humio/activity Dashboards

  • Alert Details

    The Alert Details dashboard provides comprehensive alert monitoring capabilities through detailed status and performance visualizations. This dashboard enables real-time tracking of alert health, analysis of trigger patterns, and investigation of alert problems across the monitoring environment.

  • Alerts Overview

    The Alerts Overview dashboard presents a consolidated view of alert health and performance through multi-dimensional monitoring visualizations. This dashboard enables tracking of alert problems across repositories, monitoring of trigger patterns, and analysis of lagging alerts across the alert management framework.

  • FDR Ingest Status

    The FDR Ingest Status dashboard provides real-time monitoring of data replication feeds through comprehensive problem tracking visualizations. This dashboard enables identification of feed issues by repository, analysis of SQS message retry status, and monitoring of feed health across the ingestion environment.

  • Filter Alert Details

    The Filter Alert Details dashboard presents detailed filter alert performance metrics through status and timing visualizations. This dashboard enables monitoring of historic query catch-up status, tracking of successful trigger patterns, and analysis of alert problems across filter configurations.

  • Filter Alerts Overview

    The Filter Alerts Overview dashboard provides comprehensive monitoring of filter alert operations through multi-repository status visualizations. This dashboard enables tracking of action invocation errors, analysis of user permission issues, and monitoring of query performance across the filtering framework.

  • Legacy Alert Details

    The Legacy Alert Details dashboard presents historical alert performance data through temporal status visualizations. This dashboard enables monitoring of alert query restarts, tracking of trigger success rates, and analysis of alert health status across legacy configurations.

  • Legacy Alerts Overview

    The Legacy Alerts Overview dashboard provides comprehensive monitoring of legacy alert systems through multi-dimensional problem tracking visualizations. This dashboard enables analysis of action invocation errors, monitoring of query restart patterns, and tracking of alert triggers across legacy alert implementations.

  • Scheduled Reports Overview

    The Scheduled Reports Overview dashboard presents comprehensive reporting metrics through performance and status visualizations. This dashboard enables monitoring of report generation times, tracking of PDF size limitations, and analysis of scheduling delays across the reporting framework.

  • Scheduled Search Details

    The Scheduled Search Details dashboard provides detailed performance metrics through temporal status visualizations. This dashboard enables monitoring of search execution status, tracking of problem patterns, and analysis of search health across scheduled operations.

  • Scheduled Searches Overview

    The Scheduled Searches Overview dashboard presents comprehensive search operation metrics through multi-dimensional monitoring visualizations. This dashboard enables tracking of execution errors, analysis of user permission issues, and monitoring of search performance across the scheduling framework.

Alert Details

The Alert Details dashboard provides comprehensive alert monitoring capabilities through detailed status and performance visualizations. This dashboard enables real-time tracking of alert health, analysis of trigger patterns, and investigation of alert problems across the monitoring environment.

WidgetDescriptionType
Problems Overview of problems with the alert.

Hide Query

Show Query

Table
Current Status Shows the status of the alert within the last minute. If the alert was successfully polled, it is green. Otherwise, if the alert had a failure, it is red. Otherwise, if the alert had a success, it is green. Otherwise, the alert is grey.

Hide Query

Show Query

Single Value
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Status over Time Shows the status of the alert over time.

Hide Query

Show Query

Time Chart
Lagging Behind over Time Shows whether the filter or aggregate alert is running historic queries to catch up over time. Note: Legacy alerts do not run historic queries to catch up.

Hide Query

Show Query

Time Chart
Lagging Behind Whether the filter or aggregate alert is running historic queries to catch up and not reacting to new events in the meantime. Note: Legacy alerts do not run historic queries to catch up.

Hide Query

Show Query

Single Value
Problem severity parameterPanel
Alerts Overview

The Alerts Overview dashboard presents a consolidated view of alert health and performance through multi-dimensional monitoring visualizations. This dashboard enables tracking of alert problems across repositories, monitoring of trigger patterns, and analysis of lagging alerts across the alert management framework.

WidgetDescriptionType
Alert problems Displays a table of alert problems (repository, alert name, last failed, last severity, etc.)

Hide Query

Show Query

Table
Alerts Lagging Behind by Repository/View This chart displays how many distinct aggregate or filter alerts over time per repository/view are running historic queries to catch up and not reacting to new events in the meantime. Note: Legacy alerts do not run historic queries to catch up.

Hide Query

Show Query

Time Chart
Alerts Triggered Overview of alerts that triggered and successfully invoked at least one action.

Hide Query

Show Query

Table
Successful Alert Triggers by Repository/View This chart displays how many distinct alerts triggered over time per repository or view.

