Our next-gen architecture is built to help you make sense of your ever-growing data Watch a 4-min demo video!

Back to All Docs

Flow Anomaly Flow Anomaly

Last Updated: Nov. 22, 2022

When we examined the Log Analytics market, we saw quite a few companies with great products for indexing and visualizing logs. However, the competition between all these tools was narrowed to who makes the most flexible query language or who is the fastest in indexing log data. In other words: “who applies the most brute force to big data?”.

The problem with this approach was that Log Analytics users didn’t really know how to make the best out of the valuable log data they collect since they had to know what to search for and in what timeframe. Moreover, they reacted to their production problems instead of proactively tackling them.

Our goal at Coralogix is to disrupt this market with a whole new approach: get the data you need by push, and not by pull.

Coralogix automatically learns the system’s log sequences in order to detect production software problems in real-time. The algorithm identifies which logs arrive together and in what arrival ratio and alerts the user in case this ratio was broken.

An example from one of our customers was a pattern that consisted of 3 logs that always arrived together with a ratio of 33% for each log within the sequence:

  1. About to send data to customer ID XXXXX in X seconds
  2. Sending data to customer ID XXXXX
  3. Total data sent to customer ID XXXXX is X KB

In this case, Coralogix detected a production bug in which data wasn’t sent to customers, this bug was reflected by the absence of log #2 describing the sending process. What Coralogix found was that log 1# arrived and then log #3 arrived with the value 0 for the amount of data sent in KB. Our user was notified in real-time and the problem was solved (one web server was badly configured).

You can view and investigate your anomalies by opening the Insights screen. The anomaly view contains the logs which usually arrive together with their current (anomalous) ratio vs. their normal behavior. Note that there can be more than 1 template that behaves in an anomalous way.

Below the main anomaly display you can see the automatic anomaly forensics: 

Suspected Errors: High severity logs which arrived more than normal in the anomaly timeframe

Top Errors: The top errors in the anomaly timeframe sorted by the number of occurrences

Newly introduced templates: Templates that have arrived for the first time in your application during the anomaly timeframe

The Loggregation tab presents all logs that have arrived in the anomaly timeframe with the logs participating in the anomaly highlighted.

The Loggregation tab shows an aggregated view of all the logs from the anomaly timeframe with the logs participating in the anomaly highlighted:

By clicking the ‘Edit anomaly’ button to the right-hand of the anomaly name, you can change the anomaly name and severity, or mute the anomaly to have it hidden from your dashboard:

Start now and enjoy Coralogix’s automatic anomaly detection capabilities.

On this page