# Coralogix Docs > Welcome to Coralogix Documentation. Get the help you need - find product docs, guides, developer tools and other learning resources or submit a ticket for any urgent requests. ## docs From quick fixes to mastery — Coralogix docs that move you forward. - [Coralogix Documentation](https://coralogix.com/docs/index.md): From quick fixes to mastery — Coralogix docs that move you forward. ### User Guides - [RBAC permissions](https://coralogix.com/docs/user-guides/aaa/access-control/permissions.md): Coralogix offers a flexible access management system with role-based permissions. - [Permissions list](https://coralogix.com/docs/user-guides/aaa/access-control/permissions/permissions-list.md): Coralogix offers a flexible access management system with role-based permissions. - [Access policies](https://coralogix.com/docs/user-guides/aaa/access-control/policies.md): Policy-based access control lets you set resource-level access rules on top of your role-based permissions in Coralogix. - [Application and subsystem names](https://coralogix.com/docs/user-guides/account-management/account-settings/application-and-subsystem-names.md): In order for us to help you make sense of your logs, metrics, and traces, we require that you organize your data using two metadata fields: application and subsystem name. These values will ultimately give value to your data in a manner that is most meaningful for you on your Coralogix Dashboard. Completely customizable, you can use them to catalogue and filter your logs and metrics, grant different user permissions and access to different employees, create log templates and template branches, and track anomalies in your data most efficiently. - [Coralogix domain](https://coralogix.com/docs/user-guides/account-management/account-settings/coralogix-domain.md): Coralogix offers independent domains around the globe allowing you to maintain compliance with local data storage requirements. The domain where your account is hosted will determine the endpoint for your integrations, API configurations, and more. - [General settings](https://coralogix.com/docs/user-guides/account-management/account-settings/general-settings.md): Coralogix provides you with an easy way to manage your team settings. In this short tutorial we will show you how. - [Notifications preferences](https://coralogix.com/docs/user-guides/account-management/account-settings/notifications-preferences.md): Select which automated Coralogix notifications you receive by email or Slack, and filter them to the applications and subsystems you care about. - [Session length](https://coralogix.com/docs/user-guides/account-management/account-settings/session-length.md): As part of their user management, team administrators can define the duration of idle sessions for all team members. Enabling this option will end all current login sessions after a period of time and require users to log in again. - [Team ID](https://coralogix.com/docs/user-guides/account-management/account-settings/team-id.md): This section shows how to access your Coralogix Team ID. - [API keys](https://coralogix.com/docs/user-guides/account-management/api-keys/api-keys.md): Coralogix API Keys offer a robust and flexible way to manage access and permissions within your organization. By using API keys, you can generate personal or shared keys through Coralogix's adaptable RBAC management system. This system allows you to assign specific permissions or groups of permissions, known as role presets, to each API key, ensuring precise control over access and operations. - [Send-Your-Data API key](https://coralogix.com/docs/user-guides/account-management/api-keys/send-your-data-api-key.md): In order to send your data to Coralogix, you are required to access and use your unique Coralogix Send-Your-Data API key. This tutorial demonstrates how to access the default Send-Your-Data API key associated with your Coralogix account, as well as to add unlimited Send-Your-Data API keys with advanced security settings. - [Handling PII and sensitive data](https://coralogix.com/docs/user-guides/account-management/data-privacy/handling-pii-and-sensitive-data.md): To ensure compliance with Coralogix's service terms and data privacy regulations, it is essential to anonymize personal data before sending it to the Coralogix platform. - [Infrastructure](https://coralogix.com/docs/user-guides/account-management/fair-usage/Infrastructure.md): Understand the fair usage limits for Infrastructure Explorer, what they mean, how they’re enforced, and how to monitor your usage. - [Infrastructure](https://coralogix.com/docs/user-guides/account-management/fair-usage/infrastrucutre.md): Understand the fair usage limits for Infrastructure Explorer, what they mean, how they’re enforced, and how to monitor your usage. - [Ingestion & query limits](https://coralogix.com/docs/user-guides/account-management/fair-usage/limits.md): This guide outlines the metering limits Coralogix applies to metrics usage per team. - [Metrics](https://coralogix.com/docs/user-guides/account-management/fair-usage/monitoring-limits.md): Effectively monitor and manage fair usage limits to prevent ingestion delays, performance degradation, or service interruptions. - [Understanding fair usage limits](https://coralogix.com/docs/user-guides/account-management/fair-usage/overview.md): Fair usage limits provide transparency, predictability, and control over platform usage. - [Organizational grouping](https://coralogix.com/docs/user-guides/account-management/organization-management/coralogix-entities.md): Coralogix divides users into the following logical units: Organizations, Teams, & Groups. - [Create an organization](https://coralogix.com/docs/user-guides/account-management/organization-management/create-an-organization.md): Coralogix offers the option of collectively managing multiple teams per organization via an Organization Administrator. - [Organization admin console](https://coralogix.com/docs/user-guides/account-management/organization-management/organization-admin-console.md): Coralogix supports multi-tenancy, allowing multiple teams to be connected under a single organization. Some companies prefer separate teams to isolate data based on the environment it originates from like Infrastructure, Security, and Application. Coralogix allows you to associate multiple teams with an Organization. - [Manage admins](https://coralogix.com/docs/user-guides/account-management/organization-management/organization-admins.md): Use the Manage Admins page to view, add, and remove Organization Administrators belonging your organization. - [Organization settings](https://coralogix.com/docs/user-guides/account-management/organization-management/organization-domains.md): As Organization Administrator, you can manage your Organization Settings to determine permissions for new users and which domains are allowed to connect to your organization. - [Quota manager](https://coralogix.com/docs/user-guides/account-management/organization-management/quota-management-across-organizations.md): Use Quota Manager to review quota consumption across teams and rebalance units to reduce blocking and improve utilization. - [AI Units pricing](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/ai-units-pricing.md): Understand how AI usage is measured and billed in AI Units across Coralogix AI features, including per-model token rates and AI Center policy pricing. - [Data usage metrics](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/data-usage-metrics.md): Enable Data Usage Metrics for an added layer of granularity in your data usage overview. Use it to create custom dashboards, insights, alerts, and useful summaries of your data. - [Data Usage settings panel](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/data-usage-settings-panel.md): Configure Data Usage visibility: enable the metrics ingestion pipeline and the dataplan.usage_events system dataset from a single panel. - [Data usage](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/data-usage.md): Understand how data usage is calculated, monitored, and reported in Coralogix. - [Metrics cost optimizer](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-optimization.md): Coralogix metrics optimization mechanism helps you improve system observability while reducing costs. Drop irrelevant metrics even after their ingestion to reduce data storage and processing costs. - [Metric usage analysis](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-usage-analyzer.md): Metrics Usage Analyzer helps you track ingested metrics and labels, detect high-cardinality or wasteful data, and optimize your observability pipeline for cost and performance. - [Service Governance](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-usage-analyzer/apm.md): Service Governance gives each APM service its own ingestion budget across the 16 APM spanmetrics. Use the APM Metrics tab in the Metrics Usage Analyzer to attribute APM volume and time series per service, find services approaching their limit, and act before they reach it. - [Explore tab](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-usage-analyzer/explore-tab.md): Use the Explore tab in the Metrics Usage Analyzer to identify which label values contribute most to a metric's cardinality. - [Labels](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-usage-analyzer/labels.md): Use the Labels tab in the Metrics Usage Analyzer to analyze label-level impact on storage and cardinality. - [Variations](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/metrics-usage-analyzer/variations.md): Use the Variations tab in the Metrics Usage Analyzer to break down how label combinations affect a metric's volume and cardinality. - [Optimize metrics costs in Coralogix by adjusting your scrape interval](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/optimize-metrics-costs-in-coralogix-by-adjusting-your-scrape-interval.md): Coralogix's metrics costs are influenced by the amount of metric data ingested, which is significantly impacted by the scrape interval settings of your OpenTelemetry Collector or Prometheus Agent. Adjusting your scrape intervals allows for more effective data ingestion management, leading to optimized costs and efficient usage. - [Pay-As-You-Go](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/pay-as-you-go.md): Pay-as-you-go is an option that offers flexibility to ingest up to one time your contractual quota without commitment. - [Plan and payments management](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/plan-and-payments-management.md): Choose and manage your Coralogix plan, payments, credit card and invoices easily. - [Query drilldown view](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/query-drilldown.md): Investigate how a query pattern behaves across your environment, including usage, failures, and execution context. - [Query usage analyzer](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/query-usage-analyzer.md): Use Query Analyzer to see how metrics are queried across your observability environment. Use it to identify usage patterns, track query frequency and success rates, and optimize metric costs and data hygiene. - [Live error logs](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/query-usage-analyzer/live-error-logs.md): View real-time error logs for failed query executions directly within the Query Pattern drilldown in the Query Usage Analyzer. - [Quota management](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/quota-management.md): Manage team quotas in your Coralogix account using the following tutorial. - [Quota Rules](https://coralogix.com/docs/user-guides/account-management/payment-and-billing/quota-rules.md): Quota rules in Coralogix allow you to define hard limits on the volume of data or AI interactions consumed by entity type—such as logs, metrics, spans, or AI agent interactions—to maintain control over resource usage, prevent unexpected costs, and ensure operational stability. - [TCO Optimizer](https://coralogix.com/docs/user-guides/account-management/tco-optimizer.md): The TCO Optimizer routes logs and traces to the right priority based on business value. Define policies using DPXL expressions or the Builder, preview matched data before saving, and control cost, retention, and feature access across High (Frequent Search), Medium (Monitoring), and Low (Compliance) priorities. - [Groups](https://coralogix.com/docs/user-guides/account-management/user-management/assign-user-roles-and-scopes-via-groups.md): Groups are a powerful tool in Coralogix for bringing the right people together around the right data. - [Create and manage groups](https://coralogix.com/docs/user-guides/account-management/user-management/assign-user-roles-and-scopes-via-groups/create-and-manage-groups.md): Once you have created one or more roles, you can include them in a new group. Follow the guide below to create and manage groups. To do so, you need the required permissions. - [Configure organization-level SAML SSO](https://coralogix.com/docs/user-guides/account-management/user-management/configure-org-level-saml.md): Learn how to configure organization-level SAML SSO in Coralogix: define a SAML identity provider once, assign it to multiple teams, manage default groups per team, and control the sign-in and provisioning experience. - [Manage teams](https://coralogix.com/docs/user-guides/account-management/user-management/create-and-manage-teams.md): The My Teams page allows Organization Administrators (Org Admins) to manage their teams from a single convenient location. - [Create teams](https://coralogix.com/docs/user-guides/account-management/user-management/create-teams.md): Manage your users and their associated roles and permissions across Coralogix teams. - [Sign in with email and password](https://coralogix.com/docs/user-guides/account-management/user-management/local-login.md): Sign in to Coralogix with your email and password, complete two-factor authentication if enrolled, and pick the team you want to work in. - [Login access policy](https://coralogix.com/docs/user-guides/account-management/user-management/login-access-policy.md): Control who can log in to your Coralogix team by listing the IP addresses and email domains allowed to access it. - [Login methods](https://coralogix.com/docs/user-guides/account-management/user-management/login-methods.md): Compare Coralogix sign-in options — local login, single sign-on, and two-factor authentication — and pick the right combination for your team. - [Manage team members](https://coralogix.com/docs/user-guides/account-management/user-management/manage-team-members.md): The Coralogix platform is built on a logical administrative hierarchy designed to help organizations manage user access with precision and flexibility. - [Multi-SAML for SSO](https://coralogix.com/docs/user-guides/account-management/user-management/multi-saml-for-sso.md): Learn how to enable and manage multiple SAML identity provider (IdP) configurations for Single Sign-On (SSO) within the same Coralogix team or organization, supporting parallel IdPs, migrations, and secure access across diverse user groups. - [OAuth Clients](https://coralogix.com/docs/user-guides/account-management/user-management/oauth-clients.md): Register and manage OAuth clients — including embedded Coralogix views — for the applications and services that call Coralogix APIs on a user's behalf. - [OAuth 2.1](https://coralogix.com/docs/user-guides/account-management/user-management/oauth.md): Coralogix supports OAuth 2.1 with OpenID Connect (OIDC) for authentication and authorization across AI-powered and self-registered integrations. - [SCIM](https://coralogix.com/docs/user-guides/account-management/user-management/scim.md): Coralogix supports the SCIM specification (System for Cross-Domain Identity Management), an open standard that allows you to automate user and group provisioning using a REST API. - [Scopes](https://coralogix.com/docs/user-guides/account-management/user-management/scopes.md): Create and assign scopes to ensure data is only accessible to authorized users. - [Set up two-factor authentication](https://coralogix.com/docs/user-guides/account-management/user-management/secure_login/mfa.md): With 2FA enabled, you log in with your password and a time-based one-time code from an authenticator app. This extra step helps protect your account from unauthorized access. - [SSO with SAML](https://coralogix.com/docs/user-guides/account-management/user-management/sso-with-saml.md): Coralogix provides full SAML 2.0 support so you can integrate with your chosen IdP and manage your Coralogix users' SSO login in a centralized way. Here you can find the walkthrough process for integrating with the common IdPs in the market, don't hesitate to contact us via the chat bubble within our web app if you have any questions or comments. - [Teams](https://coralogix.com/docs/user-guides/account-management/user-management/teams.md): Manage your users and their associated roles and permissions across Coralogix teams. - [LangGraph](https://coralogix.com/docs/user-guides/ai-observability/setup/langGraph.md): OpenTelemetry instrumentation for LangGraph is designed to trace graph node executions and simplify the debugging of stateful, multi-step LLM workflows. - [AI observability and guardrails](https://coralogix.com/docs/user-guides/ai.md): AI Center is a complete platform for AI-powered applications — combining observability, guardrails, evaluations, and AI SPM in one place. - [AI Center alerts and metrics](https://coralogix.com/docs/user-guides/ai/alerts.md): Deploy a prebuilt observability pack — five Events2Metrics rules and five metric threshold alerts — for monitoring AI applications. - [Monitor your applications](https://coralogix.com/docs/user-guides/ai/app_catalog.md): Track health, performance, cost, errors, and latency across all your AI applications in AI Center. - [Classic ML observability](https://coralogix.com/docs/user-guides/ai/classic_ml_observability.md): Classic ML Observability for Coralogix is hosted on the Aporia documentation site. - [Code Agents Intelligence](https://coralogix.com/docs/user-guides/ai/code-agents.md): Monitor AI coding agent activity—token usage, costs, tool calls, code changes, repository attribution, and per-user session data—directly in Coralogix. - [Claude Code & Cowork](https://coralogix.com/docs/user-guides/ai/code-agents/claude-code.md): What's on the Claude dashboard in Code Agents Intelligence — cost, code impact, and per-user activity. - [Codex CLI](https://coralogix.com/docs/user-guides/ai/code-agents/codex.md): What's on the Codex CLI dashboard in Code Agents Intelligence — tokens, sessions, latency, and per-user activity. - [Copilot](https://coralogix.com/docs/user-guides/ai/code-agents/copilot.md): What's on the Copilot dashboard in Code Agents Intelligence — cost, optimization insights, feature and IDE usage, code impact, and per-user activity. - [Cursor](https://coralogix.com/docs/user-guides/ai/code-agents/cursor.md): What's on the Cursor dashboard in Code Agents Intelligence — sessions, lines of code, model and tool usage, and per-user activity. - [Repository breakdown](https://coralogix.com/docs/user-guides/ai/code-agents/repository-breakdown.md): See how code-agent activity splits across the repositories it touches, and classify those repositories as Managed or Unmanaged by configuring Organizations in AI Center. - [Screenshots](https://coralogix.com/docs/user-guides/ai/code-agents/repository-breakdown/images.md): Images referenced by ../index.md: - [Optimize AI costs](https://coralogix.com/docs/user-guides/ai/cost.md): Track AI spend across your organization and per application, compare model and user cost, override per-token model pricing, and act on cost-pattern insights detected from live span data. - [Evaluations](https://coralogix.com/docs/user-guides/ai/evaluations.md): Evaluate the quality and safety of your AI applications using prebuilt and custom policies in Coralogix AI Center. - [Custom evaluation policies](https://coralogix.com/docs/user-guides/ai/evaluations/custom_policies.md): Create and manage custom evaluation policies in Coralogix AI Center to measure what matters for your specific application. - [Prebuilt evaluation policies](https://coralogix.com/docs/user-guides/ai/evaluations/prebuilt_policies.md): Apply prebuilt evaluation policies in Coralogix AI Center to detect security issues, hallucinations, toxicity, topic violations, and compliance risks, and set a per-eval threshold for what counts as an issue. - [AI Explorer](https://coralogix.com/docs/user-guides/ai/explorer.md): Inspect individual LLM interactions at the span level, view evaluation results and guardrail actions, and trace the full request flow end-to-end in AI Center. - [AI Center FAQs](https://coralogix.com/docs/user-guides/ai/faqs.md): Common questions about AI Center scope, supported integrations, evaluations, pricing, and Code Agents billing impact. - [Getting started with AI observability](https://coralogix.com/docs/user-guides/ai/getting_started.md): Instrument your first LLM application with OpenTelemetry and send GenAI spans to Coralogix AI Center in a few minutes. - [Guardrails](https://coralogix.com/docs/user-guides/ai/guardrails.md): Intercept and block harmful, non-compliant, or low-quality AI outputs in real time using Coralogix Guardrails. - [Custom guardrail policies](https://coralogix.com/docs/user-guides/ai/guardrails/custom_policies.md): Define domain-specific guardrail policies using natural language instructions to protect your LLM applications against business-specific risks. - [Getting started](https://coralogix.com/docs/user-guides/ai/guardrails/getting_started.md): Integrate Coralogix Guardrails with your LLM application to protect against prompt injection, PII leakage, and other security threats. - [Guard API](https://coralogix.com/docs/user-guides/ai/guardrails/guard_api.md): Use the guard() method for full control over multi-turn conversation guardrail evaluation in Coralogix. - [PII](https://coralogix.com/docs/user-guides/ai/guardrails/pii.md): Detect and block personally identifiable information in LLM prompts and responses using the Coralogix Guardrails PII detection policy. - [Guardrails prebuilt policies](https://coralogix.com/docs/user-guides/ai/guardrails/prebuilt_policies.md): Apply ready-to-use Coralogix Guardrails policies for prompt injection, PII detection, and toxicity to protect your LLM applications in real time. - [Prompt injection](https://coralogix.com/docs/user-guides/ai/guardrails/prompt_injection.md): Detect and block prompt injection attacks in your LLM applications using the Coralogix Guardrails prompt injection policy. - [Toxicity](https://coralogix.com/docs/user-guides/ai/guardrails/toxicity.md): Detect and block toxic, harmful, or offensive content in LLM prompts and responses using the Coralogix Guardrails toxicity policy. - [Integrations for LLM observability](https://coralogix.com/docs/user-guides/ai/integrations.md): Connect LLM providers and frameworks to Coralogix AI Center for end-to-end visibility into your AI applications. - [Monitor AI applications](https://coralogix.com/docs/user-guides/ai/monitor.md): Monitor health, performance, cost, quality, and security posture across all AI applications in AI Center. - [OpenTelemetry integration for AI Center](https://coralogix.com/docs/user-guides/ai/otel-integration.md): Send GenAI spans to Coralogix AI Center using the standard OpenTelemetry GenAI semantic conventions — vendor-neutral, no Coralogix-specific SDK required. - [Code examples](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples.md): Copy-pasteable scripts that send OpenTelemetry GenAI spans to Coralogix using the new semantic conventions, in Python, Java, .NET, and Go. - [Anthropic / Claude](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/anthropic-claude.md): Auto-instrument the Anthropic Claude SDK with OpenTelemetry and send GenAI spans to Coralogix AI Center. - [AWS Bedrock](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/aws-bedrock.md): Auto-instrument AWS Bedrock (botocore) with OpenTelemetry and send GenAI spans to Coralogix AI Center using the new semantic conventions. - [.NET — Microsoft.Extensions.AI](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/dotnet.md): Send GenAI spans to Coralogix AI Center from .NET using Microsoft.Extensions.AI, which implements the new OpenTelemetry semantic conventions natively. - [Go — manual instrumentation](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/go-manual.md): Build GenAI spans by hand in Go with the OpenTelemetry SDK and net/http, and send them to Coralogix AI Center using the new semantic conventions. - [Google GenAI](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/google-genai.md): Auto-instrument the Google GenAI SDK with OpenTelemetry and forward GenAI spans to Coralogix AI Center through a local collector. - [Java — manual instrumentation](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/java-manual.md): Build GenAI spans by hand in Java with the OpenTelemetry SDK and send them to Coralogix AI Center using the new semantic conventions. - [OpenAI Agents SDK](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/openai-agents-sdk.md): Auto-instrument the OpenAI Agents SDK with OpenTelemetry and send GenAI spans to Coralogix AI Center using the new semantic conventions. - [OpenLLMetry (Traceloop) — Python](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/openllmetry.md): Use the OpenLLMetry (Traceloop) SDK to auto-instrument OpenAI calls and send GenAI spans to Coralogix AI Center. - [Python — manual instrumentation](https://coralogix.com/docs/user-guides/ai/otel-integration/code-examples/python-manual.md): Build GenAI spans by hand in Python with the OpenTelemetry SDK and raw HTTP — a universal template for any provider or language. - [Compatibility matrix](https://coralogix.com/docs/user-guides/ai/otel-integration/providers.md): Verified OpenTelemetry GenAI instrumentation libraries for each LLM provider and framework. Coralogix AI Center accepts spans from any instrumentation that emits the conventions. - [Span attribute inventory](https://coralogix.com/docs/user-guides/ai/otel-integration/span-attributes.md): Complete inventory of gen_ai.* span attributes consumed by Coralogix AI Center. - [AI Center permissions](https://coralogix.com/docs/user-guides/ai/permissions.md): Required roles and permissions for accessing and managing AI Center features in Coralogix. - [AI security posture management](https://coralogix.com/docs/user-guides/ai/spm.md): AI Security Posture Management (AI SPM) gives CISOs and security teams a holistic view of AI usage within their organization, enabling them to identify risks and enforce security best practices. - [Alert aggregation](https://coralogix.com/docs/user-guides/alerting/alert-aggregation.md): You can aggregate your alerts and then display them as a widget on a custom dashboard using a gauge-type metric (cx_alerts). When alert-to-metric is enabled, all alerts start to be accumulated into bucket. The number of triggered/resolved alerts is calculated per minute, creating a time series per every permutation. - [Alert definition management](https://coralogix.com/docs/user-guides/alerting/alert-definition-management.md): Create, view, filter, and manage all your alert definitions in a single place with real-time status, labels, and quick actions for fast operational control. - [Alert drill-down view](https://coralogix.com/docs/user-guides/alerting/alert-drill-down.md): Use the Alert Drill-Down view to investigate why an alert fired — explore query logic, trigger conditions, schedules, and live charts to validate and refine alert behavior. - [Suppression Rules](https://coralogix.com/docs/user-guides/alerting/alert-suppression-rules.md): Use Suppression Rules to mute alert notifications during scheduled maintenance, testing, auto-scaling events, or outside working hours. - [Alerts map](https://coralogix.com/docs/user-guides/alerting/alerts-map.md): Alerts Map presents users with a visual representation of each alert status in real-time. Grouping all of your alerts in a scalable, information-dense manner, Coralogix ensures optimal system monitoring. - [Customizing anomaly detection alert sensitivity](https://coralogix.com/docs/user-guides/alerting/anomaly-detection-deviation-percentage.md): Tailor alert sensitivity for both logs and metrics-based anomaly detection alerts. - [Notification settings](https://coralogix.com/docs/user-guides/alerting/configure-notifications/settings.md): Decide what an alert is for: open a Case, or send a Signal-Based notification routed by label to the right connector and preset. - [Alerts as a notification source type](https://coralogix.com/docs/user-guides/alerting/configure-notifications/source-type-schema.md): This tutorial describes entity types and subtypes for Notification Center. - [Configure an alert definition](https://coralogix.com/docs/user-guides/alerting/configuring-alert-definition.md): Build alert definitions in Coralogix with a guided wizard that walks you from query to condition to notification to details, so every choice is informed by the context you have already set. - [Coralogix reporter](https://coralogix.com/docs/user-guides/alerting/coralogix-reporter.md): Coralogix reporter allows you to automate the generation of a periodic report that includes the formatted results of a predefined OpenSearch Query. This report can be distributed automatically to a mailing list. - [Flow alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/flow-alerts.md): Trigger an alert only when a defined sequence of other alerts occurs in order within a time window. - [Anomaly detection alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/anomaly-detection-alerts.md): Anomaly detection alerts learn a baseline from your logs and fire when counts deviate from it, so you catch unusual behavior without maintaining static thresholds. - [Dataset alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/dataset-alerts.md): Use dataset alerts to run log-based alerts on any logs-compatible dataset, target system datasets, and keep your alerting aligned with how your data is organized. - [Immediate notifications](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/immediate-notifications.md): Notify on every matching log as it arrives, with no aggregation window, so you catch one-off events the moment they happen. - [New value alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/new-value-alerts.md): Trigger an alert when a previously unseen value appears in a log field within a time window. Use new value alerts to catch new domains, new error codes, and other first-time occurrences. - [Ratio alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/ratio-alerts.md): Calculate the ratio between two log queries and trigger an alert when it crosses a threshold. Use ratio alerts to track error rates, regional traffic share, and denied-request proportions. - [Threshold alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/threshold-alerts.md): Trigger an alert when the count of matching logs crosses a fixed threshold over a time window. Use threshold alerts to catch error spikes, traffic drops, and volume changes. - [Time relative alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/time-relative-alerts.md): Time relative alerts compare current log counts against the same window in a prior period, so you catch shifts in behavior that a fixed threshold would miss. - [Unique count alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/unique-count-alerts.md): Unique count alerts fire on the number of distinct values in a log field, so you can measure the breadth of an issue, such as how many users encountered a 5XX error, not just that it happened. - [Anomaly detection alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/anomaly-detection-alerts.md): Detect metric behavior that deviates from a learned baseline, without defining static thresholds. - [Custom webhooks: metric alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/custom-webhooks-metric-alerts.md): Route metric alert notifications to custom outbound webhooks through the alert wizard's Notification step. - [Immediate notifications](https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/immediate-notifications.md): Notify on every matching metric sample as it arrives, with no aggregation window, for time-sensitive metric signals. - [Threshold alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/threshold-alerts.md): Trigger when a metric crosses a threshold you define over a time window, with control over duration and missing-data behavior. - [Tracing alerts](https://coralogix.com/docs/user-guides/alerting/create-an-alert/traces/tracing-alerts.md): Alert on spans that exceed a latency threshold across the services and tags you select, using a trace count condition. - [Custom evaluation delay](https://coralogix.com/docs/user-guides/alerting/custom-evaluation-delay.md): The Custom Evaluation Delay feature helps mitigate false alerts by shifting an alert's evaluation timeframe backward by a configurable amount. - [Define alert details](https://coralogix.com/docs/user-guides/alerting/define-alert-details.md): Reference for the Details step of the alert creation wizard: name, description, labels, case settings, and scheduling. - [Getting started with alerts](https://coralogix.com/docs/user-guides/alerting/getting-started.md): Create your first Coralogix alert: sign up, send data, and configure an alert definition, with an interactive walkthrough of the alert builder. - [Incidents](https://coralogix.com/docs/user-guides/alerting/incidents.md): View, filter, and manage triggered alert events. Drill down into incidents to investigate underlying logs, metrics, and traces. - [Alerting](https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts.md): Detect anomalies, respond to incidents, and reduce mean time to resolution with Coralogix alerts across logs, metrics, and traces. - [Create metric alerts from logs](https://coralogix.com/docs/user-guides/alerting/log2metric.md): Create a metric alert from a numeric log field. Coralogix generates the Events2Metrics configuration and alert, and shows historical values during setup. - [Build log queries with the Lucene query builder](https://coralogix.com/docs/user-guides/alerting/lucene-query-builder.md): Create structured log queries without writing raw Lucene syntax. The Lucene Query Builder helps you filter logs by selecting fields, operators, and values from your data. - [Understand query behavior in alerts and incident views](https://coralogix.com/docs/user-guides/alerting/lucene-query-builder/query-behavior.md): Understand how Lucene queries behave differently in real-time alert evaluation compared to the archived data shown in Case and Incident views. Learn which query patterns to avoid and how to write reliable alert queries. - [Metric based query](https://coralogix.com/docs/user-guides/alerting/metric-based-query.md): Configure metric-based queries using the Query Builder to define alert conditions, filter data, apply functions, and analyze metric behavior over time. - [Create alert conditions](https://coralogix.com/docs/user-guides/alerting/multiple-alert-conditions.md): When setting up a Coralogix alert condition, you may configure up to five condition rules, each with a threshold, timeframe, and individual priority. - [No data state](https://coralogix.com/docs/user-guides/alerting/no-data.md): Learn how no-data handling controls alert behavior when queries return no results, and how to select the