Analyze Cases automatically with Olly
Automatic case analysis puts Olly to work the moment a Case opens. When a Case matches your criteria, Olly investigates it on its own—correlating logs, metrics, and traces—and posts a root-cause finding directly on the Case, so your team can begin triage with a likely cause already in hand. The same finding travels to every destination you route Case notifications to.
What you need
- Olly enabled for your team.
- A paid Coralogix plan. Automatic case analysis is available to teams on a paid plan.
- Cases in use, with alerts configured to create Cases.
- The
OLLY-AUTOMATIONS:MANAGEpermission to configure automatic case analysis. Turning it on the first time also requires theTEAM-CUSTOM-API-KEYS:MANAGEpermission, because Olly runs analysis using a team API key.
How it works
Once you turn it on, automatic case analysis runs in four stages for every Case that matches your scope:
- Detect: A Case that matches your scope opens.
- Analyze: Olly correlates your logs, traces, and metrics to identify the most likely root cause.
- Surface: Olly's finding appears on the Case for your team to act on.
- Notify: The finding is also sent to any destination configured for the Case's notifications.
Each automatic analysis runs Olly and counts toward your team's AI units usage, the same as other Olly activity. To cap how many units automatic case analysis can consume, set a limit for it on the Automations & Agents tab in Usage Management.
Turn on automatic case analysis
- In Coralogix, select Settings, then Olly AI, then Automatic Case Analysis.
- In Key name, enter a name for the team API key Olly uses to analyze Cases on your team's behalf. The Role Preset is set to Olly and can't be changed.
- Select Turn on case analysis. Coralogix creates the team API key and starts automatic analysis. The status changes to Running.
After the key exists, use the toggle on the Case analysis section to pause or resume analysis at any time. If the team API key is later disabled or revoked, analysis pauses and the status shows Paused until you replace the key or re-enable it.
Set which Cases Olly analyzes
Scope analysis to the Cases you care about so Olly runs only where it adds value. Scope changes save automatically.
Case priorities
Select All priorities to include Cases of any priority, or select Specific priorities and then select the priorities (P1 through P5) Olly should analyze.
Ownership labels
Add one or more ownership labels to restrict analysis to Cases that carry any of them. Leave this empty to analyze all Cases that match your priority filter. Ownership labels are the same environment, service, and team labels used to route Case notifications. See Cases in Notification Center.
When both filters are set, a Case is analyzed only when it matches the priority filter and carries at least one of the selected ownership labels.
Read Olly's analysis on a Case
When a Case matches your scope, Olly analyzes it and posts the finding on the Case's Triage tab, attributed to Olly with a reminder to review it before acting. The finding has three parts:
- Investigation summary: A concise narrative of what happened, when it started, the scope of impact, and the correlated signals across logs, metrics, and traces.
- Root cause: The most likely cause based on the evidence, with a confidence level.
- Remediation recommendations: Two to four concrete, ordered next steps specific to the identified root cause.
Receive the analysis in your notifications
Because Olly's finding is stored on the Case, it travels through whatever destinations you already route Case notifications to—Slack, PagerDuty, email, or webhook—with no extra per-channel setup. Configure Case notification routing in Notification Center.
Limitations
- Automatic analysis applies to Cases that open after you turn it on. Olly does not retroactively analyze Cases that were already open.
- Analysis pauses whenever the team API key it runs as is disabled, revoked, or deleted. Replace the key or re-enable it to resume.
Permissions
| Permission | Grants |
|---|---|
OLLY-AUTOMATIONS:MANAGE | Configure automatic case analysis, including the enable toggle and scope filters. |
TEAM-CUSTOM-API-KEYS:MANAGE | Create the team API key. Required the first time you turn analysis on. |