Logs

Learn about what you may see within Oracle Communications Unified Assurance when you click Logs in the main navigation menu. The Logs UI lets you view the logs from most Unified Assurance processes.

By default, the UI shows you:

Seeing a Live Stream of Logs

When you first load the Logs UI, the saved query is run one time, and you see a static set of logs that match the query.

To see a live stream of logs, click the Live button and select a refresh interval. The stream will refresh according to the interval.

You can stop the live stream by clicking the Stop button.

Note:

Leaving the stream running for longer than ten minutes may crash your browser.

Understanding Logs

Each log message appears as a separate row in the log table. The table contains three columns:

The log details are generally in the following format:

@timestamp <timestamp> level <LEVEL> event.dataset <source_name(source_id)> message <message>

where:

Searching the Logs with the Discover Application

You can edit the default query with a different OpenSearch Piped Processing Language (PPL) query, or you can use the OpenSearch Dashboards Discover application to construct OpenSearch Dashboards Query Language (DQL) queries interactively.

To search the logs using the Discover application:

  1. Access the Discover application by doing one of the following:

    • From the Logs page, in the control bar, click the PPL menu and select DQL - Opens in Discover.

    • From the main Unified Assurance navigation menu, select Analytics, then Events, and then Discover.

  2. By default, the eventanalytics-* index pattern is selected. Change it to logs-*.

  3. Optionally, adjust the time range and add filters as needed. You can filter by a variety of fields, including application name or ID, log level, and log message.

  4. Enter search terms.

    The Discover application searches for terms entered in the search bar in all fields, not just the message. For example, if you enter broker in the search bar, all logs with the word broker in any field are returned. This can include all logs added by the Brokerd service and logs from different applications that mention the term broker in their message.

You can also expand any log in the results list to see its fields, and click the icons in the first column to use that field or value to filter the list.

See the OpenSearch documentation for more information about PPL and DQL:

About Saved Queries

The default query shows all logs. If you have different queries that you use frequently, you can create saved queries for them using the OpenSearch Saved Objects UI.

See Managing Log Analytics Queries.

Any saved searches you have imported are accessible by selecting Logs from the breadcrumb bar at the top of the Logs UI or from the OpenSearch menu, under Observability.

Caution:

It is possible to change the default query and save changes by clicking the Save button. However, your changes will apply for all users with permission to access the Logs UI. Entering a new name when you save updates the name of the default query; it does not save it as a new query.

If you accidentally delete or save changes to the default query, you can reimport it.