Skip to main content

Behavior Insights

Behavior Insights encompasses three log search operators to accelerate insights, troubleshooting, and action plans using structured logs. About 23% of the daily log ingest volume pertains to JSON data and accounts for a growing share of total log volume. This growth is driven by modern applications and underlying cloud (AWS, GCP, Azure) and orchestrator logs. Behavior Insights helps answer the following questions for SecOps, DevOps, and business users:

  • What activity patterns are evident from structured logs? What patterns are trending?
  • Which groups of users, apps, services, or resources are responsible for activity in logs?
  • Which groups of users, apps, services, or resources are responsible for unusual activity in logs?

Modeled after our LogReduce log summarization feature, the LogReduce Values and LogReduce Keys operators cluster logs based on their structure or pattern and activity content respectively.

In this section, we'll introduce the following concepts:

icon

LogCompare

Compare log data from different time periods to detect major changes or anomalies.

icon

LogReduce

Assess activity patterns for things like a range of devices or traffic on a website.

icon

LogExplain

Find the root cause of outliers in logs based on conditions you specify.

Status
Legal
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.