You can create log processing rules to tag logs. Tagging lets you add additional fields to log messages. For example, you can tag logs that contain a sent notification by adding metadata such as sent-notification: true.

Note:
  • Log processing rules are applied only to the logs that are ingested after you create and enable these rules.
  • All the actions that you perform on log processing configurations - create, modify, remove, disable, or enable, need about a minute to reflect in the system.

Procedure

  1. Expand the main menu and navigate to Log Management > Log Processing Rules.
  2. On the Tag Logs tab, click New Configuration.
  3. Provide the following information:
    Option Description
    Name A name for the log tagging configuration.
    Fields Key-value pairs that need to be tagged to the logs. You can add multiple key-value pairs to the logs.
    Apply to all logs / Apply to specific logs Apply the tagging configuration to all the logs or to specific logs. If you apply the configuration to specific logs, you can add query criteria for single or multiple fields, so that only the logs that match the criteria are tagged.
  4. Click Save.

What to do next

On the Tag Logs tab, you can:
  • Modify or remove the configuration. Click the three dots icon to the left of the configuration and select Edit or Delete.
  • Enable or disable the configuration. Click the toggle to the left of the configuration. The toggle is green when the configuration is enabled and gray when it is disabled.