Log Management and Analytics

Turn high-volume logs into connected incident evidence

Collect supported log sources, parse and enrich records with Pipelines, control access and retention, and connect logs to hosts, containers, services, traces, and alerts without treating storage volume as an investigation strategy.

What a log management solution should deliver

Make logs searchable, governed, and useful in the same investigation

A production log workflow needs documented collection, consistent fields, controlled access and retention, and links to the service, host, container, trace, and alert that explain why the record matters.

Solution overview

Guance combines supported log collection with Pipeline processing, DQL queries, dashboards, monitors, and cross-signal context. Teams can start from an error or alert, narrow the relevant records, and validate the explanation with runtime and application evidence.

Operational challenges

Volume without context: Collecting more records does not identify which service, release, or user path is affected.

Inconsistent fields: Unstructured formats and changing schemas make the same incident difficult to query across sources.

Disconnected investigations: Logs isolated from metrics and traces force teams to rebuild the timeline manually.

Governance and cost pressure: Access, sensitive fields, retention, indexing, and storage need explicit policies.

How Guance supports the workflow

Collect documented sources: Use the supported DataKit, Syslog, HTTP, cloud, and application paths that match each source.

Standardise with Pipelines: Parse, remap, enrich, mask, and route records into fields teams can query consistently.

Correlate the evidence: Carry service, environment, version, host, pod, and trace identifiers into log investigations.

Govern the lifecycle: Apply workspace access, indexes, retention, archiving, and monitors according to operational value.

Investigation workflows

Continue exploring

Frequently asked questions

What problems should a log management solution solve?

It should support documented collection, parsing, search, access control, retention, dashboards, monitors, and investigation links to services and infrastructure. Exact coverage depends on the source and configured data path.

How does Guance connect logs with metrics and traces?

Use shared service, environment, version, host, pod, and trace attributes. Correlation depends on those fields being collected and normalised consistently.

How should teams control sensitive data and log cost?

Define collection scope, masking, indexes, retention, archiving, access, and sampling before rollout. Validate the current product and deployment documentation for the controls available in your edition.

Does centralising logs eliminate the need for source systems?

No. Source systems and cloud services may remain authoritative for platform-specific controls or original records. Guance provides a shared analysis and investigation layer for configured data.

Bring representative log sources, queries, retention needs, and incident scenarios to design the right data path