LogReduce
The LogReduce® algorithm uses fuzzy logic to cluster messages together based on string and pattern similarity. Use the LogReduce button and operator to quickly assess activity patterns for things like a range of devices or traffic on a website.
The summarize
operator has been renamed to logreduce
to match the LogReduce button on the Messages tab. Both operators will continue to work in search queries as synonyms for a limited time. We recommend that you rewrite saved queries replacing summarize with LogReduce.
Watch our video on LogReduce.
In this section, we'll introduce the following concepts:
LogReduce Operator
Allows you to quickly assess activity patterns for things like a range of devices or traffic on a website.
Detect Patterns with LogReduce
Group messages with similar structures and patterns, providing insight into specific keywords or time range.
LogReduce Keys
Clusters JSON logs based on keys providing an at-a-glance summary of patterns in logs based on their schema while ignoring specific values.
LogReduce Values
Clusters JSON logs using the values of keys.
LogReduce Relevance Column
Displays a numerical score for a signature, predicting which signatures could be most meaningful.
Influence the LogReduce Outcome
Influence the algorithm by editing a signature to increase or decrease your results granularity.