The page has been translated by Gen AI.

Log Analysis

In log analysis, you collect the logs of the monitoring target, review their contents, and convert them into structured metrics for monitoring. Each monitoring target provides default collected logs, and users can create custom logs to collect and view additional logs as needed.

Reference
  • To use log analysis, you must first install and operate a log collection agent. For detailed information on installing and operating the log agent, see Managing the Agent.
  • To collect logs from Kubernetes Engine, you must configure log collection in the Samsung Cloud Platform Console.

Getting Started with Log Analysis

You can view the log status list or search for logs to be monitored to check them. To view the log status list, follow these steps.

  1. Cloud Monitoring Console > Log Analysis > Log Overview. Click Log Overview to navigate to the Log Overview page.
  2. After entering the search criteria for the service to be analyzed in the search area, click Log Search.
    • The list of services that match the search criteria and the search information are displayed at the bottom.
    • Click the View Details button for each service to display that service’s detailed log information.
      Itemdescription
      Search areaThe displayed search filters in the search area vary depending on the service type
      • Advanced Search to perform Advanced Search, click the Advanced Search button.
      • You can select one or more condition items for each advanced search filter
      Number of monitoring targets displayedSearch results quantity and the number of items displayed at once in the list
      • The default is 20 items per page.
      • The list display count can be changed to 10, 20, 30, 40, 50, or 100 items per page
      Search informationDisplay the search result values for the search criteria items.
      View DetailsView detailed information of the relevant monitoring target
      Log SearchCombine keywords and queries to search logs and view detailed information
reference
  • If a Virtual Server or Node is connected to the monitoring target, the corresponding status is also displayed in the search information area.
  • The name of the monitoring target can include Korean characters, English letters (both uppercase and lowercase), numbers, and special symbols (-, _, .), and can be up to 100 characters long.
  • When the monitoring target does not have permission, information about the unauthorized target and a permission verification message are displayed in a popup.

Check detailed log information

You can view detailed log entries and log graphs of the monitoring target.

Check log list

You can view detailed log information in the monitoring detail popup window. To view detailed monitoring information for a log, follow these steps.

  1. Cloud Monitoring Console > Log Analysis > Log Overview. Click Log Overview. Log Overview page will open.
  2. Click the log you want to view detailed information for on the Log Status page. The Monitoring Details popup window opens.
  3. Click the Log tab.
    • When you place the mouse cursor over the graph, the values of each log entry appear in a popup window.
    • Click the icon in the upper right corner to set the query period or change the refresh interval.
    • You can select the graph display method by clicking the Details, Summary buttons located at the top left of each log chart.
      ItemExplanation
      Basic InformationDisplay basic information about the monitoring target
      DetailsCharts for each log of the monitoring target are expanded and displayed
      • View a single chart in detail
      SummaryPerformance charts of the monitoring target are displayed in a grid layout
      • View multiple charts at a glance
      Set query period
      • Date/Time: Displays the reference date and time for data retrieval.
      • Refresh: Manually refreshes to the current time.
      • Start/Stop: Turns the automatic refresh feature off or on.
      • Settings: Sets the data query period or changes the automatic refresh interval
      Performance ComparisonCombine keywords and queries to search logs and view detailed information.
      Performance chartCharts for each log of the monitoring target are displayed as graphs
      • When you place the mouse cursor over the graph, the log entry value at the specified time appears in a popup window.

Search logs to verify

You can combine keywords and queries to search logs and view detailed information.

Reference
The presence and frequency of keywords can be converted into metrics, displayed as charts on the dashboard page, or used to set up related events to receive notifications.

To search the logs, follow these steps.

  1. Cloud Monitoring Console > Log Analysis > Log Overview. Click Log Overview. You will be taken to the Log Overview page.

  2. On the Log Overview page, click Log Search. You will be taken to the Log Search page.

    ItemExplanation
    Monitoring targetDisplay the service type of the monitoring target to compare
    • Click the monitoring target list to change the service
    • Changing the service will cause all charts created so far to disappear.
    • Add button to search for and add monitoring targets of the currently selected service
    • The selected monitoring targets are displayed on the page, and you can delete a monitoring target by clicking X or Delete All.
    Search criteriaSet conditions for the logs to be searched
    Set query period
    • Date/Time: Displays the reference date and time for data retrieval.
    • Refresh: Manually refresh to the current time.
    • Start/Stop: Turns the automatic refresh feature off or on.
    • Settings: Set the data query period or change the automatic refresh interval
    Log volume graphWhen you search the logs, the log entries that match the entered criteria are displayed as a chart.
    Generated log messageLog messages from the monitoring target are displayed by time.

