Automation in LogScale
Learn how to automate queries, receive notifications, and schedule reports
New to Automation?
Learn what automation is in LogScale and understand the complete landscape before implementing. Discover the four trigger types (Scheduled Search, Aggregate Alert, Filter Alert, Legacy Alert), explore all available action types (email, webhooks, Slack, OpsGenie, and more), and use the decision guide to choose the right trigger type for your needs. Perfect for those new to automation in LogScale.
- What is Automation?
- Triggers Overview: All Four Types
- Decision Guide: Which Trigger Type to Choose
- Actions Overview: Complete List
- How Triggers and Actions Work Together
- Scheduled PDF Reports Overview
Ready to Create Triggers?
You understand automation concepts and are ready to create triggers. Follow the complete workflow: choose your trigger type, create and configure triggers with proper time windows and throttling, attach actions, manage and monitor trigger execution, and troubleshoot common issues.
- Choose Your Trigger Type
- Create and Configure Triggers
- Configure Trigger Properties
- Attach Actions to Triggers
- Manage and Monitor Triggers
Ready to Create Actions?
Create and configure actions for your triggers. Learn how to create actions from scratch or templates, configure message templates with variables, test actions before attaching to triggers, manage existing actions, and dive deep into specific action types like email, Slack, webhooks, OpsGenie, PagerDuty, and more.
- Create Actions from Scratch or Templates
- Configure Action Templates and Message Formatting
- Test Actions
- Manage Actions
- Deep Dive: Specific Action Types
Automate Dashboard Delivery
Generate and deliver formatted dashboard reports automatically on a schedule. Learn when to use scheduled PDF reports versus triggers, create and configure scheduled reports, use cron templates for flexible scheduling, and manage your scheduled reports.
- What are Scheduled PDF Reports?
- Create and Configure Scheduled Reports
- PDF Export Format and Options
- Cron Schedule Templates
- Manage Scheduled Reports
Precompute Query Results
Use persisted aggregations to precompute and store query results on a schedule, making repeated queries faster and more efficient. Learn what persisted aggregations are, create and configure them, define scheduling details, and manage existing aggregations.
- What are Persisted Aggregations?
- Create Persisted Aggregations
- Configure Properties and Scheduling
- Manage Persisted Aggregations
Path 1: New to Automation?
Build a solid understanding of automation concepts before you create triggers or actions. Learn what automation is, explore all trigger types, discover available actions, and use the decision guide to choose the right approach for your needs.
What is Automation?
Learn what automation is in LogScale and how triggers, actions, and scheduled reports work together to monitor data and send notifications
Triggers Overview: All Four Types
Explore the four trigger types available in LogScale: Scheduled Search, Aggregate Alert, Filter Alert, and Legacy Alert. The overview presents each type in a dedicated tab. Understand when to use each type and how they differ
Scheduled Searches
conceptbeginnerStatic queries run on a schedule against historical data; includes use cases for scheduled searches versus alerts
Aggregate Alerts
conceptbeginnerLive queries that aggregate data and trigger on results
Filter Alerts
conceptbeginnerLive queries that trigger on individual matching events
Legacy Alerts
conceptbeginnerOlder alert type maintained for backward compatibility
Decision Guide: Which Trigger Type to Choose
Use the decision guide to select the appropriate trigger type based on query performance, ingest delay handling, notification speed, and aggregation requirements. Includes comparison table and decision diagram
Trigger Technical Fundamentals
Understand the technical concepts that control how triggers work: query types (static versus live), timestamp handling, throttling mechanisms to control notification frequency, and query execution models
General Information About Triggers
conceptintermediateFundamental concepts: queries, timestamps, throttling, and query models
Queries in LogScale
conceptintermediateUnderstand static queries versus live queries
Timestamps for Triggers
conceptintermediateLearn about @timestamp versus @ingesttimestamp
Throttling Mechanisms
conceptintermediateControl alert frequency with throttling periods
Actions Overview: Complete List
Discover all available action types that triggers can activate: email, webhooks, Slack, OpsGenie, PagerDuty, S3 upload, file upload, VictorOps, Postmark, and LogScale repository forwarding
Scheduled PDF Reports Overview
Learn about scheduled PDF reports for automated dashboard delivery. Understand how scheduled reports differ from triggers and when to use each approach
Path 2: Ready to Create Triggers?
Follow the complete workflow for creating, configuring, and managing triggers. Create your first trigger, configure properties, attach actions, and monitor execution.
