diff --git a/solutions/observability/logs/log-data-sources.md b/solutions/observability/logs/log-data-sources.md new file mode 100644 index 000000000..b2e2a54ef --- /dev/null +++ b/solutions/observability/logs/log-data-sources.md @@ -0,0 +1,26 @@ +--- +applies_to: + stack: all + serverless: all +products: + - id: observability +--- + +# Configure log data sources + +The `observability:logSources` {{kib}} advanced setting defines which index patterns your deployment or project uses to store and query log data. + +Configure this setting at **Stack Management** → **Advanced Settings** or by searching for `Advanced Settings` in the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md). + + +::::{note} +Adding indices to the `observability:logSources` setting that don't contain log data may cause degraded functionality. Changes to this setting can also impact the sources queried by log threshold rules. +:::: + +## Configure log data sources using the `saved_objects` API + +To configure log data sources using an API, use the `saved_objects` API. To do this, + +1. From **Stack Management** → **Saved Objects**, [export](/explore-analyze/find-and-organize/saved-objects.md) the log data views, which are stored as an `infrastructure-monitoring-log-view` saved object type, to use as a template. +1. Modify the relevant data view fields in the exported JSON. +1. Import the saved object using the [import saved objects API]({{kib-apis}}/operation/operation-importsavedobjectsdefault). \ No newline at end of file diff --git a/solutions/toc.yml b/solutions/toc.yml index 225ca6a40..89a6f2a0c 100644 --- a/solutions/toc.yml +++ b/solutions/toc.yml @@ -406,6 +406,7 @@ toc: - file: observability/logs/categorize-log-entries.md - file: observability/logs/inspect-log-anomalies.md - file: observability/logs/run-pattern-analysis-on-log-data.md + - file: observability/logs/log-data-sources.md - file: observability/logs/add-service-name-to-logs.md - file: observability/logs/logs-index-template-reference.md - file: observability/logs/streams/streams.md