Monitoring
Watch collected data with simple, complex and anomaly-based rules, and get alerted when something changes.
What you will do: turn a saved search into a monitoring rule and route its alerts to the people who act on them.
Monitoring runs rules against incoming data on a schedule or continuously, and raises alerts when a rule matches. Rules range from a single condition to anomaly detection on a metric.
Rule types
- Simple — a saved search matched more than, or fewer than, N events in a time window. Example: more than 10 failed logins in 5 minutes.
- Complex — several conditions combined, across sources or fields, with thresholds per group. Example: error rate above 2 % for a service while latency is also above its limit.
- Anomaly-based — XpoLog learns the normal pattern of a metric and alerts when the current value deviates from it, without a fixed threshold. AI-driven anomaly rules consume XMC AI tokens.
Steps: a first rule
- Start from a saved search (see Search).
- Open monitoring and choose New rule:
Console path: <placeholder>
- Pick the rule type and set the condition and time window.
- Choose the actions: email, a webhook to your alerting platform, or a ticket. Destinations are configured once under integrations.
- Set the severity and the schedule, then enable the rule.
- Test it by producing a matching event and checking that the alert arrives.
Keeping alerts useful
- Group alerts by the field that identifies the thing at fault (host, service, user) so one incident is one alert.
- Use anomaly rules for metrics whose normal level changes by hour or weekday.
- Install the App for a technology before writing rules for it; most common rules are already included.
Next: Apps
Verify with XPLG engineering before publishing.