Frequently asked questions
What is the difference between log monitoring and log management?
Log monitoring focuses more on quickly detecting anomalies, locating faults, and triggering alarms through logs; Log management also includes the complete lifecycle of collection, parsing, storage, governance, and permissions. Guance also covers log query analysis and log management capabilities.
What capabilities does a log analysis platform need?
A high-quality log analysis platform needs to cover log collection, field parsing, full-text retrieval, aggregation analysis, alert rules, permission governance, and contextual association. Guance further integrate logs with Trace, metrics, RUM, events, and infrastructure data, helping teams trace from a single error log to the full impact chain.
What data can Guance logs relate?
Guance logs can be linked with application traces, host metrics, container status, network data, user access sessions, and alert events through unified tags and context, enabling teams to quickly trace the impact and root cause clues from a single log.
How to change from log queries to alert rules?
Teams can save high-value query conditions in the log viewer and convert them into monitors. When the number of error logs, key fields, or exception patterns meets set conditions, Guance triggers an alert through the configured notification channel.
What scenarios are suitable for log field parsing?
Field parsing is suitable for extracting structured fields from log content such as order number, user ID, interface path, error code, region, service name, etc., facilitating subsequent filtering, aggregation, chart analysis, and issue tracking.