Add, edit, or delete lexical keywords in Health Log Analytics
Manage the keywords that Health Log Analytics looks for in your log data.
Avant de commencer
Role required: evt_mgmt_operator or evt_mgmt_admin
Pourquoi et quand exécuter cette tâche
In log data, terms like "crash" or "failed" are called lexical keywords because they indicate issues that can merit attention. When text in log data for a source matches a lexical keyword that exceeds a specified count threshold, the system identifies an anomaly and generates an alert.
Important :
A lexical keyword differs from a
key in a
key:value pair in a log line. For
example, Hostname is a key that takes on a value: the name or IP
address of the host. In contrast, a keyword like Failed is
important by itself and does not take on a value.The application comes with many default global keywords. You can add, edit, and
delete global keywords or phrases. These keywords apply to all source types.
Remarque :
To
add a specified keyword that is associated with a specific source type, see
Configure source type capabilities in Health Log Analytics.