correct no-data strategy for metric and log alerts. - [Alert webhook with GCP Chat](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/alert-webhook-with-gcp-chat.md): Configuring a Google chat webhook with Coralogix can easily be done using a custom webhook integration as shown in this tutorial. - [Alert webhook with VictorOps](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/alert-webhook-with-victorops.md): Coralogix allows for the easy creation of webhooks integrations with other services like VictorOps. - [AWS EventBridge outbound webhook](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/aws-eventbridge-outbound-webhook.md): Amazon EventBridge serves as a serverless event bus service, facilitating the collection and transmission of data from various applications and services to designated destinations. Employ the AWS EventBridge Outbound Webhook to establish a streamlined real-time mechanism, enabling Coralogix to transmit events to AWS EventBridge. - [Configure alert notifications for outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/configure-alert-notifications-for-outbound-webhooks.md): Outbound Webhooks, or alert webhooks, offer a streamlined way to receive immediate notifications for critical events in the form of alerts, facilitating prompt responses to incidents. This tutorial guides you through configuring your outgoing webhook notification settings and associating each webhook with multiple alerts. - [Create alerting email Templates with Coralogix](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/create-alerting-email-templates-with-coralogix.md): With Coralogix, you can create alerting email templates using our custom alert webhooks. These templates allow you to embed details from a log, metric, trace, or security event that triggered an event into your email subject or body, resulting in easier and more informative email notifications. - [Email group outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/email-group-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to an Email group, a pre-defined group of email recipients. With this outbound webhook, you can easily automate responses to critical events, optimizing your organization's incident management and alerting processes. - [Generic outbound webhooks (alert webhooks)](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/generic-outbound-webhooks-alert-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to any endpoint that accepts HTTP requests. With this generic outbound webhook, you can easily integrate Coralogix with different endpoints, automate responses to critical events, and improve your organization's incident management and alerting processes. - [Jira outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/jira-outbound-webhooks.md): Automatically create issues in Jira when alerts trigger in Coralogix. Route critical events to your incident workflow, reduce manual triage, and keep your team aligned. - [Microsoft Teams outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/microsoft-teams-outbound-webhooks.md): Microsoft has retired Office 365 connectors (the Incoming Webhook connector) in Microsoft Teams: - [Opsgenie outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/opsgenie-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to Opsgenie using this outbound webhook. - [PagerDuty outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/pagerduty-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to PagerDuty. With this outbound webhook, you can integrate Coralogix with PagerDuty, automate responses to critical events, and improve your organization's incident management and alerting processes. - [Send log outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/send-log-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to Coralogix. With this webhook, you can easily receive logs in Coralogix, automate responses to critical events, and improve your organization's incident management and alerting processes. - [Slack outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/slack-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to Slack. With this outbound webhook, you can easily integrate Coralogix with Slack, automate responses to critical events, and improve your organization's incident management and alerting processes. - [Workflow-based Microsoft Teams outbound webhooks](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/workflow-based-microsoft-teams-outbound-webhooks.md): Enhance your observability workflows by sending real-time event notifications and log data to Microsoft Teams. With this outbound webhook, you can easily integrate Coralogix with Microsoft Teams, automate responses to critical events, and improve your organization's incident management and alerting processes. - [Zenduty](https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/zenduty.md): Coralogix supports integration with Zenduty. - [Saved views in Alerts](https://coralogix.com/docs/user-guides/alerting/saved-views.md): Save and reuse filtered Alert Management views so you can return to common monitoring workflows without reapplying queries, filters, and table settings each time. - [Troubleshoot alerting](https://coralogix.com/docs/user-guides/alerting/troubleshooting.md): Diagnose and resolve common alerting issues in Coralogix, including alerts not triggering, delayed notifications, false positives, anomaly detection problems, and suppression rule behavior. - [Analyze](https://coralogix.com/docs/user-guides/apm/features/analyze.md): The Analyze tab in Service Catalog provides an automated, trace-based dependency map for any instrumented service. - [Apdex score](https://coralogix.com/docs/user-guides/apm/features/apdex-score.md): Take advantage of our Apdex Score widget to measure and quantify user satisfaction in your Coralogix Service Catalog. - [API error tracking](https://coralogix.com/docs/user-guides/apm/features/api-error-tracking.md): API Error Tracking simplifies debugging of backend services by assembling thousands of similar API errors into a single group. - [Comparison mode](https://coralogix.com/docs/user-guides/apm/features/comparison-mode.md): You can use service Comparison mode to view the current requests, errors, or latency compared to data from 1, 2, 7 days ago, previous consecutive period or custom timeframe). Thus, you can see how different service performance metrics change or evolve across different time periods. - [Database monitoring](https://coralogix.com/docs/user-guides/apm/features/database-monitoring.md): Part of Application Performance Monitoring, Coralogix’s Databases monitoring offers comprehensive insights into databases and service-database interactions across your host environment, enabling efficient and rapid troubleshooting of issues as they emerge. - [Dependencies](https://coralogix.com/docs/user-guides/apm/features/dependencies/introduction.md): Dependencies monitors and analyzes how your instrumented services interact with databases, external APIs, third-party libraries, and other microservices. - [View database queries](https://coralogix.com/docs/user-guides/apm/features/dependencies/view-database-queries.md): View database queries to analyze database query patterns, uncover slow or failing dependencies, and trace them back to the root transactions that initiated them. - [View external calls](https://coralogix.com/docs/user-guides/apm/features/dependencies/view-external-calls.md): Use external calls to analyze patterns, identify slow or failing dependencies, and trace them back to the root transactions that triggered them. - [Environment filter](https://coralogix.com/docs/user-guides/apm/features/environment-filter.md): The Environment filter provides an easy and consistent way to query, filter, and group APM telemetry data by environment. - [Event markers](https://coralogix.com/docs/user-guides/apm/features/event-markers.md): Correlate metric changes on APM service pages with the deployments and events that caused them. - [Group by service version](https://coralogix.com/docs/user-guides/apm/features/group-by-service-version.md): You can monitor your service health by displaying metrics for each version of your service. Use this data to track changes resulting from version updates or multiple service versions running in parallel. - [Monitoring with alerts](https://coralogix.com/docs/user-guides/apm/features/monitoring-with-alerts.md): Manage alerts within your APM interface to monitor critical metrics and receive timely notifications about potential issues. - [Monitor operations](https://coralogix.com/docs/user-guides/apm/features/operations.md): The Operations tab breaks a service down into its incoming, outgoing, and internal operations, with per-operation response time, throughput, and errors so you can find the slowest, busiest, or most error-prone endpoints and drill into their spans. - [Runtime metrics](https://coralogix.com/docs/user-guides/apm/features/runtime-metrics.md): The Runtime metrics tab in Service Catalog brings JVM internals — heap, GC, threads, CPU, and class loading — onto the same screen as traces and span metrics. - [Send JVM metrics](https://coralogix.com/docs/user-guides/apm/features/runtime-metrics/send-jvm-metrics.md): Make a Java, Scala, or Kotlin service emit JVM runtime metrics in the OpenTelemetry format so they appear in the Runtime metrics tab. - [Serverless monitoring](https://coralogix.com/docs/user-guides/apm/features/serverless-monitoring.md): Our Serverless Monitoring feature provides customers using the Coralogix AWS Lambda Telemetry Exporter with the ability to better control and understand your Lambda servers on both macro and granular levels. - [Service Catalog](https://coralogix.com/docs/user-guides/apm/features/service-catalog.md): The Service Catalog offers a centralized, data-rich resource for managing and optimizing the services within your system. It provides a holistic view of service health, enabling better decision-making and faster issue resolution, ultimately improving the performance and reliability of your entire system. - [Alert-based service health](https://coralogix.com/docs/user-guides/apm/features/service-health/alert-based-service-health.md): Alert-based Service Health in APM provides an immediate, visual traffic light assessment of the operational state of your monitored services within Coralogix. - [Policy-based service health](https://coralogix.com/docs/user-guides/apm/features/service-health/policy-based-service-health.md): Policy-based Service Health enhances the Service Health feature by automatically evaluating predefined health policies against your monitored services. - [Service Map](https://coralogix.com/docs/user-guides/apm/features/service-map.md): Our Service Map application performance monitoring feature provides a full visualization of your system architecture, breaking down your application into all its constituent services and drawing the observed dependencies between these services in real time on the basis of your distributed tracing. - [Service Level Objectives (SLOs)](https://coralogix.com/docs/user-guides/apm/features/service-slos.md): Service Level Objective (SLO) is a measurable target that defines the acceptable performance or reliability level for a service, often expressed as a percentage. - [Monitor transactions](https://coralogix.com/docs/user-guides/apm/features/transactions.md): Purpose-built for microservices-based environments, the Coralogix Transactions feature lets you investigate the radius of impact of different services over time and troubleshoot issues immediately as part of Application Performance Monitoring. - [Aligning Coralogix and OTel naming conventions](https://coralogix.com/docs/user-guides/apm/getting-started/aligning-coralogix-and-otel-naming-conventions.md): OpenTelemetry sometimes introduces breaking changes that, if left unaddressed, can disrupt the experience for customers upgrading to newer versions. To prevent this, enable a `transform` statement to ensure that span attributes and metric labels conform to Coralogix-supported label conventions. - [APM onboarding](https://coralogix.com/docs/user-guides/apm/getting-started/apm-onboarding-tutorial.md): This guide provides step-by-step instructions on configuring and using Coralogix Application Performance Monitoring (APM). - [Migration from event2metrics to span metrics](https://coralogix.com/docs/user-guides/apm/getting-started/migration-from-e2m.md): This guide explains how to transition from Events2Metrics (E2M)to Span Metrics. Span Metrics offers complete APM metric coverage, improved performance, lower cardinality risk, and tighter integration with OpenTelemetry—all without relying on custom E2M rules. - [Span metrics cardinality limiting](https://coralogix.com/docs/user-guides/apm/getting-started/span-metrics-cardinality-limits.md): Span Metrics convert spans into metrics (for example, requests, errors, and duration). When spans or metric labels include many unique values, you might see a high number of time series. This can degrade performance, increase cost, and break dashboards. - [Quick start](https://coralogix.com/docs/user-guides/apm/getting-started/span-metrics-quick-start.md): Configure Span Metrics using the method that applies to your environment. - [Recommended configurations](https://coralogix.com/docs/user-guides/apm/getting-started/span-metrics-recommended-configuration.md): Use this guide to configure Span Metrics for production environments, optimize performance, and integrate features such as sampling, latency buckets, setting metric expiration, Serverless environment, and more. - [Getting started with span metrics](https://coralogix.com/docs/user-guides/apm/getting-started/span-metrics.md): Span Metrics offers an automated method of transforming and aggregating trace data into metrics outside Coralogix using the OpenTelemetry Span Metrics Connector - [Using compact span metric](https://coralogix.com/docs/user-guides/apm/getting-started/using-compact-span-metric.md): The compact span metric is an optimized metric type designed to improve the performance of the APM Service Catalog and Database Catalog pages, especially in large-scale environments. - [Alert reasoning](https://coralogix.com/docs/user-guides/cases/alert-reasoning.md): See how an alert evaluated inside a Case, compare the engine's reading against the raw metric to spot data gaps, and open the alert's queries in Metrics Explorer, all without leaving the Case. - [Cases analytics](https://coralogix.com/docs/user-guides/cases/analytics.md): Measure operational performance across Cases with mean time metrics, group-level breakdowns, and saved analytics views so engineering managers, site reliability engineers, and team leads can answer reliability and workload questions without leaving the Cases page. - [Case sources](https://coralogix.com/docs/user-guides/cases/case-sources.md): See every source that can open a Coralogix Case, from Coralogix Alerts to Prometheus Alert Manager, and how each source creates and updates Cases. - [Cases vs Incidents](https://coralogix.com/docs/user-guides/cases/cases-incidents.md): Understand the differences between Cases and Incidents, including lifecycle behavior, investigation workflows, ownership management, noise reduction, and operational context to support effective issue management. - [Configure case creation and noise-reduction rules](https://coralogix.com/docs/user-guides/cases/cases-setting.md): Configure how and when Cases are created from Alerts, including filtering rules, suppression windows, and post-resolution cooldowns to reduce noise and ensure meaningful incident management. - [Explores from a Case](https://coralogix.com/docs/user-guides/cases/explores-from-a-case.md): Pivot from a Case into Logs Explorer, Spans Explorer, or APM Service Catalog with the Case time range and entity context already applied. - [Cases](https://coralogix.com/docs/user-guides/cases/overview.md): Coralogix Cases unifies related alerts into contextual, intelligent incidents, reducing noise, accelerating triage, and improving collaboration across teams. - [Cases PagerDuty integration](https://coralogix.com/docs/user-guides/cases/pagerduty-integration.md): Synchronize Coralogix Cases with PagerDuty incidents in both directions. Acknowledge, resolve, comment, and add resolution notes from either side and keep the Case and incident aligned. - [Prometheus Alert Manager triage](https://coralogix.com/docs/user-guides/cases/prometheus-alert-manager-triage.md): Connect Prometheus Alert Manager to Cases, triage the Cases it opens by inspecting each alert's labels, annotations, and PromQL, and link back to a Case from an Alert Manager notification. - [Set up Cases](https://coralogix.com/docs/user-guides/cases/quick-start.md): Set up Cases in Coralogix to unify related alerts into operational issues. Configure Case filtering rules, timing, noise reduction, notification routing, and optional ServiceNow integration. - [Cases saved views](https://coralogix.com/docs/user-guides/cases/saved-views.md): Save filtered Cases views to preserve query, filters, table settings, fields, and time range, then reload them from All views. - [Cases ServiceNow integration](https://coralogix.com/docs/user-guides/cases/sn-integration.md): Integrate Coralogix with ServiceNow to automatically create, update, and synchronize ServiceNow records from Coralogix Cases. - [Working with Cases](https://coralogix.com/docs/user-guides/cases/working-with-cases.md): The Cases view centralizes all triggered alerts into a single workspace, showing their state, status, priority, and category. It provides history, filtering, and drill-down tools to help teams investigate, prioritize, and resolve issues efficiently. - [Compare profiles](https://coralogix.com/docs/user-guides/continuous-profiling/compare-mode.md): Compare mode in Continuous Profiling allows you to see performance changes between two profiles. - [Upload debug symbols](https://coralogix.com/docs/user-guides/continuous-profiling/debug-symbols.md): Coralogix Continuous Profiling requires access to debug symbols to generate meaningful profiling insights. - [Welcome to Continuous Profiling](https://coralogix.com/docs/user-guides/continuous-profiling/introduction.md): With Coralogix Continuous Profiling, identify CPU and memory bottlenecks with detailed breakdowns by method name and line number. This allows for significant reductions in end-user latency and infrastructure expenses. - [Monitor CPU consumption](https://coralogix.com/docs/user-guides/continuous-profiling/monitoring-cpu.md): Continuous Profiling enables deep, function-level analysis of CPU usage across your services. - [Monitor memory consumption](https://coralogix.com/docs/user-guides/continuous-profiling/monitoring-memory.md): Use Continuous Profiling to analyze memory allocation patterns and live heap usage in Java services, identify memory-intensive functions, and optimize allocation behavior. - [Permissions](https://coralogix.com/docs/user-guides/continuous-profiling/permissions.md): Use the following permissions to enjoy Coralogix Continuous Profiling. - [Profiles catalog](https://coralogix.com/docs/user-guides/continuous-profiling/profiles-catalog.md): Profiles catalog extends APM Service Catalog with continuous profiling insights, allowing you to view and explore services even if they do not emit spans or metrics. Profiling data alone is enough to surface a service, giving you full coverage of runtime behavior alongside the rest of your APM workflows. - [Set up Continuous Profiling](https://coralogix.com/docs/user-guides/continuous-profiling/setup.md): With Coralogix Continuous Profiling, identify CPU and memory bottlenecks with detailed breakdowns by method name and line number. This allows for significant reductions in end-user latency and infrastructure expenses. - [Supported runtimes](https://coralogix.com/docs/user-guides/continuous-profiling/supported-languages.md): Runtime version ranges and symbolization details for every language Coralogix Continuous Profiling supports. - [Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/introduction.md): Coralogix Custom Dashboards give you a flexible, high-performance workspace to visualize logs, metrics, and traces—together, in real time. - [Permissions](https://coralogix.com/docs/user-guides/custom-dashboards/permissions.md): These permissions are required for engaging with Custom Dashboards. - [Add monitoring data to custom dashboard widgets](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/add-monitoring-data-to-custom-dashboard-widgets.md): Coralogix supports adding archive data to your custom dashboard widgets. This enables you to see data from the Monitoring (medium priority) tier in your custom dashboards in addition to the regular Frequent Search (high priority) data. - [Set auto refresh for Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/auto-refresh.md): Set a refresh interval on Custom Dashboards and Visual Explorer to automatically reload all widget data at a fixed cadence. - [Build a dynamic table widget](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/build-a-dynamic-table-widget.md): Learn how to create and configure a dynamic data table widget in Coralogix Custom Dashboards, including techniques for sorting, filtering, and flexible column management. - [Configure time interval for time-axis widgets](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/configure-time-interval.md): Learn how to set and optimize time intervals for time-based charts in Custom Dashboards, balancing visual detail and performance. - [Create alerts from custom dashboard widgets](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/create-alerts-from-custom-dashboard-widgets.md): Streamline your work process by creating alerts directly from your Custom Dashboard line chart widgets. Use the thresholds, variables and filters embedded in your widget to easily create alerts without ever leaving your custom dashboard. - [Create and manage custom actions](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/create-and-manage-custom-actions.md) - [Create and manage variables](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/create-and-manage-variables.md): Overview - [Create and manage annotations](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/create-annotations.md): Add Annotations in Custom Dashboards to provide rich contextual information about single points in time. - [Create metrics from your custom dashboard widget](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/create-metrics-from-your-custom-dashboard-widget.md): When you first create a dashboard, the data you're using may be raw data. However, creating visualizations often helps you to refine what information you're looking for from those logs or metrics. To enable you to take advantage of this refined data, Coralogix supports creating metrics from custom dashboard widgets.When creating a metric from a custom dashboard widget, the process depends on whether you are creating a metric from a metric, in which case you will create the new metric using a recording rule, or a log or span, in which case you will create the new metric using Events2Metric. - [Export widget data to CSV](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/export-widget-data-to-csv.md): A gallery of sample CSV files and images related to exporting widget data from custom dashboards. - [Import & export Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/import-and-export-custom-dashboards.md): Effortlessly share your custom dashboards within your organization by importing and exporting them, eliminating the need to recreate them and minimizing overhead. - [Linked widgets](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/linked-widgets.md): Reuse widgets from other dashboards by adding linked widgets to your Custom Dashboards. Linked widgets stay in sync with the source and can be unlinked for independent editing. - [Dashboards list and folders](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/manage-dashboard-catalog.md): Browse, organize, and manage your Custom Dashboards using the Dashboards List with folder-based organization, search, and drag-and-drop management. - [Manage dashboard settings](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/manage-dashboard-settings.md): The settings panel gives you centralized access to key dashboard options.. - [Manage dashboard version history](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/manage-dashboard-version-history.md): Learn how to track, restore, and manage previous versions of your custom dashboards in Coralogix for better collaboration and change control. - [Migrate from OpenSearch to Coralogix Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/migrate-from-opensearch-to-coralogix-custom-dashboards.md): Coralogix Custom Dashboards provides you with the ideal dashboard experience, allowing you to create unlimited, personalized custom dashboards using our five visualizations: Data Table, Line Chart, Gauge, Pie Chart and Bar Chart. Each visualization - supporting logs, metrics and spans - can be used to define and create a dashboard catered to your specific observability needs. - [Visualizing multiple queries in Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/multiple-queries-in-custom-dashboards.md): Learn how to make multiple queries in a single dashboard widget. - [Performance mode](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/performance-mode.md): Understand performance mode in Coralogix Custom Dashboards: when it engages on large charts, which interactions it disables, and how to restore full interactivity. - [Query builder](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/query-builder.md): Create complex queries easily using the Query Builder in Custom Dashboards. - [Replace a custom dashboard](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/replace-a-custom-dashboard.md): Update a Custom Dashboard in place by importing a JSON file. The dashboard keeps its original ID and URL, and the previous state is saved to version history. - [Save and schedule dashboard PDF reports](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/save-a-dashboard-as-a-pdf.md): Save any Custom Dashboard as a PDF or schedule recurring PDF reports to email recipients. Configure daily, weekly, or monthly cadences, sub-daily intervals, or custom cron expressions. - [Sections](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/sections.md): Sections in Custom Dashboards let you group and organize widgets into logical containers, making dashboards easier to read, manage, and reuse. - [Share dashboard content](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/share-dashboard-content.md): Learn all the ways to share dashboards, widgets, and sections from Custom Dashboards in Coralogix. - [Widget data loading](https://coralogix.com/docs/user-guides/custom-dashboards/tutorials/widget-data-loading.md): Choose between latest and fast loading for DataPrime widgets in Custom Dashboards to balance data freshness with dashboard load speed. - [Data tables](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/data-tables.md): Create a data table in Custom Dashboards to visualize logs, metrics, or spans. - [DataPrime widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/dataprime-widget.md): Coralogix's innovative DataPrime language empowers you to query your data and transform it through various operations tailored to your specific needs, such as calculation, extraction, and aggregation. - [Dynamic widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/dynamic-widget.md): Learn how to use the Dynamic Widget in Coralogix Custom Dashboards to automatically analyze your queries and get visualization suggestions based on your data. - [Basic gauges](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/gauges/basic-gauges.md): Create a customized gauge visualization in Custom Dashboards. - [Multi-Gauges](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/gauges/multi-gauges.md): Create a customized gauge visualization in Custom Dashboards. - [Geomap widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/geomap-widget.md): Visualize geographical data on custom dashboards using the Geomap widget in Coralogix. This guide explains configuration and usage tips. - [Heatmap widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/heatmap-widget.md): Learn how to use and configure the Heatmap widget in Coralogix Custom Dashboards. - [Horizontal bar charts](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/horizontal-bar-charts.md): The horizontal bar chart widget in Coralogix offers a new way to view your data. In contrast to vertical bar charts, where data is usually sorted alphabetically by column name, horizontal bar charts sort your data by value, in descending order by default. - [Legend configuration for widgets](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/legend-configuration-for-widgets.md): A widget legend is essential for creating clear and understandable visual data representations, enhancing the usability and effectiveness of the entire dashboard. Learn how to customize legends for all types of widgets supported by Coralogix, and apply additional actions to enhance the data exploration capabilities. - [Line charts](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/line-charts.md): Create a customized line chart in Custom Dashboards to visualize logs, metrics, and spans. - [Markdown widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/markdown-widget.md): As part of our Custom Dashboard capabilities, Coralogix offers a Markdown Widget. Add tables, lists, reference guides, links, code-snippets, images and more to customize, contextualize, and optimize your dashboards using Markdown syntax. - [Pie charts](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/pie-charts.md): Create a customized pie chart visualization in Custom Dashboards. - [Polystat widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/polystat-widget.md): The Polystat widget presents time series data in a hexagonal grid, where each hexagon represents an individual value sourced from logs, metrics, or spans. It enables grouping multiple values into a single, consolidated view, allowing you to display values simultaneously. - [Stat widget](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/stat-widget.md): Display a single numeric or string value as a compact, standalone indicator on a Custom Dashboard. - [Switching between visualizations in Custom Dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/switch-between-visualizations.md): Effortlessly toggle between different visualizations in **Custom Dashboards** without the need to recreate widgets from scratch. - [Vertical bar charts](https://coralogix.com/docs/user-guides/custom-dashboards/widgets/vertical-bar-charts.md): The vertical bar chart widget in Coralogix offers an additional way to view your data. In contrast to horizontal bar charts, where data is usually sorted value, vertical bar charts sort your data alphabetically by column name by default. - [Explore](https://coralogix.com/docs/user-guides/data_exploration.md): Explore is your home base for investigating, troubleshooting, and analyzing your logs and spans. - [Custom actions](https://coralogix.com/docs/user-guides/data_exploration/custom_actions.md): Turn values from a log or span into clickable jumps to Coralogix screens, internal tools, dashboards, or third-party services using URL templates with field placeholders. - [DataPrime query](https://coralogix.com/docs/user-guides/data_exploration/dataprime.md): DataPrime is the second query syntax in Explore, alongside Builder. Use it when you need the precision and flexibility of DataPrime's pipeline syntax for filtering, transforming, and aggregating log data at scale. - [Select a dataset](https://coralogix.com/docs/user-guides/data_exploration/datasets.md): Every query in Explore starts with a dataset selection. Selecting the right dataset before running a query improves both the speed and relevance of your results. - [Deep links and URL parameters](https://coralogix.com/docs/user-guides/data_exploration/deep-links.md): Build deep links that open Explore directly into a specific query, time range, dataset, view, or visualization using human-readable URL parameters. - [Explore actions](https://coralogix.com/docs/user-guides/data_exploration/explore_actions.md): Share, alert on, save to a dashboard, save as a view, or reset the current Explore configuration from the toolbar in the top-right corner. - [Export data](https://coralogix.com/docs/user-guides/data_exploration/export.md): Download Explore query results — logs, spans, traces, templates, or Overview aggregations — as a CSV, TSV, or JSON file for spreadsheet analysis, downstream tooling, archival, or sharing with teammates outside Coralogix. - [Filter with fields](https://coralogix.com/docs/user-guides/data_exploration/fields.md): Use the Fields panel to discover which fields exist in your current Explore results and to take common actions without manually typing field names into the query. - [Fields for logs](https://coralogix.com/docs/user-guides/data_exploration/logs/fields-for-logs.md): The Fields side bar in Explore logs groups fields into named sections so you can find the right filter quickly, even when a source has hundreds of attributes. - [Logs table](https://coralogix.com/docs/user-guides/data_exploration/logs/grid.md): The logs table is the default results view in Explore. It displays individual log entries as rows, with fields rendered as columns. Use the table to scan results, compare field values across entries, sort by specific columns, and open individual logs for deeper inspection. - [Log details panel](https://coralogix.com/docs/user-guides/data_exploration/logs/info_panel.md): The log details panel opens when you select a log entry in the Explore results table. It displays the full record for the selected log, including its fields and related observability data. - [LiveTail](https://coralogix.com/docs/user-guides/data_exploration/logs/livetail.md): LiveTail is a real-time pre-index log stream. Use it to watch logs as they arrive, without waiting for ingestion to finish. - [Get started with explore logs](https://coralogix.com/docs/user-guides/data_exploration/logs/quickstart.md): This quickstart walks you through a complete investigation flow in Explore — from selecting a data source to drilling down into specific log entries. Follow the steps in order to get familiar with the key features. - [Analyze log patterns with templates](https://coralogix.com/docs/user-guides/data_exploration/logs/templates.md): Use templates to group high-volume logs into recurring patterns so you can quickly identify new, rare, and abnormal errors, reduce noise during investigations, and operationalize error discovery with alerts and automation. - [Browse metric labels and values](https://coralogix.com/docs/user-guides/data_exploration/metric-explorer.md): Browse metrics, labels, and label values without writing PromQL—and generate a starting query to use in Metric Explorer or Custom Dashboards. - [Explore metrics with metric explorer](https://coralogix.com/docs/user-guides/data_exploration/metrics-explorer.md): Run PromQL queries, visualize metric trends, and drill down by label dimensions from a dedicated explore workspace without setting up a dashboard. - [Overview tab for logs](https://coralogix.com/docs/user-guides/data_exploration/overview-tab.md): Use the Overview tab on the logs dataset to see aggregated results — top contributors, distributions, and bar or pie