On Thursday, Aug. 25th, the Splunk Log Observer team is making a change that will speed up most Log Observer and Log Observer Connect queries, which may cause the logs table to show more results than before.
A screenshot of Splunk Log Observer, pointing out the logs table and the group-by control for visual analysis.
What’s changing?
Today, the logs table in the Log Observer UI only shows log messages containing the fields that the visual analysis is grouped by. For example, in the screenshot above, the visual analysis is grouped by ‘severity’.
On Thursday, Aug. 25th, we will change the logs table to show log messages with or without the fields that have been used to group the visual analysis. After Thursday, Aug. 25th, when you group by a field in Log Observer, the logs table can include messages with or without that field. If you want to ensure that the logs table only shows messages that include the fields that have been used to group the visual analysis, add a filter like “example=*”.
To add a filter in Log Observer, click the Add Filter button and search or browse for a field. Click "Include all logs with this field" to add a filter like "severity=*" as shown.
Why are we changing it?
This change will make the average Log Observer query faster and more efficient. It also makes it easier to understand what Log Observer is doing in each query. The logs table can always be returned to its original behavior by adding filters like “example=*” to the filter bar.
What effects will this change have in Log Observer?
After this change, your saved Log Observer queries that group by some field may start to include more results in the logs table than they used to, because the results can now include logs with or without that field.
If you want to ensure that the logs table will only show messages that are included in the groups shown in visual analysis, add a filter like “example=*” to the filter bar to filter by that field.
How does this work today, before the change?
You can use the group by dropdown control in Log Observer to show visual analysis grouped by different fields. Before this change, when you choose a field to group by, Log Observer would only show logs containing that field, in order to ensure that the logs table would not show messages that do not appear in the Visual Analysis area.
This original behavior can be restored by adding an explicit filter, like "example=*".
About Splunk Log Observer
Splunk Log Observer offers a no-code experience for finding and analyzing logs data integrated with Observability Cloud, for fast troubleshooting and adding to Splunk Observability Dashboards. To learn more, sign up for a free trial.
— Rebecca Tortell, Principal Product Manager, Observability
... View more