Hide Query

Show Query

Time Chart
Alerts Lagging Behind Overview over aggregate or filter alerts that are running historic queries to catch up and not reacting to new events in the meantime. Note: Legacy alerts do not run historic queries to catch up.

Hide Query

Show Query

Table
Alert Problems by Repository/View This chart displays how many distinct alerts had problems over time per repository or view.

Hide Query

Show Query

Time Chart
Problem parameters Select problem severities and categories to show. parameterPanel
FDR Ingest Status

The FDR Ingest Status dashboard provides real-time monitoring of data replication feeds through comprehensive problem tracking visualizations. This dashboard enables identification of feed issues by repository, analysis of SQS message retry status, and monitoring of feed health across the ingestion environment.

WidgetDescriptionType
FDR Ingest Problems by Repository How many distinct FDR feeds had problems per repository.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
SQS Messages Waiting for Retry SQS messages that failed and have not yet been successfully retried.

Hide Query

Show Query

Table
Filter Alert Details

The Filter Alert Details dashboard presents detailed filter alert performance metrics through status and timing visualizations. This dashboard enables monitoring of historic query catch-up status, tracking of successful trigger patterns, and analysis of alert problems across filter configurations.

WidgetDescriptionType
Lagging Behind over Time Shows whether the filter alert is running historic queries to catch up over time.

Hide Query

Show Query

Time Chart
Lagging Behind Whether the filter alert is running historic queries to catch up and not reacting to new events in the meantime.

Hide Query

Show Query

Single Value
Warnings Overview of warnings with the filter alert.

Hide Query

Show Query

Table
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Current Status Shows the status of the alert within the last minute. If the alert was successfully polled, it is green. Otherwise, if the alert had a failure, it is red. Otherwise, if the alert had a success, it is green. Otherwise, the alert is grey.

Hide Query

Show Query

Single Value
Status over Time Shows the status of the alert over time.

Hide Query

Show Query

Time Chart
Filter Alerts Overview

The Filter Alerts Overview dashboard provides comprehensive monitoring of filter alert operations through multi-repository status visualizations. This dashboard enables tracking of action invocation errors, analysis of user permission issues, and monitoring of query performance across the filtering framework.

WidgetDescriptionType
FDR Ingest Problems by Repository How many distinct FDR feeds had problems per repository.

Hide Query

Show Query

Time Chart
Errors due to Action Invocation Overview of errors with invoking actions when a filter alert triggers.

Hide Query

Show Query

Table
Errors with User Overview of errors with running filter alerts due to either the user having been deleted or the user not having permissions to run the filter alert. Fix this by either granting the user the missing permissions, change the alert to run as another user, or change the alert to run on behalf of the organization.

Hide Query

Show Query

Table
Other Errors Overview of other errors with running filter alerts than the three lists above.

Hide Query

Show Query

Table
Action Invocation Warnings Overview of warnings with invoking actions when a filter alert triggers. Note that if the filter alert has multiple actions attached and at least one succeeds, it is considered to have triggered.

Hide Query

Show Query

Table
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Filter Alerts Lagging Behind by Repository/View This chart displays how many distinct filter alerts over time per repository/view are running historic queries to catch up and not reacting to new events in the meantime.

Hide Query

Show Query

Time Chart
Filter Alerts Lagging Behind Overview over filter alerts that are running historic queries to catch up and not reacting to new events in the meantime.

Hide Query

Show Query

Table
Filter Alert Warnings by Repository/View This chart displays how many distinct filter alerts had warnings over time per repository or view.

Hide Query

Show Query

Time Chart
Filter Alerts Triggered Overview of filter alerts that triggered and successfully invoked at least one action.

Hide Query

Show Query

Table
Query Warnings Overview of warnings with running the filter alert queries.

Hide Query

Show Query

Table
Errors with Query Overview of errors with running filter alert queries. This can either be due to an error in the query or due to problems in the cluster causing errors when trying to run the query.

Hide Query

Show Query

Table
Legacy Alert Details

The Legacy Alert Details dashboard presents historical alert performance data through temporal status visualizations. This dashboard enables monitoring of alert query restarts, tracking of trigger success rates, and analysis of alert health status across legacy configurations.

WidgetDescriptionType
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Alert Query Restarts over Time Shows how many times the legacy alert query was restarted over time. If this happens more than a few times, it could indicate that the query is getting killed or has another problem.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Current Status Shows the status of the alert within the last minute. If the alert was successfully polled, it is green. Otherwise, if the alert had a failure, it is red. Otherwise, if the alert had a success, it is green. Otherwise, the alert is grey.

Hide Query

Show Query

Single Value
Status over Time Shows the status of the alert over time.