visualizations — alongside the Logs and Templates tabs that share the same query. - [Explore permissions](https://coralogix.com/docs/user-guides/data_exploration/permissions.md): Required role-based and policy-based permissions for using saved views, team default views, and access policies in Explore. - [Query builder](https://coralogix.com/docs/user-guides/data_exploration/query_builder.md): Query Builder turns log and span search into analysis — group, count, and compare across any field directly in Explore. Start by filtering with the search bar, then add Grouped by and Aggregation chips to turn raw data into grouped results. From grouped results, drill down into a specific group and apply your refined selection back to the main view. - [Search logs and spans](https://coralogix.com/docs/user-guides/data_exploration/search.md): Use the Lucene-powered search bar in Explore to find the exact logs and spans you need. Builder mode supports two input styles — a visual chip builder and a Lucene editor — and you can switch to the DataPrime syntax for advanced pipelines. As you search, Explore keeps your query, filters, and UI actions aligned so you can refine results without rebuilding your work. - [Explore spans](https://coralogix.com/docs/user-guides/data_exploration/spans.md): Investigate spans, traces, and service flows side by side in a single Explore page. Move from symptom to root cause without leaving the page. - [Ask Olly about a span or trace](https://coralogix.com/docs/user-guides/data_exploration/spans/ask-olly.md): Investigate any span or trace in Explore by asking Olly natural-language questions. Olly carries the trace ID and the selected span as context, so you can start from a suggested query or write your own. - [Explore common components](https://coralogix.com/docs/user-guides/data_exploration/spans/explore-common-components.md): Reference index for the four shared components in Explore spans—Result table, Query builder, Graphs, and Fields—across the Spans, Traces, and Flows tabs. - [Get started with Explore spans](https://coralogix.com/docs/user-guides/data_exploration/spans/explore-spans.md): Investigate spans and traces in a complete flow—choose a tab, set the time range, filter, aggregate, and drill into a single span. - [Fields for spans](https://coralogix.com/docs/user-guides/data_exploration/spans/fields-for-spans.md): The Fields side bar in Explore spans groups span fields and tags by OpenTelemetry semantic convention so you can find the right filter quickly. - [Headers and quick actions](https://coralogix.com/docs/user-guides/data_exploration/spans/headers_actions.md): In the span drilldown view, trace and span headers surface the key context you need to decide what to investigate next-service, operation, status, duration, and percentile (how the duration compares to baseline). - [Highlights tab](https://coralogix.com/docs/user-guides/data_exploration/spans/highlights-tab.md): Break the spans matching your query down by field to spot which services, endpoints, or status codes are driving a spike. Compare to a previous period to confirm whether a shift is new or recurring. - [Span fields and attributes](https://coralogix.com/docs/user-guides/data_exploration/spans/info_panel.md): The Info Panel helps you quickly understand why a request was slow, failed, or behaved unexpectedly. It provides a single, searchable view of all context for the selected span, including metadata, errors, infrastructure, and related attributes, so you can move faster from observation to root cause. - [Overview tab for spans](https://coralogix.com/docs/user-guides/data_exploration/spans/overview-tab.md): Use the Overview tab on the spans dataset to visualize aggregated and grouped span queries — by service, operation, status code, or any field — without leaving the query that drives the Spans, Traces, and Flows tabs. - [Query builder for spans](https://coralogix.com/docs/user-guides/data_exploration/spans/query-builder-for-spans.md): The Spans and Traces tabs of Explore spans extend the standard query builder with error filters, duration filters, and span-relationship filters. - [Span related data](https://coralogix.com/docs/user-guides/data_exploration/spans/related_data.md): When you investigate a slow request or a failing operation, a span on its own rarely tells the full story. Span Related Data brings the most relevant signals—logs, events, profiling, and infrastructure context-into the same drilldown so you can move from something is wrong to here’s why without jumping between tools. - [Signals tab](https://coralogix.com/docs/user-guides/data_exploration/spans/signals.md): The Signals tab in Explore spans surfaces Rate, Errors, and Duration for the active query. Outliers overlays latency percentiles, error counts, and individual span samples on one chart; RED metrics renders Rate, Errors, and Duration as three side-by-side charts. - [Investigate with the span drilldown](https://coralogix.com/docs/user-guides/data_exploration/spans/span-drilldown.md): The Span Drilldown opens when you select a trace or span in Explore. It brings together visualization, metadata, and correlated telemetry in one view. - [Spans, Traces, and Flows](https://coralogix.com/docs/user-guides/data_exploration/spans/tables-and-flows.md): Explore spans renders results across three tabs—Spans, Traces, and Flows. Learn how each tab presents your query and how to switch between them without losing context. - [Concepts](https://coralogix.com/docs/user-guides/data_exploration/spans/trace-span-concepts.md): Tracing helps you understand how requests move through your system and why they behave the way they do. It is the starting point for investigating latency, errors, and unexpected behavior across distributed services. - [Investigate large and long-running traces](https://coralogix.com/docs/user-guides/data_exploration/spans/use-cases/large-and-long-traces.md): Some traces contain tens of thousands of spans or stretch across days. Learn the limits that apply to large and long-running traces in Explore spans, and the controls—time range picker, Load more spans, Show Surrounding Spans, and CSV export—that keep them explorable. - [Follow OTel span links across traces](https://coralogix.com/docs/user-guides/data_exploration/spans/use-cases/otel-link.md): When a request crosses an async boundary—a message queue, a retry, a background job—it splits into separate traces connected by OTel span links. Follow those links from the Gantt view and the Dependencies view to open the connected trace in a new tab with the linked span already selected. - [Root span states and incomplete traces](https://coralogix.com/docs/user-guides/data_exploration/spans/use-cases/root-span-states-and-incomplete-traces.md): When the Traces tab can't show a normal Root service name, it displays a placeholder explaining whether the trace has missing or multiple root spans, or is still being ingested. Learn what each indicator means, how Coralogix chooses it, and how to act on each one. - [Identify uninstrumented services](https://coralogix.com/docs/user-guides/data_exploration/spans/use-cases/uninstrumented-services.md): Some services take part in a request but never send telemetry to Coralogix. The Dependencies Service view still shows them—reconstructed from the spans of instrumented services—so architectural blind spots stay visible. Learn how to recognize an uninstrumented service and what to do about it. - [Visualize spans and traces](https://coralogix.com/docs/user-guides/data_exploration/spans/visualize.md): Open a trace of interest in Explore spans to view its underlying spans. Select your preferred visualization mode — Dependencies, Gantt, or Flame view — to explore varied views of the span data. - [Time-series chart](https://coralogix.com/docs/user-guides/data_exploration/timeseries-chart.md): Configure the time-series chart above the Explore results grid — visualization type, scale, time bucket, and grouping — to surface trends in your query without leaving Explore. - [Explore views, tabs, and queries](https://coralogix.com/docs/user-guides/data_exploration/views_queries.md): Save views, open tabs, and manage queries in Explore to preserve investigations, run parallel queries, and reuse query expressions. - [Forwarders](https://coralogix.com/docs/user-guides/data-flow/forwarders.md): Coralogix forwarders let you effortlessly send your parsed and enriched data from Coralogix to an external Kafka cluster, integrating with your existing data pipelines and systems. Forwarders let you tap into specialized analytics tools, comply with data retention policies, and expand your observability setup. Moreover, as an AWS MSK runs open-source versions of Apache Kafka, you can avoid a single observability platform lock-in. - [Overview](https://coralogix.com/docs/user-guides/data-flow/forwarders/deployment-of-customized-aws-msk.md): Amazon Managed Streaming for Apache Kafka (MSK) is a fully managed service that allows the use of Apache Kafka for streaming data processing. This guide details how to deploy an AWS MSK and prepare it to receive parsed and enriched data from Coralogix. It’s a companion guide to the Forwarders documentation, which explains how to set up and configure Coralogix to send your telemetry data to AWS MSK. - [Connect a GCS archive bucket](https://coralogix.com/docs/user-guides/data-flow/gcs-archive.md): Configure a Google Cloud Storage (GCS) bucket as your Coralogix archive destination for the US3 (us-central1) environment. - [Pipeline Analyzer](https://coralogix.com/docs/user-guides/data-flow/pipeline-analyzer.md): Troubleshoot pipeline behavior with pinpoint accuracy using Pipeline Analyzer. - [Archive retention policy](https://coralogix.com/docs/user-guides/data-flow/s3-archive/archive-retention-policy.md): Control and modify the length of time your logs are archived using Archive Retention policies in Coralogix. - [Configure an Amazon S3 bucket](https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive.md): This tutorial demonstrates configuring an Amazon S3 bucket to send your telemetry data to Coralogix. For GCP environments, see Connect a GCS archive bucket. - [Stream aggregation](https://coralogix.com/docs/user-guides/data-flow/stream-aggregation.md): Aggregate metrics at ingest time to make high-cardinality data usable for dashboards, alerts, and queries. - [Processing and routing](https://coralogix.com/docs/user-guides/data-layer/data-processing.md): When data enters Coralogix, it goes through a structured lifecycle: received from shippers or agents, transformed with DataPrime rules, routed based on attributes like region or team, and directed into the appropriate dataspace and dataset. If a dataset doesn't already exist, it's created automatically and inherits configuration from the parent dataspace. - [Dataset management](https://coralogix.com/docs/user-guides/data-layer/dataset-management.md): Dataset Management is the central place to view, configure, and create datasets across your dataspaces. Navigate to Data Flow, then Dataset Management. - [Access control for system Datasets](https://coralogix.com/docs/user-guides/data-layer/dataset-management/access-control.md): System datasets support fine-grained access control that combines permissions and policies. This lets you manage dataset visibility and edit rights with precision. - [Default dataspace](https://coralogix.com/docs/user-guides/data-layer/default-dataspace.md): The default dataspace is where all standard observability data (logs, spans, and custom enrichments) is routed, unless configured otherwise. - [ai_sessions_claude](https://coralogix.com/docs/user-guides/data-layer/default-dataspace/ai-claude-sessions.md): Schema, access model, and opt-in content capture for the ai_sessions_claude dataset that stores Claude Code prompts, responses, tool calls, and errors. - [Create user-defined datasets in the default dataspace](https://coralogix.com/docs/user-guides/data-layer/default-dataspace/user-defined-datasets.md): Create custom datasets under the default dataspace to isolate log streams, apply access policies, and route data via TCO Optimizer. - [Entity types](https://coralogix.com/docs/user-guides/data-layer/entity-types.md): How Coralogix classifies data by pillar and entity type — the schema guarantees you can rely on and where they appear across the platform. - [Dataspaces and datasets](https://coralogix.com/docs/user-guides/data-layer/overview.md): Dataspaces and datasets provide a two-tiered model for organizing, routing, and securing observability data in Coralogix. - [Schema management](https://coralogix.com/docs/user-guides/data-layer/schema-management.md): Schema management offers a unified approach to governing your logs—letting you both discover the structure of ingested data and enforce the fields that matter most. - [Reserved fields](https://coralogix.com/docs/user-guides/data-layer/schema-management/reserved-fields.md): Explicitly define fields of importance for querying and monitoring purposes. - [Schema explorer](https://coralogix.com/docs/user-guides/data-layer/schema-management/schema-explorer.md): Explicitly define fields of importance for querying and monitoring purposes. - [The system dataspace](https://coralogix.com/docs/user-guides/data-layer/system_dataspace.md): The system dataspace provides powerful visibility into the structure, behavior, and configuration of your organization's data. You can track how schemas evolve, review alert activity, and inspect audit events — all of which support debugging, auditing, and operational insight. - [aaa.audit_events](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/aaa_audit-events.md): The schema for aaa.audit_events is coming soon. - [alerts.history](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/alerts-history.md): The alerts.history dataset is generated only for alerts processed through Notification Center. Customers must use Notification Center to have read and write access to this dataset. - [dataplan.usage_events](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/dataplan-usage-events.md): The dataplan.usage_events dataset stores aggregated data usage events for your team. Each event captures a unit of ingestion after ratios have been applied, letting you query your team's consumption alongside any other data in Coralogix using DataPrime. - [engine.queries](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/engine_queries.md): Purpose - [engine.schema_fields](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/engine-schema_fields.md): Purpose - [limit_violations](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/labs_limit-violations.md): Purpose - [notification.deliveries](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/notification_deliveries.md): Purpose - [notification.requests](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/notification_requests.md): notification.requests is currently defined as an entity-type schema and may not yet be available as a queryable system dataset in all environments. The source system/notification.requests examples below may not return data until the dataset is registered and ingested in your environment. - [dataplan.quota_events](https://coralogix.com/docs/user-guides/data-layer/system_dataspace/quota_events.md): The dataplan.quota_events dataset is a stream of quota-related events emitted by the platform — quota-definition changes, threshold breaches, ingestion blocks, Pay-as-you-go activations, and resets. Query it to track how your team's quota is allocated and consumed over time, and to investigate when and why limits are approached, exceeded, or reset. - [Access CX-Data directly](https://coralogix.com/docs/user-guides/data-query/archive-query/access-cx-data-directly.md): This guide explains how to query your S3 Coralogix archive bucket (cx-data) using a third-party framework with the standard Apache Parquet reader provided by the framework and the required schema. - [Archive query from the explore screen](https://coralogix.com/docs/user-guides/data-query/archive-query/archive-query-from-the-explore-screen.md): Archive Query enables you to directly query your logs from your S3 archive using any text or Lucene or DataPrime syntax query. Query logs from your Explore Screen irrespective of log priority, daily quota, or the time frame of the data - all with the ease of familiar functionalities. - [Import archived logs](https://coralogix.com/docs/user-guides/data-query/archive-query/import-archived-logs.md): Description - [Metrics API](https://coralogix.com/docs/user-guides/data-query/metrics-api.md): Coralogix provides a Metrics API that lets you query your hosted metrics easily. - [Relational queries](https://coralogix.com/docs/user-guides/data-query/relational-queries.md): Relational queries in Coralogix's Query Builder empower you to analyze and understand the intricate relationships within your distributed traces. - [Dynamic blocking](https://coralogix.com/docs/user-guides/data-transformation/dynamic-blocking.md): Anyone who works with log management is familiar with the situation where a rogue process or a bug introduced into an application creates a flood of logs that overloads your log management system and brings it to its quota limit. Dynamic Blocking can help prevent this situation. - [Log normalization](https://coralogix.com/docs/user-guides/data-transformation/log-normalization.md): Simplify data analysis with log normalization by introducing standardized keys for common values across product logs. - [Recording Rules](https://coralogix.com/docs/user-guides/data-transformation/metric-rules/recording-rules.md): Recording rules allow you to preprocess and derive new time series from existing ones. By recording a new metric time series, you can simplify complex and resource-intensive PromQL queries into a leaner and more quickly queried metric. The newly recorded metric can be used in various dashboard visualizations and delivers high-performance analytics. - [Auto JSON parsing](https://coralogix.com/docs/user-guides/data-transformation/parsing/auto-json-parsing.md): Coralogix provides automated parsing of any valid JSON format you send, allowing you to sort, filter, group and visualize any JSON parameter - [JSON stringify](https://coralogix.com/docs/user-guides/data-transformation/parsing/json-stringify.md): Json Stringify rule allows you to change an array or an object from JSON format to text. - [Log parsing rules](https://coralogix.com/docs/user-guides/data-transformation/parsing/log-parsing-rules.md): Log parsing rules provide you the ability to parse, extract, convert and filter your log entries. Rules can help you convert unstructured log data to JSON - [Parse JSON field](https://coralogix.com/docs/user-guides/data-transformation/parsing/parse-json-field.md): Sometimes logs arrive escaped or stringified. With the Parse JSON field rule, you can easily convert these logs back into structured JSON. - [Rule types](https://coralogix.com/docs/user-guides/data-transformation/parsing/rule-types.md): Overview of all parsing rule types available for data transformation in Coralogix, including examples and key use cases. - [Rules cheat sheet](https://coralogix.com/docs/user-guides/data-transformation/parsing/rules-cheat-sheet.md): Rules help you to take full advantage of Coralogix log parsing capabilities. For example, you can create your own rules to convert plain text logs into structured JSON logs or extract specific data from the log message as the value to a new JSON key. Coralogix parsing rules are applied prior to the indexing and storing of your logs, so you have full control over the final structure of your data. - [Background Queries](https://coralogix.com/docs/user-guides/dataengine/background_queries_v1.md): Run long-running DataPrime or Lucene queries asynchronously, and optionally save results to a system dataset for reuse across the platform. - [Background Queries v2](https://coralogix.com/docs/user-guides/dataengine/background_queries_v2.md): Run long-running DataPrime or Lucene queries asynchronously and save results as Temporary for 30 days or Persistent to a user-defined summary dataset for long-term reuse. - [Data enrichment](https://coralogix.com/docs/user-guides/enrichment_rules.md): Append contextual fields to your logs automatically during ingestion or dynamically at query time using Coralogix Data Enrichment. - [AWS resource enrichment](https://coralogix.com/docs/user-guides/enrichment_rules/aws_resource_enrichment.md): Coralogix now offers AWS Resource Enrichment, allowing you to enrich your logs with tags from Amazon Web Services (AWS) EC2 instances. Use this feature to connect your business and operation metadata from AWS and gain greater insight into your data. - [Custom enrichment](https://coralogix.com/docs/user-guides/enrichment_rules/custom_enrichment.md): Enhance log data with additional business, operational, or security context to improve log analysis and usability. - [Geo enrichment](https://coralogix.com/docs/user-guides/enrichment_rules/geo_enrichment.md): Overview - [Lookup tables](https://coralogix.com/docs/user-guides/enrichment_rules/lookup_tables.md): Coralogix enables you to enrich and filter your logs using additional context from a lookup table. For example, enrich user activity logs with the user’s department and then retrieve logs of all users in the Finance department. A lookup table, also known as a reference table, is a specific type of data structure used to simplify data lookup operations. It's a table that contains a set of values or information that can be used to quickly find corresponding values in another dataset. Lookup tables are especially useful when you want to map one value to another, such as converting a code to a meaningful description. - [Unified Threat Intelligence](https://coralogix.com/docs/user-guides/enrichment_rules/unified_threat_intelligence.md): Malware detection is an essential capability for modern businesses that helps them identify threats and malicious activity posing a risk to their environments, investigate them, and respond quickly. - [Agent management](https://coralogix.com/docs/user-guides/fleet-management/agent-management.md): The agent catalog displays a concise overview of the most important details regarding your agents: version distribution, the percentage of hosts running agents and details regarding top CPU and memory utilization. - [Fleet Management architecture](https://coralogix.com/docs/user-guides/fleet-management/architecture.md): Centrally manage the configuration of all OpenTelemetry Collectors in your environment with Fleet Manager. - [Config Navigator](https://coralogix.com/docs/user-guides/fleet-management/config-navigator.md): Config Navigator provides a real-time, interactive visualization of your OpenTelemetry (OTel) Collector configurations. This feature transforms complex YAML definitions into a transparent architectural map, allowing you to validate data flow, verify processing logic, and understand the precise relationship between pipeline components. - [Quick start: your first time using Config Navigator](https://coralogix.com/docs/user-guides/fleet-management/config-navigator/quick-start.md): This guide shows how to move from raw YAML to a visual architectural map using Config Navigator, helping you validate your first configuration. - [Configuration deep dive](https://coralogix.com/docs/user-guides/fleet-management/configuration-deep-dive.md): Configurations in Fleet Management lets you centrally manage Collector configurations across your entire fleet, regardless of how they are deployed. It provides a single, consistent control point for updates and reduces the chance of configuration drift. - [Set up configuration fallback for Fleet Management](https://coralogix.com/docs/user-guides/fleet-management/configuration-fallback.md): Set up S3-based configuration fallback for Fleet Management so agents always have a working configuration, even when Fleet Manager is unreachable. - [Configuration management](https://coralogix.com/docs/user-guides/fleet-management/configuration-management.md): The Configurations tab in Fleet Management displays all configuration groups, where each group represents a configuration and its complete version history. - [Generate configurations from templates](https://coralogix.com/docs/user-guides/fleet-management/configuration-templates.md): Generate production-ready OpenTelemetry Collector configurations from environment-specific templates in Fleet Management, without writing YAML from scratch. - [Fleet Management](https://coralogix.com/docs/user-guides/fleet-management/overview.md): Fleet Management uses the OTel OpAMP protocol to enable visualization and management of your OpenTelemetry agents - [Permissions](https://coralogix.com/docs/user-guides/fleet-management/permissions.md): Use the following permissions to manage Fleet Management. - [Upgrade configuration versions in Fleet Management](https://coralogix.com/docs/user-guides/fleet-management/upgrade-path.md): Upgrade template and OpenTelemetry Collector versions across your fleet using the one-click upgrade workflow in Fleet Management. - [Visual builder](https://coralogix.com/docs/user-guides/fleet-management/visual-builder.md): Edit OpenTelemetry Collector pipelines for Fleet Management visually — drag components onto a graph, configure them in a structured form, and apply changes back to YAML. - [Get started with Coralogix](https://coralogix.com/docs/user-guides/getting-started.md): Answer five questions to get setup instructions tailored to your environment, language, and collector. - [Common questions](https://coralogix.com/docs/user-guides/getting-started/common-questions.md): Answers to the questions new Coralogix users ask most: sending data, choosing tools, organizing and securing data, controlling cost, and known limits. - [Features tour](https://coralogix.com/docs/user-guides/getting-started/coralogix-features-tour.md): Tour the Coralogix platform capability by capability: collect any telemetry, explore and transform it, monitor your systems, detect and respond to problems, visualize everything, and act with AI. Follow any card to dive deeper. - [Packages and extensions](https://coralogix.com/docs/user-guides/getting-started/packages-and-extensions.md): Start monitoring faster with prebuilt integration packages and extension packages: one-step data collection plus ready-made alerts, dashboards, and parsing rules. - [Extension packages](https://coralogix.com/docs/user-guides/getting-started/packages-and-extensions/extension-packages.md): Deploy out-of-the-box data extensions: each unlocks a curated set of alerts, parsing rules, dashboards, saved views, and actions, so you can jumpstart Coralogix monitoring of your resources. - [Integration packages](https://coralogix.com/docs/user-guides/getting-started/packages-and-extensions/integration-packages.md): Connect a data source to Coralogix in one guided flow, with the API key, endpoint, and application and subsystem set for you. - [Quick reference](https://coralogix.com/docs/user-guides/getting-started/quick-reference.md): Endpoints, integrations, and platform capabilities at a glance. - [Troubleshooting](https://coralogix.com/docs/user-guides/getting-started/troubleshooting.md): Resolve common issues when setting up Coralogix, sending data, and verifying your integration. - [Verify your data](https://coralogix.com/docs/user-guides/getting-started/verify-your-data.md): Confirm your logs, metrics, and traces are arriving in Coralogix, and know where to look if they aren't. - [Manage infrastructure health rules](https://coralogix.com/docs/user-guides/infrastructure/health-rules.md): Define infrastructure health rules to automatically apply health policies across current and future resources that match your scope, set custom policy thresholds, and track each rule's health at a glance. - [Advanced configuration](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/advanced-configuration.md): Optimize Infrastructure Explorer performance by filtering Kubernetes entities and adjusting data collection frequency. - [Compare infrastructure configuration changes](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/compare-configuration.md): Identify exactly what changed in your infrastructure using the Configuration Compare view in Infrastructure Explorer. Review configuration versions side by side and correlate changes with resource health to speed up incident investigation. - [Configure applications to send telemetry](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/configure-application-telemetry.md): Ensure OpenTelemetry-instrumented applications forward logs, metrics, and traces to the Coralogix agent running as a DaemonSet. - [Kubernetes dashboard vs infrastructure explorer](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/dashboard-vs-infrastructure-explorer.md): Compare Kubernetes Dashboard and Infrastructure Explorer across common monitoring tasks, including metrics visibility, troubleshooting, and cross-cluster analysis. - [Deploy OpenTelemetry demo app](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/deploy-otel-demo.md): Simulate traffic and test end-to-end observability in Coralogix by deploying the OpenTelemetry Demo application. - [Explore your infrastructure](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/explore-infra.md): Learn how to view, search, group, and analyze your discovered Kubernetes and cloud resources using the Infrastructure Explorer for real-time visibility into your environment. - [FAQs](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/faqs.md): Common questions about Infrastructure Explorer data usage, event handling, filtering, and ingestion limits in Coralogix. - [Getting started with host monitoring](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/getting-started-host-monitoring.md): Bring AWS EC2 instances, Azure Virtual Machines, and Google Compute Engine instances into Infrastructure Explorer to view host metadata, resource usage, and OpenTelemetry agent metrics in one place. - [Getting started with Kubernetes monitoring](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/getting-started-kubernetes-monitoring.md): Learn how to configure the Coralogix Kubernetes integration to collect logs, metrics, traces, and infrastructure metadata for use in Infrastructure Explorer. - [Health overview](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/health-overview.md): Quickly assess the health of your infrastructure with summary widgets in Coralogix Infrastructure Explorer. Identify critical resources, understand distribution, and decide where to focus your investigation. - [Host data enrichments](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/host-data-enrichment.md): Monitor host-level metrics and processes for your hosts, including AWS EC2 instances and Azure Virtual Machines, using Coralogix OpenTelemetry integrations and AWS CloudWatch. - [Data usage](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/infra-data-use.md): Track and optimize your infrastructure telemetry ingestion with a clear view of accepted and blocked events, helping teams stay within fair usage limits and maintain accurate, cost-efficient observability. - [Health policy](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/infra-health.md): Learn how Infrastructure Explorer uses Health Policies to evaluate resource stability, surface issues quickly, and provide detailed insights into policy checks and conditions. - [Data limits](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/infrastructure-data-usage.md): Understand the fair usage limits for Infrastructure Explorer, what they mean, how they’re enforced, and how to monitor your usage. - [Kubernetes enrichment options](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/kubernetes-enrichment-options.md): Enrich host metadata and send application telemetry to the Coralogix agent for full visibility in Infrastructure Explorer. - [View lifecycle events](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/lifecycle-events.md): Use lifecycle events in Infrastructure Explorer to track resource creation, updates, keep-alive activity, and removal, and to investigate state changes that affect resource behavior. - [Search and filter](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/lucene-builder.md): Filter infrastructure resources using Builder mode for structured, chip-based filtering or Lucene mode for raw query syntax in Infrastructure Explorer. - [Infrastructure explorer](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/overview.md): Explore how Coralogix Infrastructure Explorer helps you audit, search, and investigate infrastructure entities across Kubernetes and cloud environments in real time. - [Ownership](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/ownership.md): Understand how environment, service, and team ownership is resolved and used across Infrastructure Explorer. - [View resource logs](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/resource-logs.md): View logs for a resource in Infrastructure Explorer, and stream incoming log lines in real time with LiveTail scoped to the selected resource. - [Saved views in Infrastructure Explorer](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/saved-views.md): Save filtered Infrastructure Explorer views to preserve query, filters, table settings, widget state, and time range, then reload them from All views. - [Set up with minikube](https://coralogix.com/docs/user-guides/infrastructure/infrastructure-explorer/setup-with-minikub.md): Deploy a local Kubernetes cluster with Minikube and install the Coralogix OpenTelemetry integration to power Infrastructure Explorer. - [Conduct an investigation](https://coralogix.com/docs/user-guides/investigations/conduct-an-investigation.md): Managing events that could disrupt your organization's services requires a structured, collaborative approach. Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. With this tool, you can consolidate all evidence in one place, visualize the sequence of events to understand cause and effect and collaborate seamlessly with colleagues to gather input and expertis - [Create an investigation](https://coralogix.com/docs/user-guides/investigations/create-an-investigation.md): Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. - [Open a RUM comment](https://coralogix.com/docs/user-guides/investigations/open-a-rum-comment.md): Managing events that could disrupt your organization's services requires a structured, collaborative approach. Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. With this tool, you can consolidate all evidence in one place, visualize the sequence of events to understand cause and effect and collaborate seamlessly with colleagues to gather input and expertis - [Investigations](https://coralogix.com/docs/user-guides/investigations/overview.md): Managing events that could disrupt your organization's services requires a structured, collaborative approach. Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. With this tool, you can consolidate all evidence in one place, visualize the sequence of events to understand cause and effect and collaborate seamlessly with colleagues to gather input and expertis - [Required permissions](https://coralogix.com/docs/user-guides/investigations/required-permissions.md): Managing events that could disrupt your organization's services requires a structured, collaborative approach. Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. With this tool, you can consolidate all evidence in one place, visualize the sequence of events to understand cause and effect and collaborate seamlessly with colleagues to gather input and expertis - [View and manage existing Investigations](https://coralogix.com/docs/user-guides/investigations/view-and-manage-existing-investigations.md): Managing events that could disrupt your organization's services requires a structured, collaborative approach. Coralogix's Investigations feature offers a comprehensive solution for teams to work together and plan mitigation strategies for such events. With this tool, you can consolidate all evidence in one place, visualize the sequence of events to understand cause and effect and collaborate seamlessly with colleagues to gather input and expertis - [End-of-Life announcements](https://coralogix.com/docs/user-guides/latest-updates/deprecations.md): This page consolidates all end-of-life (EoL) announcements for Coralogix features and services, with timelines, migration guidance, and links to relevant documentation. - [Deprecation of Audit v1 schema](https://coralogix.com/docs/user-guides/latest-updates/deprecations/audit-v1.md): Published: September 30, 2025 - [Deprecation of Coralogix .NET SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/dotnet-sdk-deprecation.md): Published: January 12, 2026 - [Deprecation of legacy log ingestion endpoints](https://coralogix.com/docs/user-guides/latest-updates/deprecations/endpoints.md): Published: July 1, 2025 - [Deprecation of legacy elasticsearch API ES-API endpoints](https://coralogix.com/docs/user-guides/latest-updates/deprecations/es-api.md): Published: July 6, 2025 - [GCP Terraform log collection: legacy modules deprecated](https://coralogix.com/docs/user-guides/latest-updates/deprecations/gcp-terraform-v1-modules.md): Published: April 7, 2026 - [Deprecation of native GELF and UDP rsyslog ingestion](https://coralogix.com/docs/user-guides/latest-updates/deprecations/gelf-udp-rsyslog.md): Coralogix is ending native GELF and UDP rsyslog ingestion on August 20, 2026. Migrate GELF to a Logstash forwarder and UDP rsyslog to an OpenTelemetry Collector before the cutoff to avoid data loss. - [Deprecation of Coralogix Go SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/go-sdk.md): Published: February 16, 2026 - [Deprecation of Coralogix Java SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/java-sdk.md): Published: February 16, 2026 - [Deprecation of Kubernetes dashboard](https://coralogix.com/docs/user-guides/latest-updates/deprecations/k8s-dashboard.md): Published: December 10, 2025 - [Deprecation of the legacy logs2metrics (l2m) pipeline](https://coralogix.com/docs/user-guides/latest-updates/deprecations/l2m.md): Published: November 12, 2025 - [Deprecation of Coralogix Log4j SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/log4j-sdk.md): Published: February 16, 2026 - [Deprecation of Coralogix Log4net SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/log4net-sdk.md): Published: February 16, 2026 - [Deprecation of Coralogix Logback SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/logback-sdk.md): Published: February 16, 2026 - [Deprecation of coralogix-hosted Logstash for legacy Filebeat ingestion](https://coralogix.com/docs/user-guides/latest-updates/deprecations/logstash.md): Published: February 16, 2026 - [Deprecation of Coralogix NLog SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/nlog-sdk.md): Published: February 16, 2026 - [Deprecation of Coralogix Node.js Bunyan integration](https://coralogix.com/docs/user-guides/latest-updates/deprecations/nodejs-bunyan-sdk.md): Published: April 17, 2026 - [Deprecation of Coralogix Node.js SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/nodejs-sdk.md): Published: April 17, 2026 - [Deprecation of Coralogix Node.js Winston integration](https://coralogix.com/docs/user-guides/latest-updates/deprecations/nodejs-winston-sdk.md): Published: April 17, 2026 - [Deprecation of prom-api endpoints](https://coralogix.com/docs/user-guides/latest-updates/deprecations/prom-api.md): Published: July 6, 2025 - [Deprecation of Coralogix Python Logger SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/python-logger-sdk.md): Published: April 17, 2026 - [Deprecation of Coralogix Ruby Logger SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/ruby-logger-sdk.md): Published: April 17, 2026 - [Deprecation of Coralogix Serilog SDK](https://coralogix.com/docs/user-guides/latest-updates/deprecations/serilog-sdk.md): Published: February 16, 2026 - [Deprecation of TCO overrides](https://coralogix.com/docs/user-guides/latest-updates/deprecations/tco-overrides.md): Published: October 5, 2025 - [Coralogix navigation — what’s new and how to use it](https://coralogix.com/docs/user-guides/latest-updates/new-nav.md): We’ve moved Coralogix to a left-side sidebar, allowing you to access core features faster and leaving more room for your work. - [Limitations](https://coralogix.com/docs/user-guides/mcp-server/limitations.md): Understand MCP server limitations. - [Authorize MCP with OAuth 2.1](https://coralogix.com/docs/user-guides/mcp-server/oauth.md): The MCP server connects directly to your Coralogix data using OAuth 2.1 with OpenID Connect (OIDC). - [Coralogix AI model context protocol server](https://coralogix.com/docs/user-guides/mcp-server/overview.md): Bridge your AI tooling and Coralogix telemetry to query observability data, manage alerts and parsing rules, and generate infrastructure as code with the Coralogix MCP server. - [Permissions](https://coralogix.com/docs/user-guides/mcp-server/permissions.md): Understand MCP server permissions. - [Setup and installation](https://coralogix.com/docs/user-guides/mcp-server/setup.md): Easily set up Coralogix's MCP server. It is fully remote and does not require any local installation. - [AI Center](https://coralogix.com/docs/user-guides/mcp-server/tools/ai-center.md): Inventory AI applications, manage evaluations and policies, and set model pricing in AI Center directly from your AI agent using the MCP server. - [Alerts and parsing rules](https://coralogix.com/docs/user-guides/mcp-server/tools/alerts-and-incidents.md): Manage Coralogix alert configurations and parsing rules using MCP server tools. - [Alert suppression rules](https://coralogix.com/docs/user-guides/mcp-server/tools/alerts-scheduler.md): Create, manage, and export alert suppression rules using the Model Context Protocol server. - [Alerts](https://coralogix.com/docs/user-guides/mcp-server/tools/alerts.md): Create, manage, and export alerts as infrastructure as code using the MCP server. - [Notification Center connectors](https://coralogix.com/docs/user-guides/mcp-server/tools/connectors.md): Create, manage, and export Notification Center connectors using the Model Context Protocol server. - [Coralogix docs](https://coralogix.com/docs/user-guides/mcp-server/tools/coralogix-docs.md): Search and read the Coralogix documentation portal from your AI coding assistant through the MCP server. - [Custom roles](https://coralogix.com/docs/user-guides/mcp-server/tools/custom-roles.md): Create, manage, and export custom roles using the Model Context Protocol server. - [Dashboards](https://coralogix.com/docs/user-guides/mcp-server/tools/dashboards.md): Find dashboards and saved dashboard queries using the MCP server - [Data enrichment](https://coralogix.com/docs/user-guides/mcp-server/tools/data-enrichments.md): Create, manage, and export data enrichment rules using the Model Context Protocol server. - [Events2Metrics](https://coralogix.com/docs/user-guides/mcp-server/tools/events2metrics.md): Create, manage, and export Events2Metrics resources using the Model Context Protocol server. - [Notification Center routing](https://coralogix.com/docs/user-guides/mcp-server/tools/global-routers.md): Use the Model Context Protocol server to create, manage, and export Notification Center routing configurations directly from your AI agent. - [Logs and traces](https://coralogix.com/docs/user-guides/mcp-server/tools/logs-and-traces.md): Query your Coralogix logs and traces using the MCP server. - [Metrics](https://coralogix.com/docs/user-guides/mcp-server/tools/metrics.md): Query your Coralogix metrics using the MCP server. - [Olly](https://coralogix.com/docs/user-guides/mcp-server/tools/olly.md): Use Olly, Coralogix's natural-language observability agent, from your AI coding assistant through the MCP server. - [Overview](https://coralogix.com/docs/user-guides/mcp-server/tools/overview.md): Query observability data, manage configuration resources, and generate IaC with Model Context Protocol server tools. - [Parsing Rules](https://coralogix.com/docs/user-guides/mcp-server/tools/parsing-rules.md): Create, manage, and export parsing rules as infrastructure as code using the MCP server. - [Notification Center presets](https://coralogix.com/docs/user-guides/mcp-server/tools/presets.md): Create, manage, and export Notification Center presets using the Model Context Protocol server. - [Recording rules](https://coralogix.com/docs/user-guides/mcp-server/tools/recording-rules.md): Create, manage, and export recording rule group sets using the Model Context Protocol server. - [Reference tools](https://coralogix.com/docs/user-guides/mcp-server/tools/reference.md): Use these foundational tools for understanding and querying your data effectively. - [Real User Monitoring](https://coralogix.com/docs/user-guides/mcp-server/tools/rum.md): Query and analyze frontend and mobile application performance with Real User Monitoring tools for the Coralogix MCP server. - [Service level objectives](https://coralogix.com/docs/user-guides/mcp-server/tools/slo-v2.md): Create, manage, and export service level objectives using the Model Context Protocol server. - [Total Cost Optimization log policies](https://coralogix.com/docs/user-guides/mcp-server/tools/tco-log-policies.md): Create, manage, and export Total Cost Optimization log policies using the Model Context Protocol server. - [Total Cost Optimization trace policies](https://coralogix.com/docs/user-guides/mcp-server/tools/tco-trace-policies.md): Create, manage, and export Total Cost Optimization trace policies using the Model Context Protocol server. - [Outbound webhooks](https://coralogix.com/docs/user-guides/mcp-server/tools/webhooks.md): Create, manage, and export outbound webhooks using the Model Context Protocol server. - [Events2Metrics](https://coralogix.com/docs/user-guides/monitoring-and-insights/events2metrics.md): Coralogix Events2Metrics enables you to generate metrics from your spans and logs to optimize storage without sacrificing important data.Define a query and Coralogix will execute it every minute and store different data aggregations in a long-term index. Metrics start to gather from the point in time in which they were defined. The available query time range for your Events2Metrics indices is 90 days. Activating Events2Metrics allows you to create up to 30 metrics with a 12-month retention period. - [Saved views](https://coralogix.com/docs/user-guides/monitoring-and-insights/explore-screen/create-and-manage-saved-views.md): Save Explore views for logs or spans to preserve query, fields, table settings, time range, and folder location, then reload them from All views. - [Mapping statistics](https://coralogix.com/docs/user-guides/monitoring-and-insights/mapping-statistics.md): Having an excessive number of fields in your index can result in mapping issues. By default, Coralogix enforces a maximum limit of 1,000 fields to prevent performance degradation. This threshold is in place to maintain system stability and ensure optimal query performance. - [Setting up your Lambda function metrics dashboard](https://coralogix.com/docs/user-guides/monitoring-and-insights/setting-up-your-lambda-function-metrics-dashboard.md): Interested in using the Coralogix AWS Lambda Telemetry Exporter v.0.2.0 to collect and send us Lambda function metrics? This tutorial describes how to create a dashboard for monitoring a single Lambda function. - [Synthetic monitoring with Checkly](https://coralogix.com/docs/user-guides/monitoring-and-insights/synthetic-monitoring/synthetic-monitoring-with-checkly.md): This tutorial demonstrates how to add synthetic capabilities to your Coralogix dashboard with Checkly, allowing you to view and query the results of your Checkly synthetic testing. - [Synthetic monitoring with Telegraf](https://coralogix.com/docs/user-guides/monitoring-and-insights/synthetic-monitoring/synthetic-monitoring-with-telegraf.md): This guide outlines the steps required to use the Coralogix Telegraf integration to monitor response codes and response times of URLs and ship the metrics to Coralogix. - [Version Benchmarks](https://coralogix.com/docs/user-guides/monitoring-and-insights/version-benchmarks.md): Version Benchmarks are the best way for you to understand your version status at a glance, integrate with your deployment pipeline, and get your latest build status. Whether it’s new exceptions, higher error ratios, or new broken flows - we've got you covered.Version Benchmark tags can be used as a representation of any significant change or event that may impact your system. They can be received automatically from your CI/CD pipelines or inserted manually, they can be a new version, a new big customer, or a marker of the day when your dev team had sangria at lunch. - [Visual Explorer](https://coralogix.com/docs/user-guides/monitoring-and-insights/visual-explorer.md): Visual Explorer is a powerful tool that integrates a multifunctional Explore display with customizable dashboard widgets, enhancing your log, span and metrics exploration. It provides a fast and easy way to add query-based graphs without the need for setting up custom dashboards. - [Tabs in Visual Explorer](https://coralogix.com/docs/user-guides/monitoring-and-insights/visual-explorer/use-tabs-in-visual-explorer.md): Learn how to organize multiple query visualizations in Visual Explorer using tabs. Tabs let you group related queries and keep exploratory workspaces easy to navigate. - [Connectors](https://coralogix.com/docs/user-guides/notification-center/connectors.md): Create and manage connectors in Notification Center to send notifications to Slack, PagerDuty, and HTTPS endpoints. - [Advanced configuration](https://coralogix.com/docs/user-guides/notification-center/connectors/advanced-configuration.md): Route Slack, email, and PagerDuty connectors dynamically using the field builder or Tera templating in Notification Center. - [Core concepts in Notification Center](https://coralogix.com/docs/user-guides/notification-center/core-concepts.md): Learn how Notification Center structures notifications using entities, routers, connectors, presets, and destinations. - [Connector configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/email/connector-config.md): This guide presents the connector configuration for the Email destination type. - [Message configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/email/message-config.md): This guide describes how to configure the subject and content of Email notifications using presets. - [HTTPS](https://coralogix.com/docs/user-guides/notification-center/destination-types/https.md): Notification Center supports the HTTPS destination type. - [Connector configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/https/connector-config.md): This guide presents the connector configuration for the generic HTTPS destination type. - [Message configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/https/schema-structure.md): This guide presents the schema structure for the generic HTTPS destination type. - [Incident.io configuration via HTTPS](https://coralogix.com/docs/user-guides/notification-center/destination-types/https/support-for-incident.io.md): This guide presents the connector and message configuration for incident.io via the generic HTTPS destination type. - [OpsGenie and JSM configuration via HTTPS](https://coralogix.com/docs/user-guides/notification-center/destination-types/https/support-for-opsgenie.md): Configure the generic HTTPS destination type to send alert notifications to OpsGenie or its Atlassian successor, Jira Service Management (JSM), from Coralogix Notification Center. - [Destination types](https://coralogix.com/docs/user-guides/notification-center/destination-types/introduction.md): Learn how destination types define where notifications are sent and how messages are formatted in Notification Center. - [Microsoft Teams](https://coralogix.com/docs/user-guides/notification-center/destination-types/msteams.md): Route Coralogix alert and Case notifications to Microsoft Teams channels with the native Notification Center connector. - [Install and set up Microsoft Teams](https://coralogix.com/docs/user-guides/notification-center/destination-types/msteams/install.md): Install the Coralogix app in your Microsoft Teams tenant, set up the integration, and create a connector for Notification Center. - [PagerDuty](https://coralogix.com/docs/user-guides/notification-center/destination-types/pagerduty.md): Notification Center supports the PagerDuty destination type, with one-way service-key and two-way bi-directional connector paths. - [Connector configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/pagerduty/connector-config.md): This guide presents the connector configuration for the PagerDuty destination type, including the service-key and bi-directional paths. - [Message configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/pagerduty/schema-structure.md): This guide presents the schema structure for the PagerDuty destination type. - [ServiceNow](https://coralogix.com/docs/user-guides/notification-center/destination-types/servicenow.md): Integrate Coralogix with ServiceNow to automatically create, update, and synchronize ServiceNow records from Coralogix Cases via Notification Center. - [Slack](https://coralogix.com/docs/user-guides/notification-center/destination-types/slack.md): Notification Center supports the Slack destination type. - [Connector configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/slack/connector-config.md): This guide presents the connector configuration for the Slack destination type. - [Message configuration](https://coralogix.com/docs/user-guides/notification-center/destination-types/slack/schema-structure.md): This guide presents the schema structure for the Slack destination type. - [Dynamic templating](https://coralogix.com/docs/user-guides/notification-center/dynamic-templating.md): Use Tera expressions to customize notification messages, routing, and connector behavior in Notification Center. - [Tera syntax quick reference](https://coralogix.com/docs/user-guides/notification-center/dynamic-templating/tera-syntax.md): Quick reference for Tera expressions used in Notification Center for connectors, presets, and routing rules. - [Tera usage and troubleshooting](https://coralogix.com/docs/user-guides/notification-center/dynamic-templating/tera-usage.md): Troubleshoot and optimize Tera templates for Notification Center connectors, presets, and routing rules. - [Alerts](https://coralogix.com/docs/user-guides/notification-center/entity-types/alerts.md): Alerts act as a supported entity type for Notification Center. - [Cases](https://coralogix.com/docs/user-guides/notification-center/entity-types/cases.md): Cases act as a supported entity type for Notification Center. - [Entity types](https://coralogix.com/docs/user-guides/notification-center/entity-types/introduction.md): Learn how Notification Center uses entity types and subtypes for alerts and cases. - [Notification Center](https://coralogix.com/docs/user-guides/notification-center/introduction.md): Notification Center is your home base for all outbound alert notifications sent from Coralogix to third-party destinations such as Slack or PagerDuty. - [Migrate from outbound webhooks](https://coralogix.com/docs/user-guides/notification-center/migration.md): Move legacy alert webhooks to the Notification Center model of connectors, presets, and Case-based routing. Applies to every connector type, with Slack and Microsoft Teams examples. - [Webhook field mapping](https://coralogix.com/docs/user-guides/notification-center/migration/webhook-field-mapping.md): Map each legacy outbound-webhook placeholder to its Notification Center Case-notification equivalent when rebuilding a custom webhook body as a Tera preset. - [Permissions](https://coralogix.com/docs/user-guides/notification-center/permissions.md): These permissions are required for engaging with Notification Center. - [Presets overview](https://coralogix.com/docs/user-guides/notification-center/presets/introduction.md): Define and manage presets that control message content and formatting for Notification Center destinations. - [Preset message rendering flow](https://coralogix.com/docs/user-guides/notification-center/presets/message-render-flow.md): Learn how Notification Center merges preset layers and renders final notification messages. - [Preset creation flow](https://coralogix.com/docs/user-guides/notification-center/presets/preset-creation.md): Learn how system and custom presets are created and customized in Notification Center. - [Set up your first notification flow](https://coralogix.com/docs/user-guides/notification-center/quick-start.md): Use Notification Center to route alert notifications from Coralogix to destinations such as Slack or PagerDuty. - [Condition templating](https://coralogix.com/docs/user-guides/notification-center/routing/condition-templating.md): Use Tera template expressions in routing rule conditions to control which notifications are routed to which destinations based on alert names, labels, case status, and entity type. - [Create a router](https://coralogix.com/docs/user-guides/notification-center/routing/create-router.md): Learn how to create routers in Notification Center to match notifications and route them to specific destinations. - [Define routing rule](https://coralogix.com/docs/user-guides/notification-center/routing/define-routing-rule.md): Define routing rules in Notification Center to control when notifications are sent and where they go. - [Routing](https://coralogix.com/docs/user-guides/notification-center/routing/introduction.md): Learn how Notification Center routes notifications using labels, rules, and destinations. - [Alert routing labels](https://coralogix.com/docs/user-guides/notification-center/routing/labels-to-alerts.md): Configure routing labels on alerts so Notification Center can route notifications through routers. - [Route p1 alerts to PagerDuty](https://coralogix.com/docs/user-guides/notification-center/user-scenarios/alerts-to-pagerduty.md): Route P1 alerts to PagerDuty using Notification Center connectors, presets, and routing rules. - [Example: route alerts to Slack](https://coralogix.com/docs/user-guides/notification-center/user-scenarios/alerts-to-slack.md): Route alert notifications to Slack using Notification Center connectors, presets, routers, and routing rules. - [Olly AI observability agent](https://coralogix.com/docs/user-guides/olly.md): Olly is Coralogix's AI-native observability agent that makes observability data fast, accessible, and actionable for everyone. - [Autonomous agent](https://coralogix.com/docs/user-guides/olly/autonomous-agent.md): Olly's autonomous agent runs end-to-end investigations and root cause analysis across your observability data, so you can resolve incidents in minutes instead of hours. - [Data processing, privacy, and compliance](https://coralogix.com/docs/user-guides/olly/data-privacy.md): Understand how Olly processes, protects, and governs your data, including architecture, tenant isolation, model provider policies, and compliance frameworks. - [DataPrime query assistance](https://coralogix.com/docs/user-guides/olly/dataprime-query-assistance.md): Describe what you're looking for in everyday language, and Olly converts your description into a structured DataPrime query. - [Dynamic tables and export](https://coralogix.com/docs/user-guides/olly/dynamic-tables.md): Olly can return structured results as dynamic tables that can be exported as CSV or JSON. - [Enable Olly](https://coralogix.com/docs/user-guides/olly/enable.md): Enable Olly for a Coralogix team from the Coralogix UI. - [Explain log](https://coralogix.com/docs/user-guides/olly/explain-log.md): Get clear, natural language explanations for individual log entries, including their significance, impact, and potential causes. - [Olly FAQs](https://coralogix.com/docs/user-guides/olly/faqs.md): Frequently asked questions about Olly, the AI-native observability agent. - [File attachments for chat context](https://coralogix.com/docs/user-guides/olly/file-attachments.md): Attach files to a chat message to give Olly additional context for your prompt. - [GitHub](https://coralogix.com/docs/user-guides/olly/github.md): Integrate Olly with your GitHub repositories to understand code changes, investigate issues, and speed up delivery. - [Knowledge assistance](https://coralogix.com/docs/user-guides/olly/knowledge-assistance.md): Ask questions about Coralogix platform features and get real-time answers based on Coralogix documentation. - [Memories](https://coralogix.com/docs/user-guides/olly/memories.md): Let Olly remember helpful facts and preferences from your chats so it personalizes and adds context to future responses, and manage what it stores. - [Model selection](https://coralogix.com/docs/user-guides/olly/model-selection.md): Pick which AI model Olly uses so you control the tradeoff between speed, depth, and cost. - [Olly chat](https://coralogix.com/docs/user-guides/olly/olly-chat.md): Use the Olly chat to ask questions, manage conversations, and explore artifacts generated from your observability data. - [Olly mini](https://coralogix.com/docs/user-guides/olly/olly-mini.md): Olly mini is Coralogix's embedded AI helper — focused, in-context actions like analyzing flame graphs, generating queries, summarizing cases, and explaining logs or errors. - [Rules](https://coralogix.com/docs/user-guides/olly/rules.md): Define team-wide and personal rules so Olly applies your team's conventions and your individual preferences to every chat. - [Scheduled tasks](https://coralogix.com/docs/user-guides/olly/scheduled-tasks.md): Schedule Olly to run a prompt automatically — once or on a recurring interval — and review each run from a single page. - [Skills](https://coralogix.com/docs/user-guides/olly/skills.md): Author personal and team-wide skills so Olly applies your conventions, workflows, and response style to every chat. - [Slack](https://coralogix.com/docs/user-guides/olly/slack.md): Bring Olly into team conversations on Slack for AI-powered observability collaboration. - [Usage Management](https://coralogix.com/docs/user-guides/olly/usage-management.md): Monitor team-wide AI Units consumption from Olly and cap it with monthly limits set per user or per user group so no one depletes the team quota. - [Release notes](https://coralogix.com/docs/user-guides/release-notes.md): User Guides Release Notes - [Account management](https://coralogix.com/docs/user-guides/release-notes/account-management.md): Recent updates to Account Management in Coralogix - [AI observability](https://coralogix.com/docs/user-guides/release-notes/ai-observability.md): Recent updates to AI Observability in Coralogix - [Alerting](https://coralogix.com/docs/user-guides/release-notes/alerting.md): Recent updates to Alerting in Coralogix - [APM (application performance monitoring)](https://coralogix.com/docs/user-guides/release-notes/apm-application-performance-monitoring.md): Recent updates to APM (Application Performance Monitoring) in Coralogix - [Archive](https://coralogix.com/docs/user-guides/release-notes/archive.md): Recent updates to Archive in Coralogix - [Cases](https://coralogix.com/docs/user-guides/release-notes/cases.md): Recent updates to Cases in Coralogix - [Continuous Profiling](https://coralogix.com/docs/user-guides/release-notes/continuous-profiling.md): Recent updates to Continuous Profiling in Coralogix - [Custom Dashboards](https://coralogix.com/docs/user-guides/release-notes/custom-dashboards.md): Recent updates to Custom Dashboards in Coralogix - [cx-cli](https://coralogix.com/docs/user-guides/release-notes/cx-cli.md): Recent updates to the Coralogix CLI (cx-cli) - [Data flow](https://coralogix.com/docs/user-guides/release-notes/data-flow.md): Recent updates to Data Flow in Coralogix - [DataPrime](https://coralogix.com/docs/user-guides/release-notes/dataprime.md): Recent updates to DataPrime in Coralogix - [Datasets & data query](https://coralogix.com/docs/user-guides/release-notes/datasets-data-query.md): Recent updates to Datasets & Data Query in Coralogix - [Developer portal](https://coralogix.com/docs/user-guides/release-notes/developer-portal.md): Recent updates to Developer Portal in Coralogix - [Explore](https://coralogix.com/docs/user-guides/release-notes/explore.md): Recent updates to Explore in Coralogix - [Fleet Management](https://coralogix.com/docs/user-guides/release-notes/fleet-management.md): Recent updates to Fleet Management in Coralogix - [Forwarders](https://coralogix.com/docs/user-guides/release-notes/forwarders.md): Recent updates to Forwarders in Coralogix - [Infrastructure](https://coralogix.com/docs/user-guides/release-notes/infrastructure.md): Recent updates to Infrastructure in Coralogix - [Integrations](https://coralogix.com/docs/user-guides/release-notes/integrations.md): Recent updates to Integrations in Coralogix - [Logs](https://coralogix.com/docs/user-guides/release-notes/logs.md): Recent updates to Explore Logs in Coralogix - [MCP server](https://coralogix.com/docs/user-guides/release-notes/mcp-server.md): Recent updates to MCP Server in Coralogix - [Metrics](https://coralogix.com/docs/user-guides/release-notes/metrics.md): Recent updates to Metrics in Coralogix - [Notification Center](https://coralogix.com/docs/user-guides/release-notes/notification-center.md): Recent updates to Notification Center in Coralogix - [Olly AI agent](https://coralogix.com/docs/user-guides/release-notes/olly.md): Recent updates to Olly AI Agent - [OpenTelemetry](https://coralogix.com/docs/user-guides/release-notes/opentelemetry.md): Recent updates to OpenTelemetry in Coralogix - [Parsing Rules](https://coralogix.com/docs/user-guides/release-notes/parsing-rules.md): Recent updates to Parsing Rules in Coralogix - [Pipeline Analyzer](https://coralogix.com/docs/user-guides/release-notes/pipeline-analyzer.md): Recent updates to Pipeline Analyzer in Coralogix - [Quota Rules](https://coralogix.com/docs/user-guides/release-notes/quota-rules.md): Recent updates to Quota Rules in Coralogix - [Android agent v7.6.14](https://coralogix.com/docs/user-guides/release-notes/release-note-1.md): Release Note 1 - [Android agent v7.6.15](https://coralogix.com/docs/user-guides/release-notes/release-note-2.md): Release Note 2 - [Android agent v7.6.16](https://coralogix.com/docs/user-guides/release-notes/release-note-3.md): Release Note 3 - [Android agent v7.6.17](https://coralogix.com/docs/user-guides/release-notes/release-note-4.md): Release Note 4 - [Fleet Management: archive configuration](https://coralogix.com/docs/user-guides/release-notes/release-note-5.md): Archive configuration groups and families in Fleet Management - [Access policies: new UI](https://coralogix.com/docs/user-guides/release-notes/release-note-6.md): Simplified access policy controls with general access, target group rules, and advanced policy settings - [Reserved fields](https://coralogix.com/docs/user-guides/release-notes/reserved-fields.md): Recent updates to Reserved Fields in Coralogix - [RUM (real user monitoring)](https://coralogix.com/docs/user-guides/release-notes/rum-real-user-monitoring.md): Recent updates to RUM (Real User Monitoring) in Coralogix - [Schema manager](https://coralogix.com/docs/user-guides/release-notes/schema-manager.md): Recent updates to Schema Manager in Coralogix - [Security](https://coralogix.com/docs/user-guides/release-notes/security.md): Recent updates to Security in Coralogix - [SLOs](https://coralogix.com/docs/user-guides/release-notes/slos.md): Recent updates to SLOs in Coralogix - [Spans](https://coralogix.com/docs/user-guides/release-notes/spans.md): Recent updates to Spans in Coralogix - [RUM CLI](https://coralogix.com/docs/user-guides/rum/cli/rum-cli.md): The Coralogix RUM CLI is a command-line interface tool that simplifies the process of uploading Real User Monitoring artifacts across Web and mobile platforms. This CLI tool provides an easy and efficient way to authenticate with the Coralogix API, specify the application and release information, and traverse a folder to upload the relevant source map files. - [Uploading debug symbols: iOS](https://coralogix.com/docs/user-guides/rum/cli/uploading-debug-symbols-ios.md): As part of Error Tracking, Coralogix requires dSYM (debug information) files to interpret your stack traces. The symbolization process converts the stack traces in raw format back into readable function names, file names, and line numbers related to the crash. - [Real User Monitoring](https://coralogix.com/docs/user-guides/rum/getting-started/real-user-monitoring.md): Coralogix's Real User Monitoring (RUM) is an advanced monitoring solution that provides unparalleled visibility into your application's frontend performance, all from the perspective of real users in real-time. With RUM, you can gain a comprehensive understanding of how your application performs across a variety of browsers, devices, and networks, allowing you to quickly detect issues that might be affecting your users' experience. Whether you're looking to optimize your app's performance, reduce downtime, or simply improve the user experience, RUM provides the tools and insights you need to optimize engagement with your application. - [RUM integration package](https://coralogix.com/docs/user-guides/rum/getting-started/rum-integration-package.md): Set up and configure Real User Monitoring via the RUM Integration Package to hit the ground running with our various RUM features. The package includes automatic configuration of the RUM Browser SDK, as well as upload of your source maps. Once configured, all network requests and errors in your system will be captured and sent to Coralogix. - [Analyze errors with Olly mini](https://coralogix.com/docs/user-guides/rum/product-features/analyze-errors-with-olly-mini.md): Learn how to use Olly mini in Error Tracking to analyze crashes, understand causes, and find debugging steps. - [Core Web Vitals](https://coralogix.com/docs/user-guides/rum/product-features/core-web-vitals.md): Explore the transformative world of Core Web Vitals — a pivotal Coralogix feature designed to elevate your web pages' performance and user experience. Discover how these essential metrics, including loading speed, interactivity, and visual stability, can be optimized to ensure your audience's seamless and responsive online environment. - [Error analytics](https://coralogix.com/docs/user-guides/rum/product-features/error-analytics.md): Error Analytics in Real User Monitoring (RUM) offers a powerful, at-a-glance view of error data, providing users with comprehensive insights into error occurrences within their web applications. By breaking down error data into different dimensions such as device, operating system, browser, URL, users affected, app version, and custom log labels, Error Analytics allows you to quickly identify the sources of issues and effectively prioritize your efforts. These visualizations not only streamline the troubleshooting process but also enable you to improve user experience, make data-driven decisions, and