Analyzing anomalous logs and anomaly events
To analyze anomalous logs
- In BMC Helix Log Analytics, on the Explorer tab, select the logml-* index pattern to view all the anomalous log messages.
- Analyze the anomaly score of the logs to understand the anomaly strength.
Each anomalous record contains the Anomaly and Anomaly_Score fields. The value of the Anomaly field is set to 1.0. The Anomaly_Score field represents the anomaly strength and has a value between 0 and 1. If the score is higher, the anomaly strength of the record is high.
BMC Helix Log Analytics automatically assigns severity to anomalous log messages depending on the keywords that the message contains.
For example, if a message contains the words error or critical, the anomaly is assigned the High severity.
The following table displays the severity level and its associated keywords:
To analyze log anomaly events
In BMC Helix Operations Management, use the Events page to analyze log anomaly events. Click the event to view the event details and analyze it .
The following procedure explains how you can go to BMC Helix Log Analytics from BMC Helix Operations Management.
On the Events page in BMC Helix Operations Management, c lick an anomaly event to view the event details.
Log anomaly events are generated with the Log Event class. You can hover over Classto see the class of the event.
- Click the Others tab.
- In the Search Parameters field, click the Review Logs link to open the Explorer tab in BMC Helix Log Analytics .
The Explorer tab opens in BMC Helix Log Analytics and the logs that generated the event are displayed. The anomalous logs are shown in the index pattern that begins with logml.
The anomalous log events are further processed for creating situations. For more information about situations, see Monitoring and investigating situations in the BMC Helix AIOps documentation.