Product overview


BMC Helix Log Analytics collects logs from multiple environments and uses Explorer to analyze data, troubleshoot issues, and identify root causes. BMC Helix Log Analytics provides proactive monitoring by generating events based on predefined log conditions.

BMC Helix Log Analytics streamlines log analysis by collecting, normalizing, and parsing logs, providing insights into system usage, health, and performance. BMC Helix Log Analytics is an open, scalable, and secure design that enhances troubleshooting by reducing log search time.

Watch the following video (3:36) to understand the core capabilities of BMC Helix Log Analytics to collect and analyze logs from your IT environment:

Product architecture

The Log ingestion service receives logs from various sources, such as Amazon Web Services and Kubernetes and passes it on to the Log Processing service. The Log Processing service enriches the logs, extracts fields from the logs, and generates alerts. BMC Helix Log Analytics identifies anomalies in the incoming logs by using the machine learning (ML). If an anomaly is detected, an event is generated in BMC Helix Operations Management.

1742886475848-256.png

Product capabilities and features

The following diagram illustrates the key features and capabilities of BMC Helix Log Analytics:

1742817480650-853.png

1743592626847-686.png Collect logs

 

1743592711305-782.png Configure logs

Collect logs from various sources, such as Kubernetes, Amazon Web Services, Linux servers, and Windows servers. Ingest logs by installing connectors on source systems and setting up collection policies. You can analyze the collected logs to get to the root cause of an issue.

For more information, see Collecting-logs.

 

Configure logs to extract key data from logs and add meaningful information to the log messages. By configuring the logs, you can troubleshoot the issues more efficiently and reduce the mean time to resolve (MTTR) an issue.

For more information, see Enriching-logs

1743592740167-143.pngDetect anomalies

 

1743592774048-582.png Derive insights from logs

BMC Helix Log Analytics uses machine learning (ML) based anomaly detection to identify unusual log patterns. You can configure alert policies to receive alerts when anomalies are detected. These alerts help proactively identify potential problems before they become problems, improving system reliability and troubleshooting efficiency. When an anomaly is detected an event is generated in BMC Helix Operations Management.

For more information, see Generating alerts from logs.

 

BMC Helix Log Analytics helps analyze and gain insights from logs by using the Explorer > Discover tab. Logs collected through configured policies appear as log messages, which you can search, filter, and analyze to troubleshoot issues efficiently and reduce the MTTR to solve an issue.

For more information, see Deriving insights from logs.

1743592809118-414.png Visualize logs

View out-of-the-box dashboards for quick references on log trends and create new dashboards for your specific requirements. The following out-of-the-box dashboards are available in BMC Helix Dashboards:

  • Amazon Web Services
  • Kubernetes
  • Self Monitoring
  • Syslogs
  • Windows events

For more information, see Visualizing logs.

User roles

The following user roles are available for BMC Helix Log Analytics. Users can perform tasks based on the assigned role.

For information about assigning permissions, see Setting up roles and permissions​​​​.

User roleDescriptionTasks
1743593235718-700.png Administrator

Users belonging to the administrator role are responsible for setting up

  • Collect logs
  • Configure logs
  • Alerts and monitoring
  • Access control and security
  • Visualization and reporting
  • Log archival and restoration
  • Install and manage connectors for collecting logs from various sources.
  • Create and configure collection policies to determine log ingestion.
  • Configure field extraction policies to improve log searchability.
  • Set up log enrichment policies to add meaningful information to the log messages.
  • Define alert policies to trigger alerts based on specific log conditions.
  • Configure anomaly detection settings to proactively identify unusual log patterns.
  • Implement data-level access control to restrict log access to authorized users.
  • Create and manage dashboards in BMC Helix Dashboards to monitor log data visually.
  • Export logs as CSV files for reporting and further analysis.
  • Archive logs for long-term storage and compliance.
  • Restore archived logs when needed for analysis.
1743593267748-936.pngOperator

Users belonging to the operator role are operators.

  • Monitor logs
  • Analyze logs
  • Visualize logs
  • Monitor alerts and anomalies
  • Access and analyze logs to identify issues.
  • Search and filter logs based on time range, fields, or keywords.
  • View enriched log data to gain additional context.
  • Monitor alerts triggered by specific log conditions.
  • Analyze anomalous logs detected by machine learning based anomaly detection.
  • View out-of-the-box dashboards for AWS, Kubernetes, Windows Events, and Syslogs.
  • Monitor key system metrics and log trends. 

Learn more

Use the following resources to learn more about BMC Helix Log Analytics​​​​​:

Webinars

Watch the following webinar (28:31) that explains how you can achieve service monitoring with BMC Helix Log Analytics and BMC Helix AIOps.

icon-play@2x.png https://youtu.be/l09rULNbbaI

Watch the following webinar (47:59) that explains how you can make your logs smarter with BMC Helix Log Analytics.

icon-play@2x.png https://youtu.be/OKIUWSzLbrw

Product blogs
Additional resourcesBMC Community: Learn and engage with other users of BMC Helix Log Analytics at BMC Community.

Education and certification: Go through the web-based trainings for BMC Helix Log Analytics at courses for BMC Helix Log Analytics.

Product datasheet: Access the product data sheet that summarizes the use-cases of BMC Helix Log Analytics: Datasheet.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*