  3. Click the Add button. A popup window opens where you can add a monitoring target.

  4. After clicking the monitoring target, select the log file you want to add.

  5. After selecting the log file, click the Confirm button.

  6. After entering the search criteria, click the Search button. The search results will be displayed on the log volume graph and the log messages.

    Itemdescription
    Add indicatorAdd metrics to log search results
    • Use after searching logs
    Execution HistoryCheck the list of search criteria that were recently executed
    • The execution history displays up to the last 20 executed search criteria
    • You can select the desired search history and input it as the current search criteria
    Search fieldSelect the search field
    ConditionSelect search criteria
    • like , !like , = , != , <= , >= , > , < can be selected
    search valueEnter the keyword to search
    Log SearchSelect the operator (AND, OR) for the newly added search condition
    • Displayed only when a new search condition is added
    Add conditionAdd a new search condition

  7. When you search the logs, the log entries that match the entered criteria are displayed as a chart.

    • Log entries are displayed in seconds.
      ItemExplanation
      Log volume graphThe log volume over the selected period is displayed as a graph
      • When you hover the mouse cursor over the graph, the values of each log entry appear in a popup window.
      • Clicking a bar in the graph displays the list of logs for that point in time.
      Set query period
      • Date/Time: Displays the reference date and time for data lookup
      • Refresh: Manually refresh to the current time.
      • Start/Stop: Turn the automatic refresh feature off or on.
      • Settings: Set the data query period or change the automatic refresh interval
      Monitoring targetThe monitoring target list is displayed
      • When you select a monitoring target to view log messages, the log list shows the content
      Log listLog messages generated from the monitoring target are displayed by time
      • Click the button in the log list to view the full message of that log
      • Click Download to save the currently displayed log messages in Excel and TXT file formats

Check log collection status

You can view the main log collection information for the past 7 days as a chart.

  • When you place the mouse cursor over the graph, detailed information appears in a popup window.
  • Only collected logs are aggregated, and logs that have not been collected are not displayed in the status.
Reference
  • When you create an Account, we provide a default virtual capacity of 1 GB to store the collected logs.
  • All logs can be stopped and restarted as needed.

To check the log collection status, click Cloud Monitoring Console > Log Analysis > Log Collection Dashboard.

Itemdescription
Cumulative log volumeDisplay the amount of logs collected from the 1st of each month in GB
  • Show the cumulative usage to date as a percentage of the total allocated virtual capacity.
Log collection volume for the past 7 daysDisplay the amount of logs collected over the past 7 days by service type in a graph
  • The line chart shows the quantity (kb), and the bar chart shows the cumulative usage rate.
  • Click a monitoring target in the legend area to display only that graph
Log occurrence rate by serviceDisplay logs collected over the past 7 days, categorized by service
  • Clicking a bar graph representing each service shows the monitoring target with the highest log collection within that service on the log collection TOP 10 chart.
Log Collection Top 10Display a graph of the top 10 monitoring targets that collected the most logs in the past 7 days within the selected service, based on log occurrence rates by service
  • Click each point on the graph to view detailed information for that log
  • Click a monitoring target in the legend area to display only that graph
  • Click the graph of the target service to navigate to the Log Overview page
reference

To perform monitoring related to logs, you must first install and operate a log collection agent. For detailed information on installing and operating the log agent, refer to 에이전트 관리하기.

  • Accumulated logs are stored up to a maximum of 1 GB. If it exceeds 1 GB, older logs are automatically deleted.

Check indicator configuration status

You can create a metric to display the occurrence count of log patterns as a time series. To view the metric list, click Cloud Monitoring Console > Log Analysis > Metric Configuration Status.

