Add, edit, or delete lexical keywords in Health Log Analytics
Manage the keywords that Health Log Analytics looks for in your log data.
始める前に
Role required: evt_mgmt_operator or evt_mgmt_admin
このタスクについて
In log data, terms like "crash" or "failed" are called lexical keywords because they indicate issues that can merit attention. When text in log data for a source matches a lexical keyword that exceeds a specified count threshold, the system identifies an anomaly and generates an alert.
重要:
A lexical keyword differs from a
key in a
key:value pair in a log line. For
example, Hostname is a key that takes on a value: the name or IP
address of the host. In contrast, a keyword like Failed is
important by itself and does not take on a value.The application comes with many default global keywords. You can add, edit, and
delete global keywords or phrases. These keywords apply to all source types.
注:
To
add a specified keyword that is associated with a specific source type, see
Configure source type capabilities in Health Log Analytics.