Skip to content

Getting Started with Data Analysis

Essential pages for LogScale analysts. Navigate the interface, search and investigate data, build dashboards, configure automated alerts, and understand event fields.

🧭 Navigate the LogScale User Interface
Master the LogScale UI and understand the platform's core interface components

LogScale User Interface

Complete guide to navigating the LogScale interface. Learn the layout, menu structure, navigation patterns, and core UI components. Essential foundation for all LogScale analysts to understand how to access repositories, searches, dashboards, and administrative functions.

🗄️ Set Repositories and Views
Understand data organization, retention policies, access control, and lookup file enrichment

Repositories & Views

Core organizational structure: how repositories store logs and metrics, how views provide filtered or combined perspectives. Configure retention policies, access control, and ingest tokens. Critical for understanding where data is stored and how to access it.

Enrich Data with Lookup Files

Upload and manage lookup files to enrich log data with additional context. Map IP addresses to locations, user IDs to names, asset IDs to details. Essential for contextual investigations.

📈 Create Dashboards & Widgets
Visualize data in real-time using dashboards and widgets for monitoring and analysis

Dashboard Workflow

Complete guide to dashboard capabilities and creation. Learn what you can do with dashboards, how to create custom dashboards, organize widgets, configure refresh intervals, and share dashboards with team members.

Create Widgets

Create a widget by saving a search query and adding it to a dashboard for ongoing monitoring. Step-by-step guide covering widget creation from search, visualization type selection, and layout placement.

Interactive Dashboards

Use parameter panels and variable-driven filtering to make dashboards interactive. Drill into data without leaving the dashboard view, and let users refine what they see without editing queries.

Share Dashboards

Share dashboards with others using a unique URL. Shared dashboards are read-only and do not require authentication. Use for wall monitors, executive reporting, or giving external stakeholders a live view.

Dashboard Time Controls

Manage time ranges across dashboard widgets. Understand how dashboard time settings differ from per-widget time ranges, and configure live refresh for real-time monitoring views.

🔔 Create Automated Alerts
Set up scheduled searches, aggregate alerts, filter alerts, and automated actions

Automated Alerts

Covers three trigger types: Scheduled Searches (periodic queries), Aggregate Alerts (continuous monitoring with aggregation), and Filter Alerts (instant notification). Learn when to use each type and how to configure throttling to prevent alert fatigue.

Automated Actions

Connect alert triggers to automated response actions. Supported action types include email, Slack, PagerDuty, OpsGenie, VictorOps, webhooks, S3 export, and message templates for custom notification formatting.

Scheduled PDF Reports

Schedule dashboards to be exported as PDF reports and delivered automatically by email. Use for recurring operational summaries, compliance reporting, and executive briefings.

🏷️ Event Fields and Metadata
Master LogScale's field system: metadata, tags, and user-defined fields

Event Fields Deep Dive

Deep dive into LogScale's field system: metadata fields (@timestamp, @rawstring, @id), tag fields (#datasource) controlling physical storage, and user-defined fields extracted during parsing. Understand field types, naming conventions, and how fields affect query performance. Fundamental to writing effective queries and understanding data structure.

Metadata Fields

Comprehensive guide to LogScale's special metadata fields: @timestamp (event time), @rawstring (original log line), @id (unique event identifier), @timezone (event timezone), and more. Learn how to use these built-in fields in queries and understand their role in event processing and storage.


Advanced Analysis
Pre-aggregate query results for high-performance dashboards and long-term trend analysis

Persisted Aggregations

Pre-aggregate query results on a schedule to power dashboards and reports over large data volumes without re-running expensive queries. Understand when to use persisted aggregations and how they differ from live searches.

Manage Persisted Aggregations

Create, configure, edit, and monitor persisted aggregations. Set scheduling intervals, review aggregation results, and manage the lifecycle of aggregations across repositories.

🧭 Guided Workflows
Interactive paths for searching data, data visualization, and automation

Data Visualization Workflows

Interactive paths for building dashboards and widgets. Choose from four paths: New to Data Visualization, Create Dashboards and Widgets, Widgets by Data Format, and Widgets by Use Case.

Automation Workflows

Interactive paths for setting up alerts and actions. Choose from paths covering automation fundamentals, creating triggers, configuring actions, scheduling reports, and persisted aggregations.

🔔 New Pages
🔔 Recently Updated Pages