Campaign: General Log Insight Q&A

Trend - misleading icon

Hi

 

Please see the attached screendump. The trend chart is showing a downwards trend. When I hover the mouse over the icon it shows that there is not difference in past and present trend/the trend is so small that there is little to no difference in the trend.

 

This is misleading in the sense that the trend is almost non existing

Submitted by

Type : Bug

Voting

1 vote

Campaign: Feature Requests

Improvement to query lists

Query lists can get quite large with dozens or hundreds of items inside. Allow the user to sort the query list by result. E.g. if a query returns "Has Results" show them on top. This makes it easier to focus on the relevant results. In addition the title bar of a query list shall display the amount of queries. Once the user has executed them (green play button), also display the amount of queries with "Has Results". ...more »

Submitted by

Type : Enhancement

Voting

2 votes

Campaign: Feature Requests

Perform API Queries using Extracted Fields

When using the API to perform a query, we are unable to use extracted fields are constraints when defining the query.

 

NOTE: Although the query returns extracted fields, it does not accept extracted fields.

Submitted by

Type : Enhancement

Voting

4 votes

Campaign: Feature Requests

User and admin logins on LogInsight webinterface

How can I log the logins from the administrator and other users on the LogInsight user interface and dashboards?

Submitted by

Type : Question

Voting

2 votes

Campaign: Feature Requests

More advanced query DSL

I want to be able to make more advanced (PIQL?) queries to LI. For example: 1. Apply functions (i.e. regex, arithmetic, logic, type conversion) on one or more existing fields, i.e. a. sum: fieldA + fieldB b. fieldA OR fieldB c. REGEX(fieldA, pattern) d. CAST('10.2' AS DECIMAL) e. CAST(SUBSTRING(fieldA, 0,10) AS DATETIME) 2. Create custom fields: a. DATE() AS today b. expressionA - expressionB ...more »

Submitted by

Type : Enhancement

Voting

3 votes

Campaign: Feature Requests

enhance filtering options for data sets

would be great if we could use the same filters as in "interactive analytics" for "new data set". At the moment there are just a few fields available. For example we would like to create a data set for some users so that they can only see events where "text"-field matches a regex query or certain words or e.g. the "event_type" field is a certain type. Custom extracted fields are also not available for data set filters. ...more »

Submitted by

Type : Change Current Behavior

Voting

3 votes

Campaign: Feature Requests

Add condition to query

We would like to add some conditions on the query. Today we have our monitoring which is working with codes as "200" to "399". So ours probes are switching codes all time, sometimes with a very little time between changes. The aim of this feature request is to provide a way to display events according to some conditions like : - if my field A is containing "200" - if in the following 30 minutes, the field A is switching ...more »

Submitted by

Type : New Feature

Voting

2 votes

Campaign: Feature Requests

Translate IP Addresses to host names (and vice versa) found in log content

The ability to have Log Insight perform a bi-directional look up to provide us with the host names associated to IP address' listed in log content (and vice versa) will enhance general troubleshooting.

 

This feature is already available in other logging products such as KIWI.

Submitted by

Type : New Feature

Voting

6 votes

Campaign: Feature Requests

Enrich log records

We would like to be able to enrich log records with info from an external sources (add custom tags for incoming/existing logs based on a query to an external service) like vROPS does.

 

Use cases:

a. Query GeoIP Web Service for IP’s location

b. Query CMDB via HTTP/LDAP for additional information (e.g. customer name, related services, server role, environment ….)

Submitted by

Type : New Feature

Voting

1 vote

Campaign: Feature Requests

Offer assistance with queries that take too long

Today, when performing a query that takes a long time, we display a progress bar and a pause button where the log messages are displayed. If a query takes longer that several seconds to complete, the vRLI UI should offer tips while the query is completing. For example.. "Your date filters include X days and Y events, you may want to consider reducing the length of time..." "Your filters do not include a hostname, you ...more »

Submitted by

Type : Enhancement

Voting

3 votes

Campaign: Feature Requests

Execute persisted query via API

Queries can be defined in the Log Insight UI in many places, such as Dashboards or Saved Queries or Alerts or even the Share shorturl. It is difficult to translate these queries to the format necessary for the Query API.

 

Provide an API to execute a pre-existing UI-authored Query by its persistent name/id.

Submitted by

Type : New Feature

Voting

3 votes

Campaign: Feature Requests

Execute named query (dashboards, saved search, etc) via query API

Log Insight's Query API allows the expression of an arbitrary query directly. But Log Insight's UI also allows authorship of queries -- alerts, dashboards, saved queries and even share urls all fundamentally refer to a query Log Insight knows about.

 

Expose a query API endpoint which performs a query based on the name/id of a specific saved construct, without the API client needing to recreate the underlying query.

Submitted by

Type : New Feature

Voting

3 votes