take proactive measures to minimize errors. - [Error template view](https://coralogix.com/docs/user-guides/rum/product-features/error-template-view.md): As part of our multi-faceted Error Tracking, take advantage of our Error Template View, where similar errors with shared attributes are grouped into a single template for swift and easy analysis. - [Error tracking: user manual](https://coralogix.com/docs/user-guides/rum/product-features/error-tracking-user-manual.md): As part of our Real User Monitoring (RUM) toolkit, Coralogix offers multi-faceted Error Tracking. Designed to help web application owners and developers gain insights into errors occurring within their users' browsers, this tool allows you to effectively capture and analyze frontend errors to optimize application performance and enhance the overall user experience. This user manual demonstrates how to engage with our RUM UI to get the most out of our Error Tracking features. - [Error tracking](https://coralogix.com/docs/user-guides/rum/product-features/error-tracking.md): As part of our Real User Monitoring (RUM) toolkit, Coralogix offers multi-faceted Error Tracking. Designed to help web application owners and developers gain insights into errors occurring within their users' browsers, this tool allows you to effectively capture and analyze frontend errors to optimize application performance and enhance the overall user experience. What’s more, Error Tracking is powered by our Streama© technology, allowing your data to run on the Coralogix monitoring pipeline at a third of the cost, without prior indexing. - [Highlights for Real User Monitoring](https://coralogix.com/docs/user-guides/rum/product-features/highlights.md): Highlights is a powerful tool designed to help teams quickly understand how data is distributed across different attributes. - [Measurements](https://coralogix.com/docs/user-guides/rum/product-features/measurements.md): Measurements in Coralogix’s Real User Monitoring (RUM) offers a unified, interactive dashboard to view and analyze all your client-side performance measurements—static and custom—in one place. It’s designed to streamline performance analysis and help you identify actionable insights with minimal friction. - [Mobile performance](https://coralogix.com/docs/user-guides/rum/product-features/mobile-performance.md): Understand and monitor Mobile Performance using Real User Monitoring (RUM) features for mobile applications. - [Monitoring RUM network call performance](https://coralogix.com/docs/user-guides/rum/product-features/network-call-performance-monitoring.md): Coralogix Network Performance Monitoring for Real User Monitoring (RUM) can significantly enhance front-end developers' ability to diagnose and address network-related performance issues - [RUM overview](https://coralogix.com/docs/user-guides/rum/product-features/overview.md): Use the RUM overview page to see the health of every web, mobile, and Micro-Frontend (MFE) application in a single view, then drill down into a single application to investigate errors, releases, and performance. - [Releases](https://coralogix.com/docs/user-guides/rum/product-features/releases.md): Track the adoption, crash free rate, crashes, and error templates of every release in Real User Monitoring, and drill into the health of a single release. - [RUM saved views](https://coralogix.com/docs/user-guides/rum/product-features/rum-saved-views.md): The Real User Monitoring (RUM) dashboard allows you to retrieve data and filter your view to display only items that meet specific criteria. You can use filters and queries to examine specific subsets of RUM experiences on your application, filtering by application, page URL, request status code, error message, or any log field you choose. You can save these filters and queries for future use, allowing you to focus on relevant data. - [Session replay](https://coralogix.com/docs/user-guides/rum/product-features/session-replay.md): Learn how to enable and use Session Replay to record and visually replay user sessions for enhanced user experience monitoring. - [Enable session replay on Android](https://coralogix.com/docs/user-guides/rum/product-features/session-replay/android.md): Follow this guide to enable Session Replay for Real User Monitoring (RUM) in your Android app. - [Enable session replay in flutter](https://coralogix.com/docs/user-guides/rum/product-features/session-replay/flutter.md): Follow this guide to enable Session Replay for Real User Monitoring (RUM) in your Flutter app. - [Enable session replay on iOS](https://coralogix.com/docs/user-guides/rum/product-features/session-replay/ios.md): Follow this guide to enable Session Replay for Real User Monitoring (RUM) in your iOS app. - [Enable session replay on React Native](https://coralogix.com/docs/user-guides/rum/product-features/session-replay/react-native.md): Follow this guide to enable Session Replay for Real User Monitoring (RUM) in your React Native app. - [Session replay for web](https://coralogix.com/docs/user-guides/rum/product-features/session-replay/web.md): Learn how to enable and use Session Replay to record and visually replay user sessions for enhanced user experience monitoring. - [User action and error screenshots](https://coralogix.com/docs/user-guides/rum/product-features/user-action-and-error-screenshots.md): User action screenshots enable you to capture a wide range of user actions, as well as take and store screenshots to record the exact moment an error occurs within an application or system. - [User measurements](https://coralogix.com/docs/user-guides/rum/product-features/user-measurements.md): Coralogix RUM collects and analyzes the Real User Monitoring data within Coralogix to track how users interact with your web applications in real time. This feature helps monitor performance, user behavior, and interaction patterns, providing valuable insights into the user experience (UX) - [User sessions](https://coralogix.com/docs/user-guides/rum/product-features/user-sessions.md): User Sessions provides valuable insights into the user experience by tracking and analyzing how users interact with your web applications. Use this tutorial to learn what user sessions are, how to use them effectively, and how they can enhance your Real User Monitoring (RUM) capabilities. - [Querying RUM logs](https://coralogix.com/docs/user-guides/rum/query-rum-logs.md): Easily query RUM logs using this log structure guide. - [Analyzing header and payload data](https://coralogix.com/docs/user-guides/rum/sdk-features/analyze-header-and-payload-data.md): Use RUM browser SDK for in-depth insights into your application's communication patterns, including response codes, request metadata, and payload content. - [Anonymous users](https://coralogix.com/docs/user-guides/rum/sdk-features/anonymous-users.md): Learn how Coralogix RUM SDK automatically tracks anonymous users, enabling seamless user journey analysis from pre-login to authenticated sessions. - [Capturing errors](https://coralogix.com/docs/user-guides/rum/sdk-features/capturing-errors.md): Learn about how Coralogix captures both handled and unhandled errors, and how you can enhance your event data for better monitoring. - [Configure your browser RUM data proxy](https://coralogix.com/docs/user-guides/rum/sdk-features/configure-your-browser-rum-data-proxy.md): Set up the RUM Browser SDK to route requests through a proxy. - [Custom logs](https://coralogix.com/docs/user-guides/rum/sdk-features/custom-logs.md): Use the Custom logs feature to send log messages with customized severity levels, extra data and/or custom labels - [Custom measurements](https://coralogix.com/docs/user-guides/rum/sdk-features/custom-measurements.md): Use the **Custom Measurements** feature to send performance metrics tailored to your application requirements. This API enables tracking of custom events, interactions, and load times, providing deeper insights into user behavior and application performance - [Custom spans](https://coralogix.com/docs/user-guides/rum/sdk-features/custom-spans.md): Custom spans in Coralogix offer developers unparalleled flexibility to monitor specific parts of the frontend application that matter most to their users. Unlike network request spans, which are automatically generated, custom spans allow you to define, start, and end spans at strategic points in your application's user flow or operational processes. This enables targeted performance monitoring, precise troubleshooting, and fine-grained optimization. - [Customized timing](https://coralogix.com/docs/user-guides/rum/sdk-features/customized-timing.md): Enhance your application's performance management by measuring the time difference between when the page loads and your defined timing point. You can use it to track the time it takes for specific web pages to fully load, providing insights into performance and user experience - [Data privacy and logging settings](https://coralogix.com/docs/user-guides/rum/sdk-features/data-masking.md): Censure fields in your RUM logs with data masking to safeguard end-user privacy and prevent sensitive data collection. In addition, determine whether user IP and geolocation data is collected or ignored. - [DOM navigation indications](https://coralogix.com/docs/user-guides/rum/sdk-features/dom-navigation-indications.md): Customize your application’s performance management by capturing a wide range of browser document navigation indications. - [Enhance & manage browser RUM data with beforeSend](https://coralogix.com/docs/user-guides/rum/sdk-features/enhance-and-manage-browser-rum-data-with-beforesend.md): Enable event access and modification before sending data to Coralogix using beforeSend. This feature allows you to modify content or discard events as needed. - [RUM conditional error sampling](https://coralogix.com/docs/user-guides/rum/sdk-features/error-sampling.md): Coralogix allows you to selectively track user sessions with and without errors, minimizing data overhead while focusing on critical issues. - [Ignore errors](https://coralogix.com/docs/user-guides/rum/sdk-features/ignore-errors.md): As part of Error Tracking, we understand that not all errors are created equal. Some errors may be inconsequential, recurring, or known issues that do not warrant immediate attention. To enhance your Real User Monitoring experience, we provide a feature that allows you to selectively ignore errors. This functionality empowers you to focus on the critical issues that truly impact user experience and streamline your error tracking process. - [Intercept & control RUM events with URL blueprinting](https://coralogix.com/docs/user-guides/rum/sdk-features/intercept-and-control-rum-events-with-url-blueprinting.md): The RUM Browser SDK captures RUM logs and events and populates their main attributes. URL Blueprinting gives you access to every event page or network URL collected by the RUM SDK. It allows you to modify its fields using custom-defined functions and then easily aggregate your data once ingested by Coralogix. - [Label provider](https://coralogix.com/docs/user-guides/rum/sdk-features/label-provider.md): The RUM Browser SDK captures RUM logs and events and populates their main attributes. Label Provider gives you access to every event or URL collected by the RUM SDK, allowing you to add labels using custom-defined functions and then easily filter and aggregate your data once ingested by Coralogix. - [Measuring memory usage](https://coralogix.com/docs/user-guides/rum/sdk-features/measuring-memory-usage.md): Measuring memory usage is crucial for optimizing an application’s performance and ensuring it runs efficiently. - [Micro frontend Error Tracking](https://coralogix.com/docs/user-guides/rum/sdk-features/micro-frontend-error-tracking.md): If your app employs micro frontends, it's crucial to identify which micro frontend an error originates from. With Coralogix, you can achieve this tracking, capturing, and reporting errors within a micro frontend architecture. - [Flutter](https://coralogix.com/docs/user-guides/rum/sdk-features/source-maps-flutter.md): Upload Dart symbols and source maps for your Flutter applications using the Coralogix RUM CLI to enable readable stack traces in production. - [React Native](https://coralogix.com/docs/user-guides/rum/sdk-features/source-maps-react-native.md): Take advantage of our Real User Monitoring (RUM) CLI to easily upload the source maps for your applications to the Coralogix RUM service. - [JavaScript](https://coralogix.com/docs/user-guides/rum/sdk-features/source-maps.md): Source map files are files commonly used in web development to facilitate the debugging process of minified or transpiled code. When JavaScript or CSS code is minified or transformed into a more compact form for production, it becomes challenging to trace errors back to the original source code due to the loss of meaningful variable names, line numbers, and structure. Source map files address this issue by providing a mapping between the minified code and its original, human-readable source code. This enables developers to debug efficiently by allowing browsers and debugging tools to display accurate error messages and stack traces based on the original code, aiding in the identification and resolution of issues in the development process. Take advantage of our RUM CLI to easily upload the source maps for your applications to the Coralogix RUM service. - [Trace capturing](https://coralogix.com/docs/user-guides/rum/sdk-features/trace-capturing.md): Specifying URLs for trace header propagation involves defining the specific endpoints in your application where trace headers will be transmitted during requests. - [Trace exporter](https://coralogix.com/docs/user-guides/rum/sdk-features/trace-exporter.md): Learn how to use the Coralogix RUM SDK Trace Exporter to intercept, process, and forward trace data before it is sent to Coralogix. - [Web worker support](https://coralogix.com/docs/user-guides/rum/sdk-features/web-workers-support.md): Web Worker support enables the SDK to capture events from within Web Workers, including unhandled exceptions, custom log messages, and other SDK-provided features, ensuring complete visibility across all execution contexts - [Android](https://coralogix.com/docs/user-guides/rum/sdk-installation/android.md): This guide shows you how to easily integrate the Coralogix RUM SDK into your native Android apps. Coralogix Android SDK supports Android 7.0+ (API level 24) and above. - [RUM Android SDK changelog](https://coralogix.com/docs/user-guides/rum/sdk-installation/android/release-notes.md): Release notes and changelog for the Coralogix RUM (Real User Monitoring) Android SDK (com.coralogix:android-sdk). - [iOS](https://coralogix.com/docs/user-guides/rum/sdk-installation/apple/ios.md): This guide provides instructions for integrating the Coralogix RUM SDK into iOS applications for UIKit and SwiftUI projects. It also details the configuration options, logging functionalities, and best practices for using method swizzling and SwiftUI modifiers to monitor and analyze app performance and user interactions. - [RUM iOS SDK changelog](https://coralogix.com/docs/user-guides/rum/sdk-installation/apple/release-notes.md): Release notes and changelog for the Coralogix RUM (Real User Monitoring) iOS SDK (CocoaPods Coralogix pod). - [tvOS](https://coralogix.com/docs/user-guides/rum/sdk-installation/apple/tvos.md): This guide provides instructions for integrating the Coralogix RUM SDK into tvOS applications for UIKit and SwiftUI projects. It also details the configuration options, logging functionalities, and best practices for using method swizzling and SwiftUI modifiers to monitor and analyze app performance and user interactions. - [Mobile flutter](https://coralogix.com/docs/user-guides/rum/sdk-installation/flutter/mobile.md): The Coralogix RUM Mobile SDK is a library (plugin) for Flutter that provides mobile telemetry instrumentation. Learn how to integrate with Coralogix's Real User Monitoring (RUM). - [RUM Flutter SDK changelog](https://coralogix.com/docs/user-guides/rum/sdk-installation/flutter/release-notes.md): Release notes and changelog for the Coralogix RUM (Real User Monitoring) Flutter SDK (cx_flutter_plugin). - [Web flutter](https://coralogix.com/docs/user-guides/rum/sdk-installation/flutter/web.md): The RUM browser SDK can be integrated into the Flutter web framework for telemetry instrumentation, enabling real-time performance monitoring and analytics. - [CDN browser SDK installation guide](https://coralogix.com/docs/user-guides/rum/sdk-installation/javascript/cdn-browser.md): CDN RUM browser SDK enables quick and efficient deployment of monitoring tools by embedding a script tag in your HTML - [Next.js](https://coralogix.com/docs/user-guides/rum/sdk-installation/javascript/nextjs.md): The Coralogix RUM SDK is a library (plugin) for Next.js that provides telemetry instrumentation. Learn how to integrate with Coralogix's Real User Monitoring (RUM). - [NPM browser SDK installation guide](https://coralogix.com/docs/user-guides/rum/sdk-installation/javascript/npm-browser.md): As part of our Real User Monitoring (RUM) toolkit, Coralogix offers multi-faceted Error Tracking, enabled by our RUM Browser SDK. This tutorial demonstrates how to set up and configure the RUM Browser SDK to hit the ground running with Error Tracking. Once configured, all network requests and errors in your system will be captured and sent to Coralogix. - [RUM Browser SDK changelog](https://coralogix.com/docs/user-guides/rum/sdk-installation/javascript/release-notes.md): Release notes and changelog for the Coralogix RUM (Real User Monitoring) Browser (JavaScript) SDK. - [SvelteKit](https://coralogix.com/docs/user-guides/rum/sdk-installation/javascript/sveltekit.md): The Coralogix RUM SDK is a library (plugin) for SvelteKit that provides telemetry instrumentation. Learn how to integrate with Coralogix's Real User Monitoring (RUM). - [Install RUM SDK](https://coralogix.com/docs/user-guides/rum/sdk-installation/overview.md): Learn how to install the Coralogix Real User Monitoring (RUM) SDK to start capturing frontend performance and user experience data. - [React Native plugin](https://coralogix.com/docs/user-guides/rum/sdk-installation/react-native/react-native-plugin.md): This document describes how to integrate the React Native SDK as part of Coralogix's Real User Monitoring. - [React Native SDK](https://coralogix.com/docs/user-guides/rum/sdk-installation/react-native/react-native-sdk.md): This document describes how to integrate the React Native SDK as part of Coralogix's Real User Monitoring. - [RUM React Native SDK changelog](https://coralogix.com/docs/user-guides/rum/sdk-installation/react-native/release-notes.md): Release notes and changelog for the Coralogix RUM (Real User Monitoring) React Native SDK (@coralogix/react-native-plugin). - [AWS Cloud Security Posture Management (CSPM)](https://coralogix.com/docs/user-guides/security/cloud-security-posture-management/aws-cloud-security-posture-management.md): Cloud Security Posture Management (CSPM) helps to mitigate and minimize cloud data security breaches and to assess the overall posture of the entire cloud environment against best practices and compliance standards to help remediate issues. - [Azure Cloud Security Posture Management (CSPM)](https://coralogix.com/docs/user-guides/security/cloud-security-posture-management/azure-cspm.md): Azure CSPM helps mitigate security risks, enforce compliance, and assess security posture using automated checks and best practices. This guide outlines the installation, configuration, and multi-subscription scanning setup for Azure CSPM. - [Downloading your security report](https://coralogix.com/docs/user-guides/security/cloud-security-posture-management/downloading-your-security-report.md): This guide demonstrates how to download your Coralogix security report via API. - [GCP Security Posture Management (CSPM)](https://coralogix.com/docs/user-guides/security/cloud-security-posture-management/gcp-security-posture-management.md): Security Posture Management (CSPM) helps to mitigate and minimize cloud data security breaches and to assess the overall posture of the entire cloud environment against best practices and compliance standards to help remediate issues. - [Cloudflare data ingestion](https://coralogix.com/docs/user-guides/security/security-data-sources/cloudflare-data-ingestion.md): Sending your Cloudflare events to Coralogix supports centralized log management, proactive monitoring, security analysis, and performance optimization. This integration helps you consolidate event data, set up custom alerts, detect security threats, identify performance bottlenecks, and maintain compliance, ultimately enhancing application security, reliability, and user experience through data-driven insights and actionable intelligence. - [FortiGate](https://coralogix.com/docs/user-guides/security/security-data-sources/fortigate.md): FortiGate traffic logs are essential records of network activity generated by Fortinet's security appliances, providing valuable insights into the traffic patterns, security events, and performance of your network. Send these to logs to Coralogix to gain a comprehensive and real-time view of your network's health and security. With the power of data-driven insights, you can optimize network performance, troubleshoot issues faster, and make informed decisions to enhance your organization's overall security posture. - [Okta contextual logs](https://coralogix.com/docs/user-guides/security/security-data-sources/okta-contextual-logs.md): This tutorial demonstrates how to create a pulling integration with Okta to send your contextual data logs to Coralogix. - [PingSafe](https://coralogix.com/docs/user-guides/security/security-data-sources/pingsafe.md): PingSafe is an industry-leading cloud security platform, which scans your cloud infrastructure from an attacker's lens. Security lapses are identified, prioritized, and auto-remediated to eliminate unwanted business impacts. This tutorial demonstrates how to undertake the PingSafe integration to Coralogix via webhook using Fluentd. - [SLO alerts](https://coralogix.com/docs/user-guides/slos/alerts.md): Get alerted when you are at risk of breaking SLOs with SLO alerts. - [SLO management API](https://coralogix.com/docs/user-guides/slos/apis/http-grpc-api.md): SLO Management API - [Design reliable SLOs](https://coralogix.com/docs/user-guides/slos/best-practices.md): Design Coralogix SLOs that are stable and operationally meaningful — match the SLO type, target, window, grouping, query shape, and alerting to the service. - [Create Service Level Objectives](https://coralogix.com/docs/user-guides/slos/create.md): Define Service Level Objectives in three styles — APM, event-based, or time window — from one workflow. - [Preview and validate SLOs](https://coralogix.com/docs/user-guides/slos/create/preview.md): Use the Preview panel during SLO creation to validate your queries, see the worst-performing permutations, and apply AI-suggested target adjustments before saving. - [Query validation](https://coralogix.com/docs/user-guides/slos/create/query-validation.md): During SLO creation, the system performs built-in validations. If any validation fails, an error message is displayed, and you must adjust your queries before proceeding. - [Infrastructure as code](https://coralogix.com/docs/user-guides/slos/IaC.md): Infrastructure as code - [Service Level Objectives](https://coralogix.com/docs/user-guides/slos/introduction.md): Service Level Objectives (SLOs) help you define clear, measurable performance targets for any object that emits metrics—whether it's a service, application, infrastructure component, or custom-defined entity. - [Permissions](https://coralogix.com/docs/user-guides/slos/permissions.md): Use there permissions to view and manage SLOs. - [Safe use of recording rule–based metrics and event2metrics in SLOs](https://coralogix.com/docs/user-guides/slos/recording-rule-based-metrics.md): To prevent inaccuracies in SLO calculations when using recording rule-based metrics and Event2Metrics as part of your setup, manually apply an offset to your PromQL queries. - [Using the underlying SLO metrics](https://coralogix.com/docs/user-guides/slos/underlying-metrics.md): The SLO center writes its evaluations to underlying metrics, which can be used in custom dashboards and for further calculations. - [View and manage Service Level Objectives](https://coralogix.com/docs/user-guides/slos/view-and-manage-slo.md): Stay on top of system reliability with clear visuals, real-time status, and actionable insights in the SLO Center. - [Coralogix Audit](https://coralogix.com/docs/user-guides/troubleshooting/coralogix-audit.md): Overview - [Troubleshoot data collection with Coralogix](https://coralogix.com/docs/user-guides/troubleshooting/troubleshoot-data-collection-with-coralogix.md): If you're sending logs to Coralogix using one of our integrations and the logs are not appearing in your Coralogix UI, here are a few common ways to troubleshoot your data collection. - [Grafana plugin](https://coralogix.com/docs/user-guides/visualizations/grafana-plugin.md): Coralogix allows your to define your Coralogix datastore as an additional data source to your Grafana for maximum flexibility in metric data visualizations - [Hosted Grafana view](https://coralogix.com/docs/user-guides/visualizations/hosted-grafana-view.md): Visualize your data using Coralogix's Hosted Grafana without having to integrate a personal Grafana instance with your Coralogix account. - [Hosted OpenSearch view](https://coralogix.com/docs/user-guides/visualizations/hosted-opensearch-view.md): Visualize your data using Coralogix’s Hosted OpenSearch without having to integrate your enterprise instance of OpenSearch with your Coralogix account. - [OpenSearch API](https://coralogix.com/docs/user-guides/visualizations/hosted-opensearch-view/opensearch-api.md): Coralogix provides an OpenSearch API that allows you to query your hosted OpenSearch instances securely and with ease. - [Predefined Heroku dashboard](https://coralogix.com/docs/user-guides/visualizations/predefined-heroku-dashboard.md): If you're completely new to Heroku logging, be sure to read our guide for beginners. - [Tableau plugin](https://coralogix.com/docs/user-guides/visualizations/tableau-plugin.md): This tutorial provides instructions on using the Coralogix JDBC driver with Tableau. ### DataPrime - [Welcome to the DataPrime advanced guide](https://coralogix.com/docs/dataprime/advanced-guide.md): Welcome to the DataPrime Advanced Guide. - [API queries](https://coralogix.com/docs/dataprime/API/api-queries.md): Run DataPrime or Lucene queries directly from your code—no need to open the Coralogix UI. - [gRPC API queries](https://coralogix.com/docs/dataprime/API/direct-archive-query-grpc.md): Overview - [HTTP API queries](https://coralogix.com/docs/dataprime/API/direct-archive-query-http.md): Overview - [API and background query limitations](https://coralogix.com/docs/dataprime/API/limitations.md): Limitations of the DataPrime language - [Quoting JSON in shell scripts for API requests](https://coralogix.com/docs/dataprime/API/quoting-json.md): This guide explains why quoting can break your HTTP API requests and how to structure payloads safely and cleanly. - [Introduction to the DataPrime cookbook](https://coralogix.com/docs/dataprime/cookbook.md): The DataPrime Cookbook is a collection of concise, copy-pasteable recipes designed to help you solve common log analysis and observability tasks faster. Each recipe focuses on a ready-to-use query designed to answer a specific question, flag a condition, or extract a useful signal from your data, and wraps it in a compact format that’s easy to adapt. - [Accessing fields with special characters](https://coralogix.com/docs/dataprime/cookbook/accessing_special_chars.md): Problem / Use case - [Audit schema field types and values by dataset](https://coralogix.com/docs/dataprime/cookbook/audit_schema_field_type.md): TL;DR - [Bucket longtask durations into performance ranges](https://coralogix.com/docs/dataprime/cookbook/bucket_longtask.md): Problem / Use case - [Conditionally count logs before and after 1 hour ago](https://coralogix.com/docs/dataprime/cookbook/conditionally_count.md): Problem / Use case - [Count k8s container restarts](https://coralogix.com/docs/dataprime/cookbook/container_restart.md): Problem / Use case - [Convert a timestamp](https://coralogix.com/docs/dataprime/cookbook/convert_timestamp.md): Problem / Use case - [Count and sort events by name](https://coralogix.com/docs/dataprime/cookbook/count_and_sort.md): Problem / Use case - [Count queries using joins by team](https://coralogix.com/docs/dataprime/cookbook/count_queries_by_team.md): TL;DR - [Count schema changes over time](https://coralogix.com/docs/dataprime/cookbook/count_schema_snapshots.md): TL;DR - [Summarize container restarts by deployment](https://coralogix.com/docs/dataprime/cookbook/counting_container_restarts.md): Problem / Use case - [Group failed queries by failure type](https://coralogix.com/docs/dataprime/cookbook/failed_query_analysis.md): TL;DR - [Find heavy DataPrime queries](https://coralogix.com/docs/dataprime/cookbook/find_heavy_queries.md): TL;DR - [Fuzzy search all fields](https://coralogix.com/docs/dataprime/cookbook/fuzzy_search_all_fields.md): Problem / Use case - [Calculate Lambda function invocation duration from logs](https://coralogix.com/docs/dataprime/cookbook/lambda_invocation.md): Problem / Use case - [Compare metadata vs. data field results in log queries](https://coralogix.com/docs/dataprime/cookbook/metadata.md): TL;DR - [Monitor dataset schema changes for compliance](https://coralogix.com/docs/dataprime/cookbook/monitoring_dataset_changes.md): Problem / Use case - [Parsing date strings](https://coralogix.com/docs/dataprime/cookbook/parsing_timestamps.md): Problem / Use case - [Find peak 10-minute traffic window per day](https://coralogix.com/docs/dataprime/cookbook/peak_traffic.md): Problem / Use case - [Create variables for timestamp calculations](https://coralogix.com/docs/dataprime/cookbook/timestamp_variables.md): Problem / use case - [Welcome to DataPrime](https://coralogix.com/docs/dataprime/introduction/welcome-to-the-dataprime-reference.md): DataPrime is Coralogix's piped syntax language, offering users a straightforward yet powerful tool for describing event transformations and aggregations. - [Overview](https://coralogix.com/docs/dataprime/language-reference.md): The full glossary of the DataPrime Query Language - [Access mechanisms](https://coralogix.com/docs/dataprime/language-reference/access_mechanisms.md): Metadata fields ($m) aren't shown as structured key/value rows in the Log details panel — they appear only nested in the panel's raw JSON. Querying them with the $m. mechanisms below is the most reliable way to read and inspect metadata values. - [Commands overview](https://coralogix.com/docs/dataprime/language-reference/commands-reference.md): The commands available in the DataPrime Query Language - [aggregate](https://coralogix.com/docs/dataprime/language-reference/commands-reference/aggregate.md): The `aggregate` command performs calculations across the entire working set of documents, producing summary statistics such as totals, averages, minimums, maximums, or counts. Unlike `groupby`, which splits data into multiple groups, `aggregate` computes results over the full dataset as a single group. Multiple aggregation functions can be combined in one command to produce a single document containing several computed values. !!! note Aggregations are limited to 1000 buckets in a single operation. - [block](https://coralogix.com/docs/dataprime/language-reference/commands-reference/block.md): The `block` command filters out all documents where the given predicate evaluates to true. It is the inverse of `filter`, which keeps only documents that match the predicate. - [bottom](https://coralogix.com/docs/dataprime/language-reference/commands-reference/bottom.md): The `bottom` command limits the rows returned from a query to the last *N* rows in a given set, ordered by a specified expression. It is useful for finding the lowest-ranking values or least frequent occurrences within a dataset. !!! note When using this command, pay close attention to your ordering expression, as it determines which records are considered "bottom" in the result. - [choose](https://coralogix.com/docs/dataprime/language-reference/commands-reference/choose.md): The `choose` command removes all keypaths **not explicitly specified**. This allows you to extract and reshape only the data you need from a larger log document. !!! note The `choose` command supports nested key paths and aliasing in the output, making it useful for simplifying complex documents. - [convert](https://coralogix.com/docs/dataprime/language-reference/commands-reference/convert.md): The `convert` command is a **semantic keyword** that indicates type conversion is taking place. It has no effect on query execution and exists purely to make transformations more readable and self-documenting. !!! note The `convert` keyword is optional and does not change functionality. Use it when you want to make type changes explicit in your query. - [count](https://coralogix.com/docs/dataprime/language-reference/commands-reference/count.md): The `count` command returns a single row representing the total number of documents in the current result set. It can optionally store this result in a named keypath for readability using the `into` keyword. - [countby](https://coralogix.com/docs/dataprime/language-reference/commands-reference/countby.md): The `countby` command generates a count for each distinct value in a given expression, effectively grouping the results by that key. !!! note Unlike `count`, which tallies all records in a set, `countby` provides a per-group count based on the specified key or expression. - [create](https://coralogix.com/docs/dataprime/language-reference/commands-reference/create.md): The `create` command defines a new key and assigns it a value derived from an expression. It is one of the most flexible commands in DataPrime, allowing you to **add new fields**, **populate missing data**, or **enrich existing structures** without overwriting parent keys. In practice, `create` acts like a safe write operation for structured data. You can explicitly control what happens when a key already exists, when it is missing, or when the new value's type differs from the existing one. - **Existing keys** can be overwritten, skipped, or cause the query to fail. - **Missing keys** can be created, skipped, or trigger a failure. - **Type changes** can either be enforced, ignored, or handled as an error. !!! note Key creation is granular, meaning that parent keys in the path are not overwritten. This allows you to safely add fields within existing objects, even in nested log structures. - [dedupeby](https://coralogix.com/docs/dataprime/language-reference/commands-reference/dedupeby.md): The `dedupeby` command removes duplicate documents based on one or more expressions, keeping only *N* events for each unique combination of the specified fields. This is especially useful for sampling representative data from large datasets without aggregation. Conceptually, it functions like a smart filter: it doesn’t modify event content or compute summaries—it simply trims redundancy by retaining a limited number of examples per group. Use the optional `orderby` clause to control *which* events are kept within each group—for example, the most recent entries by sorting on `$m.timestamp