Choose Your Trigger Type
Review the trigger types and use the selector guide to choose the right trigger type for your use case before creating
Create and Configure Triggers
Create triggers from the Triggers overview page or from the Search pag by following step-by-step instructions
Configure Trigger Properties
Configure general trigger properties that apply to all trigger types: name, query, time windows, throttling, timestamps, and permissions
Configure Scheduled Search Properties
Configure properties specific to scheduled searches: scheduling intervals, cron expressions, UTC offsets, backfill limits, max wait times, and timestamp selection. Skip this step if creating alerts
Schedule Configuration
guideintermediateConfigure scheduling intervals for scheduled searches
Cron Scheduling with H Syntax
referenceintermediateUse H to distribute scheduled search execution and balance system load
Timestamp Selection
guideintermediateChoose between @timestamp and @ingesttimestamp
Attach Actions to Triggers
Select and attach existing actions to your triggers. Configure which actions execute when the trigger activates
Manage and Monitor Triggers
View, edit, duplicate, export, or delete triggers. Monitor trigger execution status, check last executed timestamps, and troubleshoot issues
Trigger Management
guideintermediateComplete guide to managing triggers
Edit Triggers
guideintermediateModify trigger configuration and properties
Manage Triggers
guideintermediateView, duplicate, export, or delete triggers
Monitor Triggers
guideintermediateCheck trigger execution status and timestamps
Path 3: Ready to Create Actions?
Create and configure actions for your triggers. Learn how to create actions from scratch or templates, configure message templates, test actions, and explore specific action types.
Create Actions from Scratch or Templates
Create new actions from the Actions page: start from scratch, use exported templates, or base actions on existing package definitions
Configure Action Templates and Message Formatting
Configure message templates for actions using variables and formatting. Create dynamic messages that include query results and event data
Test Actions
Test actions with sample data before attaching them to triggers. Verify configuration, templates, and integration settings
Manage Actions
View all actions in the repository, filter by type or label, duplicate existing actions, export actions as templates, delete unused actions, and configure permissions
Deep Dive: Specific Action Types
Explore detailed configuration for each action type: email, Slack, webhooks, OpsGenie, PagerDuty, S3 upload, file upload, VictorOps, Postmark, and LogScale repository forwarding
Email Action
guideintermediateConfigure email notifications with recipients and formatting
Slack Action
guideintermediateSend notifications to Slack channels
Webhook Action
guideintermediateConfigure HTTP webhooks for custom integrations
OpsGenie Action
guideintermediateCreate OpsGenie alerts from triggers
PagerDuty Action
guideintermediateSend incidents to PagerDuty
S3 Upload Action
guideintermediateUpload query results to Amazon S3
Upload File Action
guideintermediateUpload results as files to external systems
VictorOps Action
guideintermediateSend alerts to VictorOps (Splunk On-Call)
Postmark Action
guideintermediateSend transactional emails through Postmark
LogScale Repository Action
guideintermediateForward matching events to another repository
Path 4: Automate Dashboard Delivery
Generate and deliver formatted dashboard reports automatically on a schedule. Create scheduled reports, configure cron schedules, and manage report delivery.
What are Scheduled PDF Reports?
Learn what scheduled PDF reports are and how they automatically generate formatted dashboard reports and send them to recipients based on customizable time intervals. PDF reports are ideal for regular dashboard distribution and executive reporting, while triggers are best for event-driven notifications
Create and Configure Scheduled Reports
Create scheduled reports from dashboards, configure recipients, set time intervals, customize PDF formatting, and configure email delivery settings. Scheduled reports use the same PDF formatting options available for manual dashboard exports
Cron Schedule Templates
Use cron expressions to define flexible scheduling for reports. This step is advanced and optional — basic report creation can use simple intervals. Learn to configure hourly, daily, weekly, monthly schedules with UTC time specifications and the H syntax for load distribution
Manage Scheduled Reports
View all scheduled reports in the repository, edit report schedules and recipients, monitor report execution status, and delete reports when no longer needed
Path 5: Precompute Query Results
Use persisted aggregations to precompute and store query results on a schedule. Create and configure aggregations, define scheduling details, and manage existing aggregations.
What are Persisted Aggregations?
Learn what persisted aggregations are and how they precompute and store query results on a schedule, making repeated queries faster and more efficient
Create Persisted Aggregations
Create persisted aggregations from the Search page or from the Persisted Aggregations overview page. Follow step-by-step instructions for both approaches
Configure Properties and Scheduling
Configure persisted aggregation properties and define scheduling details including intervals, lookback period, offset, and backfill options
Manage Persisted Aggregations
View, edit, and delete persisted aggregations. Monitor execution status and update queries or scheduling as your needs change
Persisted Aggregation Management
guideintermediateOverview of persisted aggregation management operations
Edit Persisted Aggregations
guideintermediateModify persisted aggregation queries and configuration
Manage Persisted Aggregations
guideintermediateView, duplicate, and delete persisted aggregations