Orientation

Monitor logs from multiple environments and use Explorer to analyze logs and get to the root cause of the issue that you are troubleshooting by using BMC Helix Log Analytics. You can proactively monitor your logs by setting up event generation when a condition is true in logs.

Related topics

Accessing and navigating the UI

Related spaces

BMC Helix security information Open link

BMC Helix IT Operations Management deployment Open link

The following image depicts how BMC Helix Log Analytics interacts with other products available in BMC Helix.

Note that BMC Helix Developer Tools contains integrations to support log collection for BMC Helix Log Analytics.

For more information about these products, see Related spaces.

Product roles

The user roles and their product goals are shown in the following image:

Product documentation

The BMC Helix Log Analytics documentation helps new and experienced users implement or use this product. Based on your role, the following sections of the documentation are recommended:


Role and permissions in BMC Helix Log Analytics

The following table lists the Operator and Administrator roles used in BMC Helix Log Analytics, the permissions assigned to it, and its responsibilities.

Use cases

Application or Service > Resource > Permission 

Description
  • Analyze logs
  • Create dashboards and visualizations

loganalytics > logs > manage

All roles (operators and administrators) require this permission to access and analyze logs in BMC Helix Log Analytics.

Archive and restore logs

loganalytics > log_archival >manage

Assign the permission to operators to archive and restore logs.

Collect logs

loganalytics > logs > manage

loganalytics > logs > ingest

intelligent-integrations > integrations > manage

intelligent-integrations > integrations > view

intelligent-integrations > connectors > manage

intelligent-integrations > connectors > view

Assign view permission for viewing rights only. For create, edit, and delete permissions, assign the manage permission.

You might want to assign view permissions to operators to view the configurations for log collection. However, administrators require all - manage, ingest, and view - permissions to collect logs.

Configure log enrichment

loganalytics > logs > manage

loganalytics > enrichment_sources > manage

loganalytics > enrichment_sources > view

loganalytics > log_policies > manage

loganalytics > log_policies > view

Assign view permission for viewing rights only. For create, edit, and delete permissions, assign the manage permission.

You might want to assign view permissions to operators to view the enrichment configurations. However, administrators require both manage and view permissions to configure log enrichment. 

For information about assigning permissions, see  Setting up roles and permissions. Open link in the BMC Helix Portal documentation.

Was this page helpful? Yes No Submitting... Thank you

Comments

  1. Graham Brown

    The sentence "Monitor logs from multiple environments and use Explorer to analyze logs and get to the root cause of the issue that you are troubleshooting by using BMC Helix Log Analytics." is used a couple of times in the documentation. I think it should incldue something about alerting. At the moment it is very much positioning Log Analytics and reactive analysis, we need to make sure we cover the proactive alerting side as well.

    Jan 18, 2023 10:06
    1. Swati Malhotra

      Thanks, @Graham! We have made the change. It will reflect on this page soon. Thanks and regards, Swati

      Jan 19, 2023 04:37