desc`, or the slowest requests by sorting on a latency field. Without `orderby`, the choice of which events to retain per group is not deterministic. !!! note The content of each retained document remains unchanged. `dedupeby` only limits how many documents are kept for each unique grouping. - [distinct](https://coralogix.com/docs/dataprime/language-reference/commands-reference/distinct.md): The `distinct` command returns one document per unique value (or combination of values) for the given expressions. It is particularly useful for reporting or identifying unique entities within a dataset. Functionally, it behaves like a lightweight `groupby` without any aggregation functions—simply collapsing duplicates and returning the first occurrence of each distinct value. !!! note Use `distinct` when you want a list of unique keys, not an aggregate summary. - [enrich](https://coralogix.com/docs/dataprime/language-reference/commands-reference/enrich.md): The `enrich` command adds contextual information to logs by performing lookups against a custom enrichment table. It merges additional columns from the lookup into each log document based on a matching key. This is particularly useful for attaching static metadata (like user details, service mappings, or IP ownership) to incoming logs without modifying upstream systems. The enrichment is applied **at query time**, meaning you always work with the most recent version of the enrichment table. Each lookup table must be created and uploaded beforehand as a **Custom Enrichment**. For setup and management instructions, see [Custom Enrichment](../../../user-guides/enrichment_rules/custom_enrichment/index.md). !!! note - All values in a lookup table are stored as strings. Use conversion functions such as `toNumber()` or `toTimestamp()` if a different type is required. - If a log already contains the enriched key, `enrich` will merge or update only the matching sub-keys; unrelated fields remain unchanged. - [explode](https://coralogix.com/docs/dataprime/language-reference/commands-reference/explode.md): The `explode` command transforms an array of *N* elements into *N* separate documents, each containing one element of the array at the specified keypath. It’s commonly used to “flatten” nested data structures for easier analysis or aggregation. When using `explode`, you can control whether to keep or remove the original document fields via the `original` modifier: - `original discard` removes all original fields, producing minimal output with just the exploded key. - `original preserve` retains the original document fields, duplicating them across the new documents. !!! note If the destination keypath already exists in the document, it is overwritten by the exploded value. The default behavior is `original discard`. - [extract](https://coralogix.com/docs/dataprime/language-reference/commands-reference/extract.md): The `extract` function allows you to transform raw strings into structured data by parsing out embedded values and storing them as objects. It supports various extraction strategies to convert unstructured fields into clean, queryable formats. - [filter](https://coralogix.com/docs/dataprime/language-reference/commands-reference/filter.md): The `filter` command removes all documents that do not satisfy a specified condition. Only events for which the condition evaluates to `true` are retained in the result set. This command forms the foundation of most queries—it defines which data should be kept for further transformation or aggregation. Filters can be simple comparisons or complex logical expressions involving multiple conditions and functions. !!! note When comparing keypaths to `null`, the comparison only works on scalar values (`string`, `number`, `timestamp`, etc.). For nested JSON objects, comparisons with `null` will always return `null`. - [find / text](https://coralogix.com/docs/dataprime/language-reference/commands-reference/find_text.md): The `find` command performs a free-text search within a specified keypath. It acts as a shorthand for combining `filter` with a text match (`~`). This command is ideal for quick searches across log messages or string fields where full parsing is unnecessary. The alias `text` can be used interchangeably with `find`. - [groupby](https://coralogix.com/docs/dataprime/language-reference/commands-reference/groupby.md): The `groupby` command aggregates documents that share one or more common values or calculated expressions, allowing you to compute metrics such as `sum`, `avg`, `max`, `min`, and `count`. It is the cornerstone of DataPrime’s analytical capabilities, enabling powerful summarization and insight generation from raw event data. Each unique combination of grouping expressions produces a single output document. The `aggregate` or `agg` keyword specifies which aggregation functions to apply within each group. !!! note You can group by both keypaths and calculated expressions. When grouping by an expression, DataPrime evaluates it dynamically for each document before grouping. - [join](https://coralogix.com/docs/dataprime/language-reference/commands-reference/join.md): The `join` command merges the current (left) query with the results of a second (right) query. Conceptually, it forms a Cartesian product of left and right rows, then applies join logic based on a condition (`on`) or matching keypaths (`using`) and writes the matching right-side row into a destination keypath (`into`). **Join types** * **left** (default): Keep all left rows; attach matching right rows or `null` when no match. * **inner**: Keep only rows that match on both sides. * **full**: Keep all rows from both sides; non-matching fields are `null`. * **cross**: Return the full Cartesian product; no `on`/`using` supported. **Addressing fields** * Use `left=>` and `right=>` prefixes inside `on` to disambiguate fields with the same name; omit when a keypath exists only on one side. **Behavior & caveats** * Conditions support **equality (`==`)** on keypaths; chain multiple with `&&`. * One side must be relatively small (< 200MB); reduce size with `filter` or `remove`. * In left joins, nulls in the join keys prevent matches; use `join full` to include unmatched keys from either side. * Joins can duplicate rows if multiple matches exist; consider preprocessing (e.g., `distinct`) to avoid unintended multiplicity. - [limit](https://coralogix.com/docs/dataprime/language-reference/commands-reference/limit.md): The `limit` command restricts the number of documents returned by a query to a specified count. It is typically used after sorting or aggregation operations to retrieve only the most relevant or top results from a larger dataset. This command is especially useful for performance optimization or for displaying only a subset of high-value results (for example, the top 100 users or the most recent 50 logs). !!! note The `limit` command does not guarantee order unless used after an explicit `orderby`. If order matters, always pair it with `orderby` to ensure predictable results. - [lucene](https://coralogix.com/docs/dataprime/language-reference/commands-reference/lucene.md): The `lucene` command executes a Lucene query within a DataPrime query, allowing users to seamlessly combine Lucene’s search syntax with DataPrime’s structured query capabilities. This enables powerful hybrid queries—for example, filtering or aggregating over results first narrowed by a Lucene search expression. !!! note Field names inside the Lucene query are relative to `$d` (the root level of user data). You can combine Lucene search with other DataPrime commands such as `filter`, `aggregate`, or `groupby`. - [move](https://coralogix.com/docs/dataprime/language-reference/commands-reference/move.md): The `move` command relocates a keypath to a new position within a document. This is useful when keypaths are deeply nested or inconsistently structured, making queries cumbersome to write and read. When a keypath is moved, its value (and any child keys if it’s an object) is transferred to the target keypath, and the original keypath is removed. !!! note If the source keypath is an object, the entire key and all child elements are moved to the new location. - [multigroupby](https://coralogix.com/docs/dataprime/language-reference/commands-reference/multigroupby.md): The `multigroupby` command concatenates the results from two or more [`groupby`](groupby.md) queries into a single dataset. It allows multiple aggregation queries to execute in one scan, improving efficiency and keeping grouped results synchronized. **Key benefits:** - **Efficiency:** Data is scanned only once across multiple groupings. - **Synchronization:** Results remain coherent, avoiding mismatches between independently run groupby queries. !!! note The maximum number of buckets that `multigroupby` can process is 64. - [orderby / sortby](https://coralogix.com/docs/dataprime/language-reference/commands-reference/orderby_sortby.md): The `orderby` command sorts query results in ascending or descending order based on one or more expressions. It supports multiple sort keys, allowing you to order by several fields sequentially. The command has several aliases, `orderby`, `sortby`, `order by`, and `sort by`, that behave identically. !!! note Sorting is limited to 10,000 values. Beyond that limit, order is not guaranteed. - [redact](https://coralogix.com/docs/dataprime/language-reference/commands-reference/redact.md): The `redact` command replaces parts of a string that match a given substring or regular expression with a replacement value. It’s commonly used to hide sensitive information such as emails, tokens, or identifiers found in message fields. You can use either a plain string or a regular expression pattern to define what should be redacted. !!! note The optional keyword `matching` improves readability but is not required. - [remove](https://coralogix.com/docs/dataprime/language-reference/commands-reference/remove.md): The `remove` command deletes one or more keypaths from every document in the working set. It is the inverse of `choose`, which keeps only the specified fields. This is especially useful for sanitizing logs or removing fields containing unnecessary or sensitive information before performing analysis. !!! note `remove` can operate on scalar values or entire objects. - [replace](https://coralogix.com/docs/dataprime/language-reference/commands-reference/replace.md): The `replace` command overwrites the value of an existing keypath with the result of a new expression. It is often used to clean or transform existing values while maintaining the same document structure. This is particularly helpful for decoding, normalizing, or updating data fields without creating new keys. - [source](https://coralogix.com/docs/dataprime/language-reference/commands-reference/sources/source.md): The `source` command is a foundational component of DataPrime. It informs the DataPrime engine which datasource you wish to read from. !!! note While you can start your query with this, the `source` command is optional and will default to `logs`. ### Basic usage In DataPrime, you read data by specifying a **dataset** within an optional **dataspace**: ```dataprime source / ``` If no dataspace is provided, the query defaults to the `default` dataspace. This allows for concise syntax when working within the most common data sources. Common datasets include: * `logs` – Application and infrastructure logs. *Default dataset. Equivalent to `source default/logs`.* * `spans` – Distributed tracing data from systems like OpenTelemetry. *Equivalent to `source default/spans`.* * `enrichments/` – [custom enrichment](../../../../user-guides/enrichment_rules/custom_enrichment/index.md) tables uploaded via the UI or API. *For example: `source default/enrichments/ip_lookup`* You can also query your **High (Frequent Search)** tier directly through the `frequentsearch` dataspace: * `frequentsearch/logs` – High-priority logs kept in the Frequent Search (hot) tier. * `frequentsearch/spans` – High-priority spans kept in the Frequent Search (hot) tier. Because `frequentsearch` datasets behave like any other source, you can reference them in [`join`](../join.mdx) and [`union`](../union.mdx) operations alongside `default` and `system` data. For more, see the [data layer overview](../../../../user-guides/data-layer/overview.mdx). You can also query system-generated datasets such as: * `system/engine.queries` – Logs of all DataPrime query executions. * `system/alerts.history` – Historical records of alert events. > Dataset names may include dots (e.g., `engine.queries`) but are still treated as flat identifiers—not nested structures. This structure supports querying across teams, environments, or pipelines—whether you’re debugging logs, analyzing performance, or auditing notifications. - [around](https://coralogix.com/docs/dataprime/language-reference/commands-reference/sources/time/around.md): The `around` keyword allows users to declare a timerange, defined as some interval before and after a `timestamp`, on which a query should operate. !!! note The `interval`, if specified, **MUST** be positive. !!! note If the `interval` is not specified, then a default value of `30m` is used. - [between](https://coralogix.com/docs/dataprime/language-reference/commands-reference/sources/time/between.md): The `between` keyword specifies a date range on which a query on `logs` or `spans` should operate. !!! note The `between` keyword will work on any time expression, but the result of the expression must be of type `timestamp`. - [last](https://coralogix.com/docs/dataprime/language-reference/commands-reference/sources/time/last.md): The `last` keyword specifies how far back in time a query should go, defined by a given `interval`. !!! note The value of the given `interval` MUST be non-negative. - [timeshifted](https://coralogix.com/docs/dataprime/language-reference/commands-reference/sources/time/timeshifted.md): The `timeshifted` keyword modifies the timerange within the scope of the query. This is useful when, for example, a custom dashboard has a global timerange of `Today` but your query only makes sense when looking at yesterday's data. - [stitch](https://coralogix.com/docs/dataprime/language-reference/commands-reference/stitch.md): The `stitch` command performs a **horizontal union** of two datasets, combining them side-by-side. It aligns rows from one dataset with rows from another and merges their columns into a single unified dataset. This is particularly useful for joining datasets that share a logical order but lack a join key. **Key behaviors:** - Rows are combined in order (row 1 with row 1, row 2 with row 2, etc.). - If one dataset contains more rows than the other, unmatched rows include `null` values for missing columns. - The resulting dataset contains all columns from both sides. **Difference from `union`:** - `stitch` merges datasets horizontally (adding columns). - `union` merges datasets vertically (adding rows). - [top](https://coralogix.com/docs/dataprime/language-reference/commands-reference/top.md): The `top` command returns the first N results after sorting by one or more expressions in the `by` clause. It can be used with plain expressions or with aggregation functions. !!! note - Without aggregation, `top` limits the full result set to N rows, ordered by a given expression. - With aggregation, `top` groups results by the result expressions and returns the top N groups (not N rows per group), ranked by the ordering expression. - Sorting direction (ascending/descending) is determined by the expression or implicit aggregate ordering. !!! note `top` with aggregation returns top N **groups overall**, not N rows per group. - [union](https://coralogix.com/docs/dataprime/language-reference/commands-reference/union.md): The `union` command concatenates the results from two or more datasets into one dataset. This allows users to combine results from multiple queries into one seamless dataset. One dataset can be a result set piped into the `union` command and then concatenated with another dataset. - [wildfind / wildtext](https://coralogix.com/docs/dataprime/language-reference/commands-reference/wildfind_wildtext.md): The `wildfind` command searches for a given string across **all keypaths** in every document in the working set. It is useful when you don’t know which field contains the target value. The alias `wildtext` behaves identically. !!! note `wildfind` is significantly slower than `find` or `text`, since it must inspect every field in every document. Use `find` when the keypath is known for better performance. - [Functions overview](https://coralogix.com/docs/dataprime/language-reference/functions-reference.md): All functions available in the DataPrime Query Language - [any_value](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/any_value.md): Returns any non-null value from the specified expression within a group. If no expression is provided, it defaults to the `$d` object. Returns `null` if all values in the group are `null`. - [approx_count_distinct](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/approx_count_distinct.md): Returns an approximate count of unique, non-null values for a given expression. * A document is counted if it contains a unique, non-null value. * The result is approximate, optimized for performance rather than precision. !!! note `approx_count_distinct` is an aggregation function and must be used with a grouping keyword such as `groupby`. - [avg](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/avg.md): Returns the average (mean) value of a numerical expression. !!! note The input must be a number. Use a cast if the field is stored as a string. - [collect](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/collect.md): Returns an array of values collected from an expression for each group. * Supports optional deduplication (`distinct`), null filtering (`ignoreNulls`), and element limits (`limit`). * Values are aggregated into an array, preserving order of processing unless constrained by `distinct` or `limit`. - [count_if](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/count_if.md): Returns the number of rows that satisfy a given condition, counting only non-null expression values. * Useful for measuring subsets of data within groups. * Can evaluate a condition alone or in combination with a non-null expression. !!! note `count_if` is an aggregation function and must be used with a grouping keyword such as `groupby`. - [distinct_count_if](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/distinct_count_if.md): Returns the number of distinct, non-null values that satisfy a given condition. * A document is counted only if the condition evaluates to `true`. * Duplicate values for the same expression are counted once per group. !!! note `distinct_count_if` is an aggregation function and must be used with a grouping keyword such as `groupby`. - [distinct_count](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/distinct_count.md): Returns the number of distinct, non-null values for a given expression. * Each unique value is counted once per group. !!! note `distinct_count` is an aggregation function and must be used with a grouping keyword such as `groupby`. !!! warning `distinct_count` isn't supported on the **High (Frequent Search)** tier. On `frequentsearch` data, use [`approx_count_distinct`](./approx_count_distinct.mdx) instead, which returns an approximate count of distinct values. - [max_by](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/max_by.md): Returns the value of an expression associated with the maximum value of a given sort key. * Both `sortKey` and `expression` must be comparable types (`string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, or `enum`). * Useful for retrieving details from the row that has the maximum value of another field. - [max](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/max.md): Returns the largest numerical value from the input. * Can be used in aggregation to compute the maximum value across grouped rows. * When used with multiple arguments, returns the largest among them. - [min_by](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/min_by.md): Returns the value of an expression associated with the minimum value of a given sort key. * Both `sortKey` and `expression` must be comparable types (`string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, or `enum`). * Useful for retrieving details from the row that has the earliest or smallest value of another field. - [min](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/min.md): Returns the smallest numerical value from the input. * Can be used in aggregation to compute the minimum value across grouped rows. * When used with multiple arguments, returns the smallest among them. - [percentile](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/percentile.md): Returns the approximate n-th percentile of a numerical expression. * The percentile value must be between `0` and `1`. * The calculation is approximate, with accuracy controlled by the optional `error_threshold`. - [sample_stddev](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/sample_stddev.md): Returns the sample standard deviation of a numerical expression within a group. * Designed for use cases where substantial values are missing, such as when data is heavily sampled. !!! note Use `sample_stddev` when working with incomplete datasets (e.g., sampled trace data). For full datasets, prefer `stddev`. - [sample_variance](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/sample_variance.md): Returns the sample variance of a numerical expression within a group. * Useful for analyzing variability when working with incomplete datasets. * Designed for scenarios like heavy trace sampling, where global variance would be misleading. !!! note Use `sample_variance` when only a subset of data is available. For complete datasets, prefer `variance`. - [stddev](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/stddev.md): Returns the standard deviation of a numerical expression within a group. * Useful for measuring how much values vary around the mean. * Best applied when a complete dataset is available (for sampled data, use `sample_stddev`). - [sum](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/sum.md): Returns the total of all numerical values passed into the function. * Can be used in aggregation to compute totals across grouped rows. * When used with multiple arguments, returns the sum of all provided values. - [variance](https://coralogix.com/docs/dataprime/language-reference/functions-reference/aggregation/variance.md): Returns the variance of a numerical expression within a group. * Variance measures how far values spread out from the mean. * Best applied when a complete dataset is available (for sampled data, use `sample_variance`). - [arrayAppend](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayappend.md): Returns a new array with an additional element appended to the end of an existing array. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayConcat](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayconcat.md): Returns a new array by concatenating the elements of two arrays into a single array. * Both arrays must be of the same element type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayContains](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arraycontains.md): Returns `true` if an array includes the specified element, or `false` if it does not. * This function is the mirror version of [inArray](inArray.md). * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayInsertAt](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayinsertat.md): Returns a new array with an element inserted at the specified position. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayJoin](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayjoin.md): Returns a single string by joining the elements of an array using the specified delimiter. * The element type must be compatible with string conversion. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayLength](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arraylength.md): Returns the number of elements in an array. - [arrayRemove](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayremove.md): Returns a new array with the specified element removed. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayRemoveAt](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayremoveat.md): Returns a new array with the element at the specified position removed. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. * Positions are **0-indexed**. - [arrayReplaceAll](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayreplaceall.md): Returns a new array where all instances of a specified value are replaced with a new value. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arrayReplaceAt](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arrayreplaceat.md): Returns a new array with the element at the specified position replaced by a new value. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [arraySort](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arraysort.md): Returns a new array with the elements sorted according to the specified options. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. * By default, the array is sorted in ascending order, with null values appearing last. - [arraySplit](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/arraysplit.md): Returns an array of substrings by splitting a string using the specified delimiter. * The delimiter can be either a `string` or a `regexp`. - [cardinality](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/cardinality.md): Returns the number of unique elements in an array. * The element type must match the array type. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [inArray](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/inArray.md): Returns `true` if the specified element exists within the array, or `false` if it does not. * This function is the inverse of [`arrayContains`](arraycontains.md). * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [isEmpty](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/isempty.md): Returns `true` if the array contains no elements, or `false` otherwise. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [isSubset](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/issubset.md): Returns `true` if `array1` is a subset of `array2`, or `false` otherwise. * When comparing `array1` and `array2`, duplicates are discarded. This means two arrays of different lengths but with the same unique elements are considered equal. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [isSuperset](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/issuperset.md): Returns `true` if `array1` is a superset of `array2`, or `false` otherwise. * When comparing `array1` and `array2`, duplicates are discarded. This means two arrays of different lengths but with the same unique elements are considered equal. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [setDiff](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/setdiff.md): Returns the set difference of two arrays, producing a new array with elements from `array1` that are not in `array2`. * Duplicates are discarded when computing the difference. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [setDiffSymmetric](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/setdiffsymmetric.md): Returns the symmetric difference of two arrays, producing a new array with elements that exist in either `array1` or `array2` but not in both. * Duplicates are discarded when computing the difference. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [setEqualsTo](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/setequalsto.md): Returns `true` if `array1` and `array2` contain the same unique elements, or `false` otherwise. * When comparing arrays, duplicates are discarded. This means two arrays of different lengths but with the same unique elements are considered equal. * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [setIntersection](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/setintersection.md): Returns the intersection of two arrays, producing a new array with elements common to both. * Both arrays are treated as sets: * Duplicates are removed from both arrays * Order is not preserved in the result * `null` is treated as an empty set * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [setUnion](https://coralogix.com/docs/dataprime/language-reference/functions-reference/array/setunion.md): Returns the union of two arrays, producing a new array that contains all unique elements from both. * Both arrays are treated as sets: * Duplicates are removed * Order is not preserved in the result * `null` is treated as an empty set * Supported element types include `string`, `bool`, `number`, `interval`, `timestamp`, `regexp`, and `enum`. - [case_contains](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case_contains.md): Returns a value based on whether a string contains one of several specified substrings. This function is a shorthand for `case` expressions with [`contains()`](../string/contains.md) logic and helps shorten queries that would otherwise repeat conditional statements. If no clause matches and no `_` fallback is present, `case_contains` returns `null`. !!! warning "Behavior change" Earlier implementations of `case_contains` evaluated each clause with the [text match](../../../user-guide/foundations/understanding-expressions.md) (`~`) operator instead of `contains()`, which did not match the documented behavior. `case_contains` now correctly evaluates each clause with [`contains()`](../string/contains.md) for case-sensitive substring matching. If your query relied on the previous text-match behavior, use [`case_find`](case_find.md) instead. !!! note `case_contains` checks clauses top-to-bottom and returns the **first match**, so order matters. - [case_equals](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case_equals.md): Returns a value based on whether an expression equals one of several specified values. This function is a shorthand for `case` expressions with equality (`==`) logic and helps shorten queries that would otherwise repeat conditional statements. If no clause matches and no `_` fallback is present, `case_equals` returns `null`. !!! note `case_equals` checks clauses top-to-bottom and returns the **first match**, so order matters. - [case_find](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case_find.md): Returns a value based on whether a string matches one of several specified text patterns. This function is a shorthand for `case` expressions with [text match](../../../user-guide/foundations/understanding-expressions.md) (`~`) logic and helps shorten queries that would otherwise repeat conditional statements. Use `case_find` when you want pattern matching — the same behavior the [`find`](../../commands-reference/find_text.md) command uses for free-text search. For strict substring containment, use [`case_contains`](case_contains.md) instead. If no clause matches and no `_` fallback is present, `case_find` returns `null`. !!! note `case_find` checks clauses top-to-bottom and returns the **first match**, so order matters. - [case_greaterthan](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case_greaterthan.md): Returns a value based on whether a number is greater than one of several thresholds. This function is a shorthand for `case` expressions with `>` (greater than) logic and helps shorten queries that would otherwise repeat conditional statements. If no clause matches and no `_` fallback is present, `case_greaterthan` returns `null`. !!! note `case_greaterthan` checks clauses top-to-bottom and returns the **first match**, so order matters. - [case_lessthan](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case_lessthan.md): Returns a value based on whether a number is less than one of several thresholds. This function is a shorthand for `case` expressions with `<` (less than) logic and helps shorten queries that would otherwise repeat conditional statements. If no clause matches and no `_` fallback is present, `case_lessthan` returns `null`. !!! note `case_lessthan` checks clauses top-to-bottom and returns the **first match**, so order matters. - [case](https://coralogix.com/docs/dataprime/language-reference/functions-reference/cases/case.md): Returns a value from the first clause whose condition evaluates to `true`. Each clause is a `condition -> value` pair: when `condition` evaluates to `true`, `case` returns `value`. You can include any number of clauses, plus an optional `_ -> default` fallback. If no condition matches and no fallback is present, `case` returns `null`. !!! note `case` checks clauses top-to-bottom and returns the **first match**, so order matters. - [dataset](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/dataset.md): Return the name of the **dataset** that a record originated from, such as `logs` or `spans`. This is especially useful when a query combines records from more than one dataset — for example with [`union`](../../commands-reference/union.mdx) or [`join`](../../commands-reference/join.mdx) — and you need to know which dataset each record came from. !!! note To learn how datasets and dataspaces work, see [`source`](../../commands-reference/sources/source.mdx). - [dataspace](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/dataspace.md): Return the name of the **dataspace** that a record originated from, such as `default`. This is especially useful when a query combines records from more than one source — for example with [`union`](../../commands-reference/union.mdx) or [`join`](../../commands-reference/join.mdx) — and you need to know which dataspace each record came from. !!! note To learn how datasets and dataspaces work, see [`source`](../../commands-reference/sources/source.mdx). - [firstNonNull](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/firstnonnull.md): Return the first non-null value from a list of arguments, in the order they are provided. !!! note Works only on scalar values such as `number`, `string`, or `timestamp`. Does not work on objects. - [if](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/if.md): Return one value if a condition is `true`, otherwise return an alternative value. - [in](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/in.md): Return `true` if a given value matches any value in a list of candidates, otherwise return `false`. - [recordLocation](https://coralogix.com/docs/dataprime/language-reference/functions-reference/general/recordlocation.md): Return the cloud storage location of a record, such as the URL of an S3 object when using AWS S3. !!! note Works only with data stored in your cloud storage. Running this on indexed documents (Frequent Search mode) will return `null`. Use it alongside [`dataset()`](./dataset.mdx) and [`dataspace()`](./dataspace.mdx) to capture the full source of a record — its dataspace, dataset, and exact storage location. - [ipInSubnet](https://coralogix.com/docs/dataprime/language-reference/functions-reference/ip/ipinsubnet.md): Return `true` if an IP address belongs to a given subnet, otherwise return `false`. - [ipPrefix](https://coralogix.com/docs/dataprime/language-reference/functions-reference/ip/ipprefix.md): Return the CIDR subnet for a given IP address and subnet size. - [abs](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/abs.md): Returns the absolute value of a number. Useful for computing the total difference between two values without regard to sign. - [ceil](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/ceil.md): Returns the smallest integer greater than or equal to a number. For example, `1.5` becomes `2`, and `8.1` becomes `9`. - [e](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/e.md): Returns Euler’s number `e`, a mathematical constant approximately equal to `2.718281828459045`. This value is limited to 15 decimal places. - [floor](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/floor.md): Returns the largest integer less than or equal to a number. For example, `1.5` becomes `1`, and `8.1` becomes `8`. - [fromBase](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/frombase.md): Converts a string representation of a number in a given base into its numeric value. For example, `"101"` in base `2` becomes `5` in base `10`. - [ln](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/ln.md): Computes the natural logarithm (base *e*) of a number. - [log](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/log.md): Returns the logarithm of a number to a specified base. Common uses include modeling compound interest, exponential growth or decay, pH levels, and earthquake magnitudes. - [log2](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/log2.md): Returns the base-2 logarithm of a number. Equivalent to `log(2, number)`. - [mod](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/mod.md): Returns the remainder after dividing a number by a divisor. Equivalent to the modulus operator (`%`). - [pi](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/pi.md): Returns the mathematical constant π (pi), limited to 15 decimal places. - [power](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/power.md): Returns the result of raising a number to the power of an exponent. - [random](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/random.md): Returns a pseudorandom decimal between `0` (inclusive) and `1` (exclusive). !!! note `random` is not cryptographically secure. - [randomInt](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/randomint.md): Returns a pseudorandom integer between `0` (inclusive) and an upper bound (exclusive). !!! note `randomInt` is not cryptographically secure. - [round](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/round.md): Returns a number rounded to the nearest integer or to a specified number of decimal places. For example, `1.5` becomes `2` and `8.1` becomes `8`. - [sqrt](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/sqrt.md): Returns the square root of a number. !!! note This is the inverse of `power(number, 2)`. - [toBase](https://coralogix.com/docs/dataprime/language-reference/functions-reference/number/tobase.md): Converts a number into its string representation in a specified base. For example, converting `10` into base `16` results in `"a"`. - [byteLength](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/bytelength.md): Returns the number of bytes required to represent a UTF-8 encoded string. - [chr](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/chr.md): Converts a numeric Unicode code point into its corresponding string character. - [codepoint](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/codepoint.md): Converts a Unicode character into its numeric code point representation. - [concat](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/concat.md): Joins multiple strings together and return the result as a single string. - [contains](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/contains.md): Returns `true` if the given substring appears anywhere in a string; otherwise return `false`. The check is case sensitive. For case-insensitive matching, normalize both values with `toLowerCase()` or `toUpperCase()` before calling `contains`. - [decodeBase64](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/decodebase64.md): Decodes a Base64-encoded string into its original value. - [encodeBase64](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/encodebase64.md): Encodes a string into its Base64 representation. - [endsWith](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/endswith.md): Returns `true` if a string ends with a given substring, otherwise return `false`. !!! note Unlike `contains`, which checks for a substring anywhere in the string, `endsWith` only matches the end. - [indexOf](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/indexof.md): Returns the position of the first occurrence of a substring within a string. The index is zero-based. If the substring is not found, the function returns `-1`. - [length](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/length.md): Returns the number of characters in a string. - [ltrim](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/ltrim.md): Removes whitespace from the start of a string while leaving the end unchanged. - [matches](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/matches.md): Returns `true` if a string matches a given regular expression. The expression is applied to the entire string; partial matches return `false`. - [pad](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/pad.md): **Alias for [`padLeft`](./padleft.md).