Phone:400-882-3320
Search one incident across heterogeneous logs
Normalise first: Use consistent timestamps, services, environments, severities, and ownership fields before relying on shared queries.
What a log management solution should deliver
A production log workflow needs documented collection, consistent fields, controlled access and retention, and links to the service, host, container, trace, and alert that explain why the record matters.
Guance combines supported log collection with Pipeline processing, DQL queries, dashboards, monitors, and cross-signal context. Teams can start from an error or alert, narrow the relevant records, and validate the explanation with runtime and application evidence.
Volume without context: Collecting more records does not identify which service, release, or user path is affected.
Inconsistent fields: Unstructured formats and changing schemas make the same incident difficult to query across sources.
Disconnected investigations: Logs isolated from metrics and traces force teams to rebuild the timeline manually.
Governance and cost pressure: Access, sensitive fields, retention, indexing, and storage need explicit policies.
Collect documented sources: Use the supported DataKit, Syslog, HTTP, cloud, and application paths that match each source.
Standardise with Pipelines: Parse, remap, enrich, mask, and route records into fields teams can query consistently.
Correlate the evidence: Carry service, environment, version, host, pod, and trace identifiers into log investigations.
Govern the lifecycle: Apply workspace access, indexes, retention, archiving, and monitors according to operational value.
Normalise first: Use consistent timestamps, services, environments, severities, and ownership fields before relying on shared queries.

Preserve correlation keys: Use trace IDs, service tags, host names, pods, versions, and request attributes to continue the investigation.

Process deliberately: Filter, sample, mask, and route data according to its diagnostic and compliance value.

Operationalise the query: Promote validated searches into shared views and alert rules with clear owners and runbooks.

It should support documented collection, parsing, search, access control, retention, dashboards, monitors, and investigation links to services and infrastructure. Exact coverage depends on the source and configured data path.
Use shared service, environment, version, host, pod, and trace attributes. Correlation depends on those fields being collected and normalised consistently.
Define collection scope, masking, indexes, retention, archiving, access, and sampling before rollout. Validate the current product and deployment documentation for the controls available in your edition.
No. Source systems and cloud services may remain authoritative for platform-specific controls or original records. Guance provides a shared analysis and investigation layer for configured data.