Hide Query

Show Query

Time Chart
Legacy Alerts Overview

The Legacy Alerts Overview dashboard provides comprehensive monitoring of legacy alert systems through multi-dimensional problem tracking visualizations. This dashboard enables analysis of action invocation errors, monitoring of query restart patterns, and tracking of alert triggers across legacy alert implementations.

WidgetDescriptionType
FDR Ingest Problems by Repository How many distinct FDR feeds had problems per repository.

Hide Query

Show Query

Time Chart
Errors due to Action Invocation Overview of errors with invoking actions when a filter alert triggers.

Hide Query

Show Query

Table
Errors with User Overview of errors with running filter alerts due to either the user having been deleted or the user not having permissions to run the filter alert. Fix this by either granting the user the missing permissions, change the alert to run as another user, or change the alert to run on behalf of the organization.

Hide Query

Show Query

Table
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Alert Query Restarts over Time Shows how many times the legacy alert query was restarted over time. If this happens more than a few times, it could indicate that the query is getting killed or has another problem.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Alert Query Restarts Lists all the times legacy alert queries restarted in time descending order. No. of times restarted represents how many times the query has restarted in the search window. If this number is high, it could indicate that the query is getting killed or has another problem.

Hide Query

Show Query

Table
Filter Alerts Triggered Overview of filter alerts that triggered and successfully invoked at least one action.

Hide Query

Show Query

Table
Scheduled Reports Overview

The Scheduled Reports Overview dashboard presents comprehensive reporting metrics through performance and status visualizations. This dashboard enables monitoring of report generation times, tracking of PDF size limitations, and analysis of scheduling delays across the reporting framework.

WidgetDescriptionType
FDR Ingest Problems by Repository How many distinct FDR feeds had problems per repository.

Hide Query

Show Query

Time Chart
Warnings with Scheduled Reports Overview of warnings related to scheduled reports.

Hide Query

Show Query

Table
Errors due to Action Invocation Overview of errors with invoking actions when a filter alert triggers.

Hide Query

Show Query

Table
Scheduled Reports Lagging Behind Overview of scheduled reports which cannot keep up with the schedule and where a planned execution was skipped. Scheduled reports that are on this list should first be checked if they have other problems. Second, if the time they lagged behind was a time where LogScale was not running optimally. If neither is the case, the target dashboard might need to be optimized.

Hide Query

Show Query

Table
Number of too large PDF reports generated There is a limit to the size of pdf files LogScale will send. This widget shows a number of too large pdf reports that have been generated and attempted sent.

Hide Query

Show Query

Single Value
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Errors with Scheduled Reports Overview of errors related to scheduled reports.

Hide Query

Show Query

Table
Scheduled Report Generation Time (Ms) Overview of the time it takes for a report to transition from being planned to completing either as a success with the email being sent or a failure.

Hide Query

Show Query

Time Chart
Filter Alerts Triggered Overview of filter alerts that triggered and successfully invoked at least one action.

Hide Query

Show Query

Table
Scheduled Search Details

The Scheduled Search Details dashboard provides detailed performance metrics through temporal status visualizations. This dashboard enables monitoring of search execution status, tracking of problem patterns, and analysis of search health across scheduled operations.

WidgetDescriptionType
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Status over Time Shows the status of the alert over time.

Hide Query

Show Query

Time Chart
Scheduled Searches Overview

The Scheduled Searches Overview dashboard presents comprehensive search operation metrics through multi-dimensional monitoring visualizations. This dashboard enables tracking of execution errors, analysis of user permission issues, and monitoring of search performance across the scheduling framework.

WidgetDescriptionType
FDR Ingest Problems by Repository How many distinct FDR feeds had problems per repository.

Hide Query

Show Query

Time Chart
Errors due to Action Invocation Overview of errors with invoking actions when a filter alert triggers.

Hide Query

Show Query

Table
Scheduled Reports Lagging Behind Overview of scheduled reports which cannot keep up with the schedule and where a planned execution was skipped. Scheduled reports that are on this list should first be checked if they have other problems. Second, if the time they lagged behind was a time where LogScale was not running optimally. If neither is the case, the target dashboard might need to be optimized.

Hide Query

Show Query

Table
Errors with User Overview of errors with running filter alerts due to either the user having been deleted or the user not having permissions to run the filter alert. Fix this by either granting the user the missing permissions, change the alert to run as another user, or change the alert to run on behalf of the organization.

Hide Query

Show Query

Table
Successful Alert Triggers This chart displays when the alert successfully triggered.

Hide Query

Show Query

Time Chart
Problems Number of error or warning logs per feed as well as the number of restarts. Unless the feed configuration is changed, a restart suggests some sort of problem with the feed. Also shows information about the last problem.

Hide Query

Show Query

Table
Filter Alerts Triggered Overview of filter alerts that triggered and successfully invoked at least one action.

Hide Query

Show Query

Table