** Adds characters to the beginning of a string until it reaches the desired length. If the string is longer than the target length, it is truncated from the end. !!! note The `fillWith` argument must be a single-character string. - [padLeft](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/padleft.md): Adds characters to the beginning of a string until it reaches the desired length. If the string is longer than the target length, it is truncated from the end. !!! note The `fillWith` argument must be a single-character string. - [padRight](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/padright.md): Adds characters to the end of a string until it reaches the desired length. If the string is longer than the target length, it is truncated from the end. !!! note The `fillWith` argument must be a single-character string. - [regexpSplitParts](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/regexpsplitparts.md): Splits a string using a regular expression as the delimiter and return the token at the specified index. The index starts at 1, not 0. - [rtrim](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/rtrim.md): Removes whitespace from the end of a string while leaving the beginning unchanged. - [splitParts](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/splitparts.md): Splits a string using a delimiter and return the token at the specified index. The index starts at 1, not 0. - [startsWith](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/startswith.md): Returns `true` if a string begins with a given substring, otherwise return `false`. !!! note Unlike `contains`, which checks for a substring anywhere in the string, `startsWith` only matches the beginning. - [substr](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/substr.md): Extracts a substring from a string starting at a given position, with an optional length. Useful for simple value extraction without needing regular expressions. - [textSearch](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/textsearch.md): Searches for a text phrase within a target value. The behavior depends on the type of the target: * **Primitive types** (`string`, `number`, `bool`, `interval`, `timestamp`, `regexp`, `enum`) are converted to strings before searching. * **Objects** are searched by their values (keys are ignored). * **Arrays** are searched by their elements. The `phrase` must appear as one or more complete tokens. Tokens are defined during log parsing and are split on the following characters: whitespace (`\s`), `=`, `/`, `:`, `@`, `#`, `$`, `*`, `|`, `,`, `;`, `'`, `"`, `(`, `[`, `{`, `}`, `)`, `]`, `<`, `>`, `.`, `_`, `-`. Because of this, a search for `online` will not match `onlineboutique` (one token), but will match `online_boutique` (`online` and `boutique` are separate tokens). Similarly, `Version 17` matches `Version 17.4 (Build 21E213)` because `Version` and `17` are two tokens, but `Vers` would not match because it is not a full token. - [toLowerCase](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/tolowercase.md): Converts all alphabetical characters in a string to lowercase. - [toUpperCase](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/touppercase.md): Converts all alphabetical characters in a string to uppercase. - [trim](https://coralogix.com/docs/dataprime/language-reference/functions-reference/string/trim.md): Removes whitespace from both the start and end of a string. - [addInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/addinterval.md): Returns the sum of two intervals as a single interval value. For example, adding an interval of `1d` (one day) to another `1d` produces `2d` (two days). !!! note This function also supports negative intervals. For example, `1d + -1h` results in `23h`, following standard arithmetic rules where adding a negative is equivalent to subtraction. - [addTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/addtime.md): Returns a new timestamp by adding an interval to an existing timestamp. Both `timestamp` and `interval` are first-class types in DataPrime, so ensure that the correct types are passed. !!! note Negative intervals are supported and act as subtraction. For example, adding `-1h` to a timestamp subtracts one hour. - [diffTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/difftime.md): Returns the duration between two timestamps as an interval. The result is not the absolute difference: * Positive if `to > from` * Negative if `to < from` - [extractTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/extracttime.md): Returns a specific unit of time extracted from a timestamp, such as the hour, minute, or second. !!! note * Date units such as `'month'` or `'week'` start from **1**, not 0. * Units smaller than `minute` return floating-point numbers; all others return integers. - [formatInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/formatinterval.md): Returns an interval rendered as a string, with optional control over which time unit is displayed. - [formatTimestamp](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/formattimestamp.md): Returns a timestamp formatted as a string, with optional control over the output format and time zone. - [fromUnixTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/fromunixtime.md): Returns a parsed timestamp from a numeric Unix time value. The Unix epoch starts on January 1, 1970. Timestamps before this are represented by negative numbers. - [multiplyInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/multiplyinterval.md): Returns an interval multiplied by a numeric factor, allowing extrapolation over time. !!! note Both integer and decimal factors are supported. - [now](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/now.md): Returns the current time as a timestamp at query execution. * Produces nanosecond precision if supported by the runtime, otherwise falls back to milliseconds. * Always returns the same value across multiple invocations within the same query. - [parseInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/parseinterval.md): Returns an interval parsed from a string representation such as `2d` or `35m10s`, enabling calculations with durations. A valid string must follow these rules: * Format: `NdNhNmNsNmsNusNns` where `N` is a non-negative integer * At least one time unit must be present * No unit may appear more than once (`1d2d` is invalid) * Units must appear in descending order (days → nanoseconds). `1d1s` is valid; `1s1d` is not * A leading `-` is allowed to indicate a negative interval (the only valid position for `-`) * If the format is invalid, the function returns `null` - [parseTimestamp](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/parsetimestamp.md): Returns a parsed timestamp from a date or time string, enabling use of DataPrime's time functions. !!! note If the string cannot be parsed (for example, if it does not match the expected format), the function returns `null`. - [parseToTimestamp](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/parsetotimestamp.md): Returns a timestamp parsed from a date/time string with an optional format specification and time zone override. See [`parseTimestamp`](./parsetimestamp.md) for details. - [roundInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/roundinterval.md): Returns an interval rounded down to a specified precision. All time units smaller than the specified `timeunit` are zeroed out. - [roundTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/roundtime.md): Returns a timestamp rounded down to the nearest interval. !!! note Functionally equivalent to dividing a timestamp by an interval: `timestamp / interval`. - [subtractInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/subtractinterval.md): Returns the result of subtracting one interval from another. !!! note Equivalent to `addInterval(left, -right)` or `left - right`. - [subtractTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/subtracttime.md): Returns a timestamp reduced by a given interval. !!! note Equivalent to `addTime(t, -i)` or `t - i`, where `t` is a timestamp and `i` is an interval. - [timeRound](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/timeround.md): Returns a timestamp rounded down to a specified interval. This function is deprecated in favor of `roundTime`. - [Specifying timestamp formats](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/timestamp_formats.md): The DataPrime functions parseTimestamp and formatTimestamp accept a format argument that can be used to specify the format for parsing, respectively printing a timestamp to a string. The syntax is based on the strftime function from programming languages such as Python, C or Rust. It can be any valid string with embedded format specifiers as detailed in the table below. Other parts of the string which are not format specifiers are reproduced verbatim. - [toInterval](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/tointerval.md): Returns an interval created from a numeric value and an optional time unit. This function works with integers, decimals, positive, and negative values. - [toIso8601DateTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/toiso8601datetime.md): Returns a timestamp formatted as an ISO 8601 string (e.g. `2023-08-11T07:29:17.634Z`). This function supports nanosecond precision. - [toTimeUnit](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/totimeunit.md): Returns an interval converted to a numeric value in the requested time unit. Use `toTimeUnit` when you need an interval as a plain number — for example, to report a duration in seconds, plot it on a numeric chart, or compare it against a numeric threshold. - [toUnixTime](https://coralogix.com/docs/dataprime/language-reference/functions-reference/time/tounixtime.md): Returns the number of time units since the Unix epoch (`1970-01-01T00:00:00Z`) for a given timestamp. !!! note Timestamps before the epoch are represented as negative numbers. - [urlDecode](https://coralogix.com/docs/dataprime/language-reference/functions-reference/url/urldecode.md): Returns the decoded version of a URL-encoded string. URL encoding replaces certain characters with escape sequences (for example, spaces become `%20`) so they can be safely transmitted in URLs. Use `urlDecode` to restore the original values after parsing. - [urlEncode](https://coralogix.com/docs/dataprime/language-reference/functions-reference/url/urlencode.md): Returns the URL-encoded version of a string. URL encoding replaces special characters with escape sequences (for example, spaces become `%20`) so values can be safely transmitted in URLs. Use `urlEncode` when preparing data for output, such as with log forwarders. - [uuid](https://coralogix.com/docs/dataprime/language-reference/functions-reference/uuid.md): Returns a randomly generated UUID, useful for assigning identifiers to documents. - [isUuid](https://coralogix.com/docs/dataprime/language-reference/functions-reference/uuid/isuuid.md): Returns `true` if a given string is a valid UUID, otherwise returns `false`. Use `isUuid` to clean data or flag malformed identifiers in logs and datasets. - [randomUuid](https://coralogix.com/docs/dataprime/language-reference/functions-reference/uuid/randomuuid.md): Returns a randomly generated UUIDv4, useful for assigning identifiers to documents. - [Limitations](https://coralogix.com/docs/dataprime/language-reference/limitations.md): Limitations of the DataPrime language - [DataPrime Types](https://coralogix.com/docs/dataprime/language-reference/types.md): | Type | Description | Encoding | - [User guide](https://coralogix.com/docs/dataprime/user-guide.md): Welcome to the DataPrime User Guide. This guide helps you learn how to query and transform observability data using DataPrime, the Coralogix query language. - [DataPrime expression language (DPXL)](https://coralogix.com/docs/dataprime/user-guide/dpxl.md): DataPrime Expression Language, or DPXL, is an expression language based on DataPrime expression syntax. Leverage it across the Coralogix platform to define rich expression-based filters. - [Foundations](https://coralogix.com/docs/dataprime/user-guide/foundations.md): Welcome to the Foundations section of the DataPrime User Guide. This section covers the building blocks of DataPrime, enabling you to understand how data is structured and how the DataPrime query language works. It sets the stage for using DataPrime effectively by grounding you in its core syntax, commands, and concepts. By the end of this section, you’ll have the knowledge you need to start composing queries with confidence. - [Data access mechanisms](https://coralogix.com/docs/dataprime/user-guide/foundations/access-mechanisms.md): Goal - [DataPrime foundations](https://coralogix.com/docs/dataprime/user-guide/foundations/getting-oriented.md): Understanding what DataPrime is and where it fits into the Coralogix platform helps you make the most of its powerful querying capabilities. Whether you're exploring logs, building dashboards, or writing advanced queries, getting oriented with DataPrime is the first step toward unlocking unified observability across your telemetry data. - [Making a query](https://coralogix.com/docs/dataprime/user-guide/foundations/making-a-query.md): Goal - [Using DataPrime to troubleshoot common query issues](https://coralogix.com/docs/dataprime/user-guide/foundations/troubleshooting.md): Common issues and fixes - [Understanding commands](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-commands.md): Goal - [Understanding expressions](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-expressions.md): Goal - [Understanding functions](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-functions.md): Goal - [Understanding logs](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-logs.md): Goal - [Understanding spans](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-spans.md): Goal - [Understanding types](https://coralogix.com/docs/dataprime/user-guide/foundations/understanding-types.md): Goal - [Using DataPrime](https://coralogix.com/docs/dataprime/user-guide/using-dataprime.md): Now that you’ve learned the core building blocks of the DataPrime language— how data is structured, how commands and functions work, and how to run a query— you’re ready to start solving real problems. - [Aggregating data](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/aggregation.md): Goal - [Using arrays, strings, and complex structures with DataPrime](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/arrays.md): Goal - [How to use DataPrime to build conditional logic into your queries](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/conditional-logic.md): Goal - [Using DataPrime to enrich and reshape data](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/enriching-data.md): Goal - [Using DataPrime to isolate and shape logs for deeper analysis](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/isolate-and-shape.md): Goal - [How to use DataPrime to combine datasets and correlate logs](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/join_union.md): Goal - [Using DataPrime to clean and normalize data with functions](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/normalize_data.md): Goal - [How to use DataPrime to detect patterns and anomalies in your data](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/patterns.md): Goal - [Using DataPrime to track time and durations](https://coralogix.com/docs/dataprime/user-guide/using-dataprime/time.md): Goal ### Integrations Explore Coralogix integrations and quick-start tools to get up and running fast with customizable parsing rules, dashboards, alerts, and more. - [Integrations and quick-start extensions](https://coralogix.com/docs/integrations.md): Explore Coralogix integrations and quick-start tools to get up and running fast with customizable parsing rules, dashboards, alerts, and more. - [Anthropic](https://coralogix.com/docs/integrations/ai-observability/anthropic.md): Through integrations with the Anthropic Python SDK, Coralogix delivers end-to-end visibility into AI workloads, supporting proactive issue detection and efficient performance tuning. - [Amazon bedrock](https://coralogix.com/docs/integrations/ai-observability/bedrock.md): Through integrations with Bedrock, Coralogix delivers end-to-end visibility into AI workloads, supporting proactive issue detection and efficient performance tuning. - [Claude Code integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/claude-code.md): Connect Claude Code to Coralogix to stream token usage, costs, tool calls, code changes, and session activity using built-in OpenTelemetry support. - [Claude Cowork integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/claude-cowork.md): Connect Claude Cowork to Coralogix to stream session activity, token usage, cost estimates, and tool calls as OpenTelemetry telemetry — set up entirely from the Claude admin panel. - [Claude integrations with Coralogix](https://coralogix.com/docs/integrations/ai-observability/claude.md): Connect Claude Code and Claude Cowork to Coralogix for unified observability across Claude agents. - [Codex CLI integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/codex-cli.md): Connect Codex CLI to Coralogix to stream API requests, tool calls, and session traces using built-in OpenTelemetry support. - [Cursor integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/cursor.md): Connect Cursor to Coralogix to stream agent session traces, tool usage, code changes, and session activity. - [Gemini](https://coralogix.com/docs/integrations/ai-observability/gemini.md): Through a dedicated integration with the Gemini SDK, Coralogix delivers a unified view of calls across various LLM providers, enabling teams to track performance, costs, and errors in a single place. - [GitHub app for AI discovery](https://coralogix.com/docs/integrations/ai-observability/github-app-for-ai-discovery.md): Connect the Coralogix GitHub app for AI discovery to scan your repositories for AI-related projects, the models they use, and the applications Coralogix monitors. - [GitHub Copilot integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/github-copilot-usage.md): Observe GitHub Copilot in Coralogix: managed daily usage and billing metrics from the GitHub App, plus live per-session telemetry from the built-in OpenTelemetry in Copilot CLI. - [Google ADK](https://coralogix.com/docs/integrations/ai-observability/google-adk.md): Through a dedicated integration with Google ADK (Agent Development Kit), Coralogix delivers full observability into your agent workflows, enabling teams to trace, debug, and optimize AI-powered applications built with Gemini. - [LangChain](https://coralogix.com/docs/integrations/ai-observability/langchain.md): Through a dedicated integration with the LangChain SDK, Coralogix delivers a unified view of calls across various LLM providers, enabling teams to track performance, costs, and errors in a single place. - [LangGraph](https://coralogix.com/docs/integrations/ai-observability/langgraph.md): OpenTelemetry instrumentation for LangGraph is designed to trace graph node executions and simplify the debugging of stateful, multi-step LLM workflows. - [LiteLLM](https://coralogix.com/docs/integrations/ai-observability/litellm.md): Through a dedicated integration with the LiteLLM SDK, Coralogix delivers a unified view of calls across various LLM providers, enabling teams to track performance, costs, and errors in a single place. - [Mastra](https://coralogix.com/docs/integrations/ai-observability/mastra.md): Export OpenTelemetry GenAI spans from Mastra to Coralogix for full visibility into agent runs, model generations, and tool calls. - [Microsoft Foundry](https://coralogix.com/docs/integrations/ai-observability/microsoft-foundry.md): Through integrations with the Azure AI Projects Python SDK (Microsoft Foundry), Coralogix delivers end-to-end visibility into AI workloads, supporting proactive issue detection and efficient performance tuning. - [OpenAI agents SDK](https://coralogix.com/docs/integrations/ai-observability/open-ai-agents-sdk.md): Learn how to set up and configure the OpenAI SDK for AI Observability in Coralogix. - [OpenAI](https://coralogix.com/docs/integrations/ai-observability/openai.md): Through integrations with OpenAI, Coralogix delivers end-to-end visibility into AI workloads, supporting proactive issue detection and efficient performance tuning. - [OpenClaw integration with Coralogix](https://coralogix.com/docs/integrations/ai-observability/openclaw.md): Connect OpenClaw to Coralogix to stream gateway sessions, token usage, costs, model runs, message flow, and webhook activity using built-in OpenTelemetry support. - [Strands agents](https://coralogix.com/docs/integrations/ai-observability/strands.md): Through a dedicated integration with the Strands Agents SDK, Coralogix enriches built-in OpenTelemetry traces with GenAI semantic conventions, giving teams full visibility into agent behavior, tool usage, and model outputs. - [AWS CloudWatch metric streams with Amazon Data Firehose](https://coralogix.com/docs/integrations/aws/amazon-data-firehose/aws-cloudwatch-metric-streams-with-amazon-data-firehose.md): Utilize any of our setup options for Amazon Data Firehose and CloudWatch metric streams to seamlessly stream your CloudWatch metrics into Coralogix. Process and analyze the metrics for enhanced monitoring and deeper insights. - [Extensions](https://coralogix.com/docs/integrations/aws/amazon-data-firehose/extensions.md): Coralogix offers a variety of out-of-the-box data extensions to complement the CloudWatch Metrics via Firehose integration package. - [Send logs using Amazon Data Firehose](https://coralogix.com/docs/integrations/aws/amazon-data-firehose/send-logs-using-amazon-data-firehose.md): Amazon Data Firehose delivers real-time streaming data to destinations like Amazon Simple Storage Service (Amazon S3), Amazon Redshift, or Amazon OpenSearch Service (successor to Amazon Elasticsearch Service), and now supports delivering streaming data to Coralogix. There is no limit on the number of delivery streams, so it can be used for retrieving data from multiple AWS services. Coralogix is an AWS Partner Network (APN) Advanced Technology Partner with AWS  Competencies in DevOps. The platform enables you to easily explore and analyze logs to gain deeper insights into the state of your applications and AWS infrastructure. Analyze all of your AWS service logs while storing only those you need. Generate metrics from aggregated logs to uncover and alert on trends in your AWS services. - [AWS EKS Fargate logs](https://coralogix.com/docs/integrations/aws/amazon-eks-fargate-logs.md): Seamleslly collect and send your EKS Fargate cluster logs straight to Coralogix. - [APM using AWS EC2](https://coralogix.com/docs/integrations/aws/apm-amazon-ec2.md): Using Amazon Data Firehose, you can now send metrics to Coralogix from Amazon Elastic Compute Cloud (Amazon EC2) and view them on your Coralogix dashboard using our application performance monitoring features. - [AWS CloudFormation logs](https://coralogix.com/docs/integrations/aws/aws-cloudformation-logs.md): Send your logs to Coralogix using AWS CloudFormation, granting you observability into your CloudFormation events. The following tutorial demonstrates how to configure an AWS CloudFormation template using a Lambda function to send your telemetry data to Coralogix. - [AWS CloudFront logs](https://coralogix.com/docs/integrations/aws/aws-cloudfront-logs.md): Enable logging from your Amazon CloudFront distribution to seamlessly send web access logs to Coralogix using the AWS CloudFront Logs via Firehose integration package. - [AWS CloudTrail Terraform module](https://coralogix.com/docs/integrations/aws/aws-cloudtrail-terraform-module.md): Using Coralogix Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code. This tutorial demonstrates how to install our CloudTrail collection Lambda. - [AWS CloudTrail](https://coralogix.com/docs/integrations/aws/aws-cloudtrail.md): Coralogix provides a predefined Lambda function to forward your CloudTrail logs straight to the Coralogix platform using our app in the Serverless Application Repository. - [AWS CloudWatch: data collection options](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/aws-cloudwatch-data-collection-options.md): Amazon CloudWatch collects and visualizes real-time logs, metrics, and event data in automated dashboards to streamline your infrastructure and application maintenance. Send these to Coralogix to enhance your data management, analysis, and monitoring capabilities. Coralogix provides multiple methods to collect logs and metrics from Amazon CloudWatch. - [AWS CloudWatch metrics processing](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/aws-cloudwatch-metrics-processing.md): Amazon CloudWatch monitors your Amazon Web Services (AWS) resources and applications you run on AWS in real time. Use the Coralogix destination to easily forward metrics for your AWS resources to Coralogix using CloudWatch Metric Stream and Firehose Delivery Stream. - [AWS CloudWatch metrics](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/aws-metrics-via-cloudwatch.md): The Coralogix AWS Metrics integration offers a simple and easy way to ingest AWS metrics into Coralogix. It’s a cost-efficient alternative Amazon Firehose. In addition, it accepts S3 metrics with 24-hour frequency that can’t be collected via Firehose/CloudWatch metrics streams. - [ECS enhanced monitoring for CloudWatch metrics](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/ecs-enhanced-monitoring.md): Coralogix offers ECS enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon ECS API to collect tags and additional metrics. - [ElastiCache enhanced monitoring for CloudWatch metrics](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/elasticache-enhanced-monitoring.md): Coralogix offers ElastiCache enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon ElastiCache API to collect tags and additional metrics. - [RDS enhanced monitoring for CloudWatch metrics](https://coralogix.com/docs/integrations/aws/aws-cloudwatch/rds-enhanced-monitoring.md): Coralogix offers RDS enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon RDS API to collect tags and additional metrics. - [AWS CloudTrail log collection via SNS trigger](https://coralogix.com/docs/integrations/aws/aws-coudtrail-log-collection-via-sns-trigger.md): Coralogix provides a predefined Lambda function to easily forward your CloudTrail logs through SNS to the Coralogix platform. For easy setup, use our app in the AWS serverless application repository. - [AWS EKS Fargate](https://coralogix.com/docs/integrations/aws/aws-eks-fargate.md): Integrate Coralogix seamlessly with Amazon EKS on AWS Fargate to effortlessly collect, analyze, and visualize logs, metrics, and traces from your containerized applications, empowering you with comprehensive full-stack monitoring and insights. - [AWS Elastic Beanstalk](https://coralogix.com/docs/integrations/aws/aws-elastic-beanstalk.md): This tutorial demonstrates how to instrument a Java application running on the Tomcat platform within an Elastic Beanstalk environment. - [AWS EventBridge](https://coralogix.com/docs/integrations/aws/aws-eventbridge.md): Amazon EventBridge is a serverless event bus service that makes it easy to collect and send data from across your applications and services to any destination. Use EventBridge to seamlessly deliver real-time data from your application to Coralogix for monitoring and analysis. - [AWS Infrastructure Explorer](https://coralogix.com/docs/integrations/aws/aws-infrastructure-explorer.md): Connect your AWS account to Coralogix to collect metadata for EC2 instances and network interfaces, and enrich logs, metrics, and traces with cloud context in Infrastructure Explorer. - [AWS inspector](https://coralogix.com/docs/integrations/aws/aws-inspector.md): The following tutorial demonstrates how to successfully integrate AWS Inspector with Coralogix by using AWS Event Bridge API destinations. - [AWS Kinesis with Logstash](https://coralogix.com/docs/integrations/aws/aws-kinesis-with-logstash.md): Coralogix provides integration to connect Logstash to AWS Kinesis , so you can send your logs from anywhere into Coralogix. - [AWS Lambda telemetry exporter](https://coralogix.com/docs/integrations/aws/aws-lambda-telemetry-exporter.md): This tutorial demonstrates how to set up and install the Coralogix AWS Lambda Telemetry Exporter - an AWS Lambda extension that uses AWS Lambda Telemetry API to seamlessly collect Lambda function logs, as well as Lambda platform logs, metrics, and traces. - [AWS load balancer](https://coralogix.com/docs/integrations/aws/aws-load-balancer.md): This tutorial demonstrates how to collect your AWS Elastic Load Balancers, Application Load Balancers, and Network Load Balancers using Elastic Load Balancing. The data, decrypted and retaining original timestamps, is sent to Coralogix. The process is installation-free and entails simply deploying a Lambda function. - [AWS MSK & Kafka](https://coralogix.com/docs/integrations/aws/aws-msk-and-kafka.md): Coralogix’s Kafka lambdas provide an easy way to send Kafka topics’ data to Coralogix. The preferred integration method is to use our AWS Serverless Application Repository. - [Cross-region configuration](https://coralogix.com/docs/integrations/aws/aws-privatelink/aws-privatelink-cross-region-connection.md): This tutorial provides step-by-step guidance on configuring AWS PrivateLink cross-region connectivity. - [Lambda configuration](https://coralogix.com/docs/integrations/aws/aws-privatelink/aws-privatelink-lambda-configuration.md): This tutorial provides step-by-step guidance on configuring AWS PrivateLink Lambda connectivity. - [VPC peering for PrivateLink (legacy)](https://coralogix.com/docs/integrations/aws/aws-privatelink/aws-privatelink-vpc-peering-configuration.md): This tutorial provides step-by-step guidance on configuring AWS PrivateLink VPC peering connectivity. - [AWS PrivateLink](https://coralogix.com/docs/integrations/aws/aws-privatelink/aws-privatelink.md): AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported AWS services, and your on-premises networks without exposing your traffic to the public internet. Interface VPC endpoints, powered by PrivateLink, connect you to services hosted by Coralogix. This tutorial provides AWS Coralogix PrivateLink endpoints, as well as instructions for local and cross-region