Reference
Metrics converted to time-series data can be set as events or added to a dashboard for real-time monitoring.
Itemdescription
Search areaThe displayed search filters in the search area vary depending on the service type
  • To perform Advanced Search, click the Advanced Search button.
  • You can select one or more condition items for each advanced search filter
Number of monitoring targets displayedDisplay search results
  • The default is 20 per page.
  • Change the list display count to 10, 20, 30, 40, 50, or 100 per page.
Search informationDisplay the search result values for the search criteria items.
AddAdd a new metric
DeleteSelect the metric in the search information and delete it.

Check detailed indicator information

Follow these steps to view detailed information about the indicator.

  1. Cloud Monitoring Console > Log Analysis > Metric Configuration Status. Click Metric Configuration Status. You will be taken to the Metric Configuration Status page.
  2. Indicator Setting Status Click the indicator name to view detailed information on the page. Indicator Details popup window opens.

Add indicator

You can add a new metric to display the desired log data as a time series.

Reference
  • Log metrics can only be set for monitoring targets where the log agent is installed or logs are being collected. For detailed information on installing and operating the log agent, refer to 에이전트 관리하기.

To add a new metric, follow these steps.

  1. Cloud Monitoring Console > Log Analysis > Click Metric Configuration Status. You will be taken to the Metric Configuration Status page.

  2. Indicator Settings Status on the page, click the Add button. Add Indicator popup will open.

  3. Enter indicator name.

    • Metric names can only use English uppercase and lowercase letters, underscores (_), periods (.), and hyphens (-).
    • To distinguish metrics from general performance, the prefix metricfilter. is automatically added and cannot be removed or changed.
      ItemExplanation
      Indicator NameEnter the name of the metric to create
      Monitoring TargetDisplay the service type of the monitoring target to compare
      • Click the monitoring target list to change the service
      • Changing the service will cause all charts created so far to disappear.
      • Click the Add button to search for and add the monitoring target of the currently selected service
      • The selected monitoring target is displayed on the page, and you can delete the monitoring target by clicking X or Delete All
      Search CriteriaSet conditions for the logs to be searched
      Set Query Period
      • Date/Time: Displays the reference date and time for data retrieval
      • Refresh: Refreshes directly to the current time.
      • Start/Stop: Turns the automatic refresh feature off or on.
      • Settings: Allows you to set the data query period or change the automatic refresh interval.
      Log volume graphWhen you search the logs, the log entries that match the entered criteria are displayed as a chart
      Generated log messageLog messages from the monitoring target are displayed by time.
  4. Click the Add button. A popup window opens where you can add a monitoring target.

  5. After clicking the monitoring target, select the log file you want to add.

  6. After selecting the log file, click the Confirm button.

  7. After entering the search criteria, click the Search button. The search results will be displayed on the log volume graph and the generated log messages.

    Itemdescription
    Add indicatorAdd metrics to log search results
    • Use after searching logs
    Execution HistoryCheck the list of search criteria that were recently executed
    • The execution history displays up to the last 20 executed search criteria
    • You can select the desired search history and input it as the current search criteria
    Search fieldSelect the search field
    ConditionSelect search criteria
    • like , !like , = , != , <= , >= , > , < can be selected
    search valueEnter the keyword to search
    operatorSelect the operator (AND, OR) for the newly added search condition
    • Displayed only when a new search condition is added
    Add conditionAdd a new search condition

  8. Click the Confirm button. A new metric will be added with a toast popup message.

Modify indicator search criteria

To modify the indicator’s search criteria, follow these steps.

  1. Cloud Monitoring Console > Log Analysis > Click Metric Configuration Status. Metric Configuration Status page will open.
  2. Indicator Settings Overview On the page, click the indicator name of the metric you want to edit. The Indicator Details popup will open.
  3. In the Indicator Details popup, click the Edit button. The Edit Indicator popup opens.
  4. Metric Update After modifying the search criteria in the popup window, click the Confirm button. The metric will be updated along with a toast popup message.

Delete indicator

To delete the indicator, follow these steps.

reference
  • If there are charts or event policies that use the metric you want to delete, you cannot delete that metric.
  1. Cloud Monitoring Console > Log Analysis > Metric Configuration Status. Click it. You will be taken to the Metric Configuration Status page.
  2. On the Indicator Settings page, select the indicator to delete, then click the Delete button. The indicator will be removed along with a toast popup message.
Performance Analysis
Managing Events