humio/activity Dashboards
Alerts Overview
Widget | Description | Type |
---|---|---|
Alert Problems by Repository/View |
How many distinct FDR feeds had problems per repository.
logscale
| Time Chart |
Action Invocation Problems |
Overview of errors with invoking actions when a filter alert
triggers.
logscale
| Table |
User Problems |
Overview of errors with running filter alerts due to either the
user having been deleted or the user not having permissions to run
the filter alert. Fix this by either granting the user the missing
permissions, change the alert to run as another user, or change
the alert to run on behalf of the organization.
logscale
| Table |
Successful Alert Triggers by Repository/View |
This chart displays when the alert successfully triggered.
logscale
| Time Chart |
Alert Query Start over Time |
Shows how many times the legacy alert query was restarted over
time. If this happens more than a few times, it could indicate
that the query is getting killed or has another problem.
logscale
| Time Chart |
Other Problems |
Number of error or warning logs per feed as well as the number of
restarts. Unless the feed configuration is changed, a restart
suggests some sort of problem with the feed. Also shows
information about the last problem.
logscale
| Table |
Alert Query Start |
Lists all the times legacy alert queries restarted in time
descending order. No. of times restarted represents how many times
the query has restarted in the search window. If this number is
high, it could indicate that the query is getting killed or has
another problem.
logscale
| Table |
Alerts Triggered |
Overview of filter alerts that triggered and successfully invoked
at least one action.
logscale
| Table |
FDR Ingest Status
Widget | Description | Type |
---|---|---|
Alert Problems by Repository/View |
How many distinct FDR feeds had problems per repository.
logscale
| Time Chart |
Other Problems |
Number of error or warning logs per feed as well as the number of
restarts. Unless the feed configuration is changed, a restart
suggests some sort of problem with the feed. Also shows
information about the last problem.
logscale
| Table |
SQS Messages Waiting for Retry |
SQS messages that failed and have not yet been successfully
retried.
logscale
| Table |
Scheduled Searches Overview
Widget | Description | Type |
---|---|---|
Alert Problems by Repository/View |
How many distinct FDR feeds had problems per repository.
logscale
| Time Chart |
Action Invocation Problems |
Overview of errors with invoking actions when a filter alert
triggers.
logscale
| Table |
Scheduled Searches Lagging Behind |
Overview of scheduled reports which cannot keep up with the
schedule and where a planned execution was skipped. Scheduled
reports that are on this list should first be checked if they have
other problems. Second, if the time they lagged behind was a time
where LogScale was not running optimally. If neither is the case,
the target dashboard might need to be optimized.
logscale
| Table |
User Problems |
Overview of errors with running filter alerts due to either the
user having been deleted or the user not having permissions to run
the filter alert. Fix this by either granting the user the missing
permissions, change the alert to run as another user, or change
the alert to run on behalf of the organization.
logscale
| Table |
Successful Alert Triggers by Repository/View |
This chart displays when the alert successfully triggered.
logscale
| Time Chart |
Other Problems |
Number of error or warning logs per feed as well as the number of
restarts. Unless the feed configuration is changed, a restart
suggests some sort of problem with the feed. Also shows
information about the last problem.
logscale
| Table |
Alerts Triggered |
Overview of filter alerts that triggered and successfully invoked
at least one action.
logscale
| Table |