific action types like email, Slack, webhooks, OpsGenie, PagerDuty, and more.

  • Create Actions from Scratch or Templates
  • Configure Action Templates and Message Formatting
  • Test Actions
  • Manage Actions
  • Deep Dive: Specific Action Types
Get Started
Path 4

Automate Dashboard Delivery

Schedule dashboard reports with automatic PDF delivery

Generate and deliver formatted dashboard reports automatically on a schedule. Learn when to use scheduled PDF reports versus triggers, create and configure scheduled reports, use cron templates for flexible scheduling, and manage your scheduled reports.

  • What are Scheduled PDF Reports?
  • Create and Configure Scheduled Reports
  • PDF Export Format and Options
  • Cron Schedule Templates
  • Manage Scheduled Reports
Get Started
Path 5

Precompute Query Results

Store aggregated data for faster, repeated querying with persisted aggregations

Use persisted aggregations to precompute and store query results on a schedule, making repeated queries faster and more efficient. Learn what persisted aggregations are, create and configure them, define scheduling details, and manage existing aggregations.

  • What are Persisted Aggregations?
  • Create Persisted Aggregations
  • Configure Properties and Scheduling
  • Manage Persisted Aggregations
Get Started

Path 1: New to Automation?

Build a solid understanding of automation concepts before you create triggers or actions. Learn what automation is, explore all trigger types, discover available actions, and use the decision guide to choose the right approach for your needs.

1

What is Automation?

Learn what automation is in LogScale and how triggers, actions, and scheduled reports work together to monitor data and send notifications

3

Decision Guide: Which Trigger Type to Choose

Use the decision guide to select the appropriate trigger type based on query performance, ingest delay handling, notification speed, and aggregation requirements. Includes comparison table and decision diagram

5

Actions Overview: Complete List

Discover all available action types that triggers can activate: email, webhooks, Slack, OpsGenie, PagerDuty, S3 upload, file upload, VictorOps, Postmark, and LogScale repository forwarding

6

Scheduled PDF Reports Overview

Learn about scheduled PDF reports for automated dashboard delivery. Understand how scheduled reports differ from triggers and when to use each approach

Path 2: Ready to Create Triggers?

Follow the complete workflow for creating, configuring, and managing triggers. Create your first trigger, configure properties, attach actions, and monitor execution.

1

Choose Your Trigger Type

Review the trigger types and use the selector guide to choose the right trigger type for your use case before creating

2

Create and Configure Triggers

Create triggers from the Triggers overview page or from the Search pag by following step-by-step instructions

3

Configure Trigger Properties

Configure general trigger properties that apply to all trigger types: name, query, time windows, throttling, timestamps, and permissions

4

Configure Scheduled Search Properties

Configure properties specific to scheduled searches: scheduling intervals, cron expressions, UTC offsets, backfill limits, max wait times, and timestamp selection. Skip this step if creating alerts

5

Attach Actions to Triggers

Select and attach existing actions to your triggers. Configure which actions execute when the trigger activates

Path 3: Ready to Create Actions?

Create and configure actions for your triggers. Learn how to create actions from scratch or templates, configure message templates, test actions, and explore specific action types.

1

Create Actions from Scratch or Templates

Create new actions from the Actions page: start from scratch, use exported templates, or base actions on existing package definitions

2

Configure Action Templates and Message Formatting

Configure message templates for actions using variables and formatting. Create dynamic messages that include query results and event data

3

Test Actions

Test actions with sample data before attaching them to triggers. Verify configuration, templates, and integration settings

4

Manage Actions

View all actions in the repository, filter by type or label, duplicate existing actions, export actions as templates, delete unused actions, and configure permissions

Path 4: Automate Dashboard Delivery

Generate and deliver formatted dashboard reports automatically on a schedule. Create scheduled reports, configure cron schedules, and manage report delivery.

1

What are Scheduled PDF Reports?

Learn what scheduled PDF reports are and how they automatically generate formatted dashboard reports and send them to recipients based on customizable time intervals. PDF reports are ideal for regular dashboard distribution and executive reporting, while triggers are best for event-driven notifications

2

Create and Configure Scheduled Reports

Create scheduled reports from dashboards, configure recipients, set time intervals, customize PDF formatting, and configure email delivery settings. Scheduled reports use the same PDF formatting options available for manual dashboard exports

3

Cron Schedule Templates

Use cron expressions to define flexible scheduling for reports. This step is advanced and optional — basic report creation can use simple intervals. Learn to configure hourly, daily, weekly, monthly schedules with UTC time specifications and the H syntax for load distribution

4

Manage Scheduled Reports

View all scheduled reports in the repository, edit report schedules and recipients, monitor report execution status, and delete reports when no longer needed

Path 5: Precompute Query Results

Use persisted aggregations to precompute and store query results on a schedule. Create and configure aggregations, define scheduling details, and manage existing aggregations.

1

What are Persisted Aggregations?

Learn what persisted aggregations are and how they precompute and store query results on a schedule, making repeated queries faster and more efficient

2

Create Persisted Aggregations

Create persisted aggregations from the Search page or from the Persisted Aggregations overview page. Follow step-by-step instructions for both approaches