setup. - [Endpoints and deployment](https://coralogix.com/docs/integrations/aws/aws-privatelink/endpoints-deployment.md): Use this page as a reference when configuring or validating Coralogix PrivateLink connectivity. Configuration instructions are covered in the PrivateLink guides. - [Same-region configuration](https://coralogix.com/docs/integrations/aws/aws-privatelink/same-region-connectivity.md): This tutorial provides step-by-step guidance on configuring AWS PrivateLink same-region connectivity. - [AWS resource metadata collection Terraform module](https://coralogix.com/docs/integrations/aws/aws-resource-metadata-collection-terraform-module.md): Use Coralogix Terraform modules to install and manage AWS service integrations with Coralogix as modules in your infrastructure code. This guide shows you how to install our Resource Metadata Collection Lambda. - [AWS resource metadata collection](https://coralogix.com/docs/integrations/aws/aws-resource-metadata-collection.md): Deploy the Coralogix-Resource-Metadata AWS Lambda function in your AWS account. The function collects metadata of EC2 instances and AWS Lambda functions in the region of your AWS account and sends them to Coralogix. - [AWS secrets manager Lambda layer](https://coralogix.com/docs/integrations/aws/aws-secrets-manager-lambda-layer.md): Deploy the AWS Secrets Manager Lambda layer to be used in any of our AWS integrations. Doing so ensures the security of your ApiKey, which is presented in the Lambda as a secret rather than an environment variable. - [AWS Terraform module](https://coralogix.com/docs/integrations/aws/aws-terraform-module.md): Terraform simplifies the way we deploy our infrastructure and allows us to maintain it as code.Using our Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code.Our modules are open source and available on our Github and in the Terraform Registry. - [AWS VPC flow logs Terraform module](https://coralogix.com/docs/integrations/aws/aws-vpc-flow-logs-terraform-module.md): Using Coralogix Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code. This tutorial demonstrates how to install the VPC Flow Logs collection Lambda. - [AWS VPC flow logs](https://coralogix.com/docs/integrations/aws/aws-vpc-flow-logs.md): The legacy Coralogix-VPC-Flog-Logs-S3 SAR app is deprecated. For new deployments, use the unified Coralogix AWS Shipper, which supports VPC flow logs via S3 with the IntegrationType parameter. The parameter set differs from the legacy app described below; see the coralogix-aws-shipper repository for the current reference. These instructions will be migrated in a follow-up. - [Cloud Accounts](https://coralogix.com/docs/integrations/aws/cloud-accounts.md): Connect a cloud provider account to Coralogix with Cloud Accounts, discover its resources, and deploy metrics monitoring per service and region. - [OpenTelemetry ECS fargate](https://coralogix.com/docs/integrations/aws/opentelemetry-ecs-fargate.md): Seamlessly stream logs, metrics, and traces generated by AWS ECS Fargate containers to Coralogix for optimal monitoring, analysis, and visualization. - [Microsoft Azure activity and Audit logs with Filebeat](https://coralogix.com/docs/integrations/azure/azure-activity-and-audit-logs-with-filebeat.md): For us to be able to get audit logs from Azure, we are going to use the FileBeat Module. - [Azure activity logs](https://coralogix.com/docs/integrations/azure/azure-activity-logs.md): Collect Azure Activity logs and submit them to Coralogix for seamless integration. - [Azure Blob Storage via Event Grid Terraform module](https://coralogix.com/docs/integrations/azure/azure-blob-storage-via-event-grid-terraform-module.md): Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install the Coralogix function app, allowing you to connect your Blob Storage container and send logs to Coralogix. - [Azure Blob Storage to OTel Terraform module](https://coralogix.com/docs/integrations/azure/azure-blob-to-otel-terraform-module.md): Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install the Coralogix function app, allowing you to connect your Blob Storage container and send logs to OTel Endpoint. - [Azure diagnostic data Terraform module](https://coralogix.com/docs/integrations/azure/azure-diagnostic-data-terraform-module.md): Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app, which processes logs and metrics that are forwarded through diagnostic settings to an Event Hub and are then transmitted to Coralogix. - [Azure Event Hub Terraform module](https://coralogix.com/docs/integrations/azure/azure-event-hub-terraform-module.md): Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app that connects to your Event Hub and sends logs to Coralogix. - [Azure Infrastructure Explorer](https://coralogix.com/docs/integrations/azure/azure-infrastructure-explorer.md): Connect your Azure tenant to Coralogix to collect metadata for Azure Virtual Machines and Virtual Machine Scale Set instances, and enrich logs and traces with resource context. - [Azure metrics](https://coralogix.com/docs/integrations/azure/azure-metrics.md): Collect metrics from your Azure subscriptions using the Azure Monitor REST API and route them to Coralogix for dashboards, alerts, and Infrastructure Explorer correlation. - [Azure platform monitoring](https://coralogix.com/docs/integrations/azure/azure-platform-monitoring.md): Microsoft Azure platform monitoring focuses on capturing platform logs - Microsoft Entra ID, Activity, and Resource logs - from various components within your environment. - [Azure Queue Storage Terraform module](https://coralogix.com/docs/integrations/azure/azure-queue-storage-terraform-module.md): Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app that connects to your storage queue and sends logs to Coralogix. - [Azure resource logs](https://coralogix.com/docs/integrations/azure/azure-resource-logs.md): Collect Azure Resource logs and send them to Coralogix for seamless integration. - [Azure Resource Manager (ARM) integration packages](https://coralogix.com/docs/integrations/azure/azure-resource-manager-integration-packages.md): Access our Azure Resources Integration Packages to automatically deploy our various Microsoft Azure integrations. Extend your platform capabilities with packages and sources, without expending unnecessary time and resources. Gain insights into role, user, group and directory management, successful and failed sign-in events, and application management data that helps you understand your users’ experience and immediately troubleshoot any errors. - [Blob Storage via Event Grid: Microsoft Azure Resource Manager (ARM)](https://coralogix.com/docs/integrations/azure/blob-storage-via-event-grid-microsoft-azure-resource-manager.md): Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs. The Azure Blob Storage via EventGrid integration allows parsing of Azure Blobs, triggered by an EventGrid subscription notification. - [Blob Storage to OTel: Microsoft Azure Resource Manager (ARM)](https://coralogix.com/docs/integrations/azure/blob-to-otel-microsoft-azure-resource-manager.md): Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs. The Azure Blob Storage To OTel integration allows parsing of Azure Blobs, triggered by an EventHub subscription, and sending the data to OTel endpoint. - [Diagnostic data: Microsoft Azure Resource Manager (ARM)](https://coralogix.com/docs/integrations/azure/diagnostic-data-microsoft-azure-resource-manager.md): Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs.The Azure Diagnostic Data integration allows processing of logs and metrics submitted to an Event Hub using the resource diagnostic settings configuration. - [Event Hub: Microsoft Azure Resource Manager (ARM)](https://coralogix.com/docs/integrations/azure/event-hub-microsoft-azure-resource-manager.md): Coralogix provides seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs. - [Introduction to Microsoft Azure](https://coralogix.com/docs/integrations/azure/introduction-to-microsoft-azure.md): The Coralogix Azure integrations enable the collection of logs and metrics from your Azure environment. Gain insights into role, user, group and directory management, successful and failed sign-in events, and application management data that helps you understand your users' experience and immediately troubleshoot any errors. - [Microsoft Azure API rate limits](https://coralogix.com/docs/integrations/azure/microsoft-azure-api-rate-limits.md): Monitor Azure ARM API rate limits to track remaining request quota and avoid throttling. The integration collects remaining read and write request counts at subscription, global, and tenant scopes. - [Microsoft Azure compute scale and quotas](https://coralogix.com/docs/integrations/azure/microsoft-azure-compute-scale-and-quotas.md): Azure Virtual Network is the fundamental building block for your Azure-based private network. The service enables many types of Azure VMs to securely communicate with each other, the internet, and on-site networks. You can use the Virtual Network statistics to create metrics and send them to Coralogix. - [Microsoft Azure Functions](https://coralogix.com/docs/integrations/azure/microsoft-azure-functions.md): Coralogix provides a seamless integration with Microsoft Azure Cloud, so you can send your logs from anywhere and parse them according to your needs. We provide several trigger strategies with any of the following automatic integrations using Azure custom template deployments: Event Hub, Blob Storage, and Queue Storage. - [Microsoft Azure Service Bus](https://coralogix.com/docs/integrations/azure/microsoft-azure-service-bus.md): Microsoft Azure Service Bus is a cloud-based messaging service that connects any applications, devices, and services running in the cloud to any other applications or services. You can use the Service Bus statistics to create metrics and send them to Coralogix. - [Microsoft Azure SQL Server metrics](https://coralogix.com/docs/integrations/azure/microsoft-azure-sql-server-metrics.md): Azure SQL Database provides geo-replication for disaster recovery and high availability. You can use the SQL Server metrics to monitor replication link states and send them to Coralogix. - [Microsoft Azure status logs](https://coralogix.com/docs/integrations/azure/microsoft-azure-status-logs.md): Forwarding your Azure status logs to Coralogix simplifies log consolidation, enhances monitoring capabilities, and streamlines issue resolution. By directing Azure status logs to Coralogix, you gain a unified perspective on your Azure infrastructure's status, enabling swift identification of irregularities, proactive problem-solving, and informed decision-making. This integration empowers teams to optimize resource allocation, bolster system dependability, and uphold operational efficiency, utilizing Coralogix's analytical, alerts, and visualization features to extract actionable insights from Azure status logs and ensure a resilient cloud environment. - [Microsoft Azure Virtual Network](https://coralogix.com/docs/integrations/azure/microsoft-azure-virtual-network.md): Azure Virtual Network is the fundamental building block for your Azure-based private network. The service enables many types of Azure VMs to securely communicate with each other, the internet, and on-site networks. You can use the Virtual Network statistics to create metrics and send them to Coralogix. - [Microsoft Entra ID logs](https://coralogix.com/docs/integrations/azure/microsoft-entra-id-logs.md): Collect Microsoft Entra ID (previously Azure Active Directory) audit, sign-in, and provisioning logs, and submit them to Coralogix for seamless integration. - [Optional configurations: Microsoft Azure](https://coralogix.com/docs/integrations/azure/optional-configurations-microsoft-azure.md): Coralogix offers optional configurations for particular use-cases utilizing our Azure deployments. - [Queue Storage: Microsoft Azure Resource Manager (ARM)](https://coralogix.com/docs/integrations/azure/queue-storage-microsoft-azure-resource-manager.md): Coralogix provides seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs.Deploy the Azure Queue Storage integration to send Coralogix your JSON-formatted queue messages using the ARM template below. - [Akamai](https://coralogix.com/docs/integrations/cdns/akamai-datastream.md): The following tutorial demonstrates how to collect your Akamai DataStream logs and send them to Coralogix. Once ingested by our platform, query, archive, define alerts, and create dashboards with your data. - [Cloudflare](https://coralogix.com/docs/integrations/cdns/cloudflare.md): Cloudflare Enterprise customers have access to Logpush service which allows you to forward logs to cloud service providers like AWS. In this tutorial, you will find all steps to send logs to Coralogix via your S3 bucket. - [Cloudflare Logpush Terraform module](https://coralogix.com/docs/integrations/cdns/cloudflare/cloudflare-logpush-terraform-module.md): Terraform simplifies the way we deploy our infrastructure and allows us to maintain it as code. - [Fastly logs via HTTPS streaming](https://coralogix.com/docs/integrations/cdns/fastly-logs-via-https-streaming.md): Fastly's real-time log streaming feature provides the ability to send Fastly logs to any HTTPS endpoint. - [CircleCI](https://coralogix.com/docs/integrations/ci/cd/circleci.md): Integrate your CircleCI workflows and jobs pipeline with Coralogix to automatically receive reports and analyze version upgrades for their impact on the overall quality of your production system. - [GitHub Actions](https://coralogix.com/docs/integrations/ci/cd/github-actions.md): Monitoring GitHub Actions is critical for understanding what causes delays and failures in your CI/CD pipelines. Coralogix supports sending logs, traces, and metrics from completed actions to the platform by providing its own GitHub Action workflow. - [Jenkins plugin](https://coralogix.com/docs/integrations/ci/cd/jenkins-plugin.md): The Coralogix Jenkins plugin facilitates the transmission of audit, security, and pipeline console logs to Coralogix, while pushing tags to the Coralogix platform. - [Jenkins telemetry](https://coralogix.com/docs/integrations/ci/cd/jenkins-telemetry.md): Monitoring Jenkins telemetry is critical to understanding what is causing delays and failures in your CI/CD pipelines. Coralogix leverages the OpenTelemetry plugin for Jenkins to monitor metrics and traces. Logs and tagging are supported using our Coralogix plugin for Jenkins. - [AWS SNS data ingestion](https://coralogix.com/docs/integrations/contextual-data/aws-sns-data-ingestion.md): Collect your AWS SNS messages in the Coralogix platform using our automatic Contextual Data Integration Package. The package automatically generates a URL to be use when creating an SNS subscription. - [AWS status logs](https://coralogix.com/docs/integrations/contextual-data/aws-status-logs.md): Routing your AWS status logs to Coralogix streamlines log aggregation, augments monitoring efficiency, and expedites problem resolution. By funneling your AWS status logs into Coralogix's log management platform, you attain a consolidated view of your AWS infrastructure's condition, enabling rapid anomaly detection, proactive troubleshooting, and informed decision-making. This integration empowers teams to fine-tune resource allocation, fortify system reliability, and sustain operational effectiveness, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from AWS status logs and ensure a robust and resilient cloud environment. - [Bitbucket data ingestion](https://coralogix.com/docs/integrations/contextual-data/bitbucket-data-ingestion.md): Send your Bitbucket logs to Coralogix to enhance log consolidation, strengthen monitoring capabilities, and streamline issue resolution. By directing Bitbucket logs into Coralogix, you can achieve a comprehensive view of your code repository activities, enabling swift anomaly detection, proactive debugging, and informed decision-making. This integration empowers teams to optimize development workflows, fortify system reliability, and maintain operational effectiveness, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Bitbucket logs and ensure a productive and resilient software development environment. - [GCP status logs](https://coralogix.com/docs/integrations/contextual-data/gcp-status-logs.md): Sending Google Cloud Platform (GCP) status logs to Coralogix facilitates streamlined log aggregation, real-time monitoring, and efficient troubleshooting. By channeling GCP status logs into Coralogix's log management platform, organizations gain a comprehensive view of their cloud infrastructure's health, enabling rapid detection of anomalies, proactive issue resolution, and data-driven decision-making. This integration empowers teams to optimize resource utilization, enhance system reliability, and maintain operational excellence by leveraging Coralogix's analytics and visualization tools to extract valuable insights from GCP status logs. - [GitHub data ingestion](https://coralogix.com/docs/integrations/contextual-data/github-data-ingestion.md): Sending your GitHub logs to Coralogix streamlines log management, augments development monitoring, and enhances issue resolution. By routing GitHub logs into Coralogix, you gain a consolidated view of your code repository activities, enabling rapid anomaly detection, proactive debugging, and data-driven decision-making. This integration empowers development teams to optimize workflows, strengthen system reliability, and sustain operational effectiveness, utilizing Coralogix's analytics, alerts, and visualization tools to extract valuable insights from GitHub logs and ensure a seamless and resilient software development lifecycle. - [GitLab data ingestion](https://coralogix.com/docs/integrations/contextual-data/gitlab-data-ingestion.md): Sending your GitLab logs to Coralogix streamlines log aggregation, strengthens monitoring capabilities, and enhances issue resolution for efficient software development. By directing GitLab logs into Coralogix, you gain a comprehensive view of your version control activities, enabling rapid anomaly detection, proactive debugging, and informed decision-making. This integration empowers development teams to optimize workflows, bolster system reliability, and maintain operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from GitLab logs and ensure a collaborative and resilient software development environment. - [Intercom data ingestion](https://coralogix.com/docs/integrations/contextual-data/intercom-data-ingestion.md): Companies that use Intercom for customer relations can ingest Intercom events in their logs, in order to correlate them with other events in their systems, and then seamlessly send them to Coralogix and take advantage of Coralogix log analytic capabilities, alerts, and top-notch visualization features. - [Opsgenie data ingestion](https://coralogix.com/docs/integrations/contextual-data/opsgenie-data-ingestion.md): Sending your Opsgenie alerts to Coralogix streamlines alert management, enhances monitoring capabilities, and facilitates comprehensive incident analysis. By directing your Opsgenie alerts into Coralogix, you gain a centralized view of your alerting activities, enabling rapid incident detection, proactive troubleshooting, and data-driven decision-making. This integration empowers teams to optimize response workflows, strengthen system reliability, and ensure operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Opsgenie alerts and ensure a streamlined and resilient incident response process. - [PagerDuty data ingestion](https://coralogix.com/docs/integrations/contextual-data/pagerduty-data-ingestion.md): Forwarding your PagerDuty alerts to Coralogix streamlines alert consolidation, augments monitoring capabilities, and expedites incident resolution. By routing your PagerDuty alerts into Coralogix, you achieve a unified view of your alerting and incident management activities, enabling swift anomaly detection, proactive troubleshooting, and informed decision-making. This integration empowers teams to optimize incident response workflows, enhance system reliability, and sustain operational effectiveness, utilizing Coralogix's analytics, alerts, and visualization tools to extract valuable insights from PagerDuty alerts and ensure an efficient and resilient incident management process. - [Slack data ingestion](https://coralogix.com/docs/integrations/contextual-data/slack-data-ingestion.md): Log the activity on your Slack channels and send it to Coralogix with the Coralogix application. - [StatusPage data ingestion](https://coralogix.com/docs/integrations/contextual-data/statuspage-data-ingestion.md): Sending the Statuspage feed to Coralogix facilitates centralized incident monitoring, analysis, and streamlined communication. By directing Statuspage updates into Coralogix's log management platform, organizations can consolidate incident-related information, gain insights into the impact of service disruptions, and correlate these events with other operational data. This integration empowers teams to enhance incident response, analyze patterns, and improve communication by leveraging Coralogix's log analysis and visualization tools to extract valuable insights from Statuspage feeds, ultimately leading to improved service reliability, customer satisfaction, and operational resilience. - [Coralogix endpoints](https://coralogix.com/docs/integrations/coralogix-endpoints.md): Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This document provides generally available endpoints. - [OpenTelemetry custom logs](https://coralogix.com/docs/integrations/data-ingestion/opentelemetry-custom-logs.md): Send your custom logs to Coralogix using our OpenTelemetry-compatible endpoint. - [OpenTelemetry custom metrics](https://coralogix.com/docs/integrations/data-ingestion/opentelemetry-custom-metrics.md): Coralogix provides a scalable Prometheus-compatible managed service for time-series data. Employ our custom metric endpoint, including serverless computing and quick cURL-like calls, to send counters, gauges, and histograms to Coralogix. - [OpenTelemetry custom traces](https://coralogix.com/docs/integrations/data-ingestion/opentelemetry-custom-traces.md): Send your custom traces to Coralogix using our OpenTelemetry-compatible endpoint. - [GELF](https://coralogix.com/docs/integrations/docker/gelf.md): Coralogix will permanently disable native GELF ingestion on August 20, 2026. Migrate to a Logstash-based forwarder before the cutoff to avoid data loss. See the GELF and UDP rsyslog deprecation notice for full migration steps. - [Coralogix endpoint updates and deprecations](https://coralogix.com/docs/integrations/endpoint-updates.md): Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This document provides updates regarding endpoint changes and deprecations. - [Static IPs and regional DNS endpoints](https://coralogix.com/docs/integrations/endpoint-updates/ingestion-deprecation.md): Coralogix is migrating to static Elastic IP ranges and standardized regional DNS endpoints. This page lists the new IP allowlists and DNS endpoints by region. - [Upcoming deprecations](https://coralogix.com/docs/integrations/endpoint-updates/upcoming-deprecations.md): Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This page provides updates regarding upcoming endpoint changes and deprecations. - [Quick-start extensions](https://coralogix.com/docs/integrations/extensions.md): Coralogix offers a variety of out-of-the-box data extensions. Each tailored extension unlocks a set of predefined items - alerts, parsing rules, dashboards, saved views, actions, and more - allowing you to jumpstart Coralogix monitoring of your external-facing resources. - [Filebeat](https://coralogix.com/docs/integrations/files/beats-filebeat.md): This integration is maintained for legacy support and is not recommended for new use cases. We recommend using OpenTelemetry (OTel) for a more modern, flexible, and industry-standard observability solution. - [CockroachDB](https://coralogix.com/docs/integrations/files/cockroachdb.md): This guide demonstrates the process of integrating Coralogix with a self-managed CockroachDB instance from Cockroach Labs. Initially, we will set up a CockroachDB instance on an EC2 instance, following the outlined steps below. - [Fluent Bit](https://coralogix.com/docs/integrations/files/fluent-bit.md): Coralogix provides seamless integration with Fluent Bit, allowing you to send your logs from anywhere and parse them according to your needs. - [Fluentd](https://coralogix.com/docs/integrations/files/fluentd.md): Coralogix provides seamless integration with Fluentd so you can send your logs from anywhere and parse them according to your needs. - [Logstash](https://coralogix.com/docs/integrations/files/logstash.md): Coralogix provides a seamless integration with Logstash, so you can send your logs from anywhere and parse them according to your needs. - [NXLog](https://coralogix.com/docs/integrations/files/nxlog.md): The following tutorial demonstrates how to configure NXLog to seamlessly send your logs to Coralogix. - [Vector](https://coralogix.com/docs/integrations/files/vector.md): Coralogix provides seamless integration with Vector so you can send your logs from anywhere and parse them according to your needs. - [Windows event logs with Winlogbeat](https://coralogix.com/docs/integrations/files/windows-event-logs-with-winlogbeat.md): Coralogix provides a seamless integration with Winlogbeat to help you send your Windows Event Viewer logs directly to Coralogix and parse them according to your needs. - [GCP - getting started](https://coralogix.com/docs/integrations/gcp/gcp-getting-started.md): Coralogix offers a number of basic integrations with Google Cloud Platform. - [GCP Infrastructure Explorer](https://coralogix.com/docs/integrations/gcp/gcp-infrastructure-explorer.md): Connect a GCP project to Coralogix to collect metadata for Compute Engine, Google Kubernetes Engine (GKE), and Cloud Storage resources for Infrastructure Explorer context. - [GCP log explorer](https://coralogix.com/docs/integrations/gcp/gcp-log-explorer.md): Coralogix offers a number of different approaches for collecting logs from your Google Cloud environments including using GCP Log Explorer and Google Cloud Storage.The tutorial describes how to configure a Logs router to send logs to a Pub/Sub topic and deliver them to Coralogix using a push subscription on the topic. - [GCP logs](https://coralogix.com/docs/integrations/gcp/gcp-logs.md): Google Cloud Platform (GCP) offers integrated monitoring and observability tools that enable users to gather and analyze logs from their GCP resources. Send these GCP logs to Coralogix to search, analyze, and visualize your data. Gain insights into application behavior, identify errors, and troubleshoot problems effectively. - [GCP metrics](https://coralogix.com/docs/integrations/gcp/gcp-metrics.md): Google Cloud Platform provides built-in monitoring and observability tools that allow users to collect and analyze metrics and traces from their GCP resources. Send Google Cloud metrics seamlessly to Coralogix. Search, analyze, and visualize your data, gaining insights into application behavior, identifying errors, and troubleshooting problems. - [GCP pub/sub Terraform module](https://coralogix.com/docs/integrations/gcp/gcp-pub/sub-terraform-module.md): This module will be installing our function app that gets messages from your Pub/Sub topic and sends logs to Coralogix. - [GCP storage](https://coralogix.com/docs/integrations/gcp/gcp-storage.md): Coralogix deprecated the legacy v1 Terraform deployment path on this page for new deployments starting April 7, 2026. For new GCP log-ingestion deployments, use the pull-based GCP Logs integration instead. See the end-of-life notice for details. - [GCP traces](https://coralogix.com/docs/integrations/gcp/gcp-traces.md): Google Cloud Platform provides built-in monitoring and observability tools that allow users to collect and analyze metrics and traces from their GCP resources. Send Google Cloud traces seamlessly to Coralogix. Search, analyze, and visualize your data, gaining insights into application behavior, identifying errors, and troubleshooting problems. - [Google Workspace alert center](https://coralogix.com/docs/integrations/gcp/google-workspace-alert-center.md): Google Workspace Alert Center offers real-time security alerts and insights that help you protect your organization from the latest threats, including phishing, malware, and other suspicious activity. The following tutorial will show you how to integrate Google Workspace Alert Center with Coralogix directly. - [Google Workspace users](https://coralogix.com/docs/integrations/gcp/google-workspace-users.md): This integration will let you collect all user details from your Google Workspace Admin Console along with their metadata. This provides your Coralogix features with additional user details to get better context. - [Google Workspace](https://coralogix.com/docs/integrations/gcp/google-workspace.md): Google Workspace audit logs provide detailed records of user activities, such as logins, file sharing, and administrative actions. These logs help you understand how Google Workspace applications are being used, track changes, and monitor for suspicious behavior, enabling you to maintain a secure and efficient workspace. - [Private Service Connect (PSC) for GCP](https://coralogix.com/docs/integrations/gcp/psc_setup.md): Connect your GCP workloads to Coralogix privately using Google Cloud's Private Service Connect. - [GCP Private Service Connect Terraform module](https://coralogix.com/docs/integrations/gcp/psc-terraform-module.md): Provision consumer-side Google Cloud Private Service Connect resources for private connectivity from GCP to Coralogix using Terraform. - [Getting started](https://coralogix.com/docs/integrations/getting-started.md): Overview - [Coralogix icons 2.0](https://coralogix.com/docs/integrations/icons-cx.md): cx-actions - [Coralogix icons](https://coralogix.com/docs/integrations/icons.md): coralogix-actions - [Generic incoming webhooks](https://coralogix.com/docs/integrations/incoming-webhooks/generic-incoming-webhooks.md): Coralogix offers customers the option of automating the creation of your incoming webhooks to connect your applications to Coralogix. - [UpGuard](https://coralogix.com/docs/integrations/incoming-webhooks/upguard.md): The following tutorial demonstrates how to send your telemetry data to Coralogix using UpGuard. Follow this five-step guide for each notification that you would like to send us. - [Fluent Bit Helm chart for Kubernetes](https://coralogix.com/docs/integrations/kubernetes/fluent-bit-helm-chart-for-kubernetes.md): Use our multi-arch Helm chart to streamline your Kubernetes monitoring by creating a DaemonSet on your Kubernetes cluster using the Helm package manager. - [Coralogix Fluent Bit Helm chart migration to the official Fluent Bit Helm chart](https://coralogix.com/docs/integrations/kubernetes/fluent-bit-helm-chart-migration.md): This guide explains how to migrate from the Coralogix Fluent Bit Helm chart to the official Fluent Bit Helm chart. - [Fluentd Helm chart for Kubernetes](https://coralogix.com/docs/integrations/kubernetes/fluentd-helm-chart-for-kubernetes.md): Here at Coralogix, we love Kubernetes and we love making things simple. To help streamline your Kubernetes monitoring, we created this chart to bootstrap our optimized Fluentd image to create a DaemonSet on your Kubernetes cluster using the Helm Package Manager. - [Kubernetes with Filebeat](https://coralogix.com/docs/integrations/kubernetes/kubernetes-with-filebeat.md): kubernetes versions - [Kubernetes with Fluent Bit (without Helm)](https://coralogix.com/docs/integrations/kubernetes/kubernetes-with-fluent-bit-without-helm.md): kubernetes versions - [Kubernetes with Fluentd (without Helm)](https://coralogix.com/docs/integrations/kubernetes/kubernetes-with-fluentd-without-helm.md): Fluentd is a versatile data shipper with numerous available plugins and functionalities, playing a pivotal role as a logs shipper to our platform. Below are instructions on how to set up the Fluentd shipper along with the http output plugin to transmit logs to the Coralogix platform. - [Collect CloudWatch metrics with Telegraf](https://coralogix.com/docs/integrations/metrics/collect-cloudwatch-metrics-with-telegraf.md): Amazon CloudWatch monitors your Amazon Web Services (AWS) resources and applications you run on AWS in real time. Use the Coralogix destination to easily forward metrics for your AWS resources to Coralogix using Telegraf. - [Custom metrics](https://coralogix.com/docs/integrations/metrics/custom-metrics.md): Coralogix provides a scalable Prometheus-compatible managed service for time-series data. This tutorial presents a series of use cases employing our custom metric endpoint, including serverless computing and quick cURL-like calls to send counters and gauges to Coralogix. - [External labels](https://coralogix.com/docs/integrations/metrics/external-labels.md): New! Send Coralogix your metrics using external labels, maximizing query performance and adding an extra layer of granularity in your data indexing. - [Beats: Metricbeat](https://coralogix.com/docs/integrations/metrics/metricbeat.md): Coralogix provides a seamless integration with Metricbeat so help you send your metric data from anywhere and create metric dashboards. - [MongoDB Atlas](https://coralogix.com/docs/integrations/metrics/mongodb-atlas.md): MongoDB Atlas is is a fully-managed cloud database that handles the complexity of deploying, managing, and healing your deployments on the cloud service provider of your choice.Deploy this integration to send your MongoDB Atlas metrics to you Coralogix account using the OpenTelemetry Collector. - [Nagios](https://coralogix.com/docs/integrations/metrics/nagios.md): This tutorial demonstrates how to send your logs and metrics to Coralogix using Nagios. - [Prometheus](https://coralogix.com/docs/integrations/metrics/prometheus.md): Automatically ship your Prometheus metrics into your Coralogix account and store them without making complex changes to your architecture. - [RabbitMQ metrics](https://coralogix.com/docs/integrations/metrics/rabbitmq-metrics.md): This is a tool to pull Metrics from RabbitMQ Admin UI and send them to Coralogix. It will deploy a lambda function to your AWS Account. - [StatsD](https://coralogix.com/docs/integrations/metrics/statsd.md): StatsD is an open-source standard and, by extension, a toolkit designed for sending, collecting, and aggregating custom metrics from diverse applications. This tutorial demonstrates installing and running StatsD to send your metrics to Coralogix. - [Telegraf operator](https://coralogix.com/docs/integrations/metrics/telegraf-operator.md): This tutorial demonstrates how to run Telegraf Operator in Kubernetes to export your telemetry data to Coralogix. - [Telegraf](https://coralogix.com/docs/integrations/metrics/telegraf.md): This tutorial demonstrates how to send your metrics to Coralogix via Telegraf. - [Zabbix](https://coralogix.com/docs/integrations/metrics/zabbix.md): This tutorial demonstrates how to send your metrics to Coralogix via Zabbix. - [OCI Audit logs](https://coralogix.com/docs/integrations/oci/oci-audit-logs.md): This integration guide focuses on connecting your Oracle Cloud Infrastructure (OCI) environment to Coralogix using OCI Notification Service. - [Heroku integration with Coralogix](https://coralogix.com/docs/integrations/paas-platforms/heroku.md): Coralogix offers multiple integration methods for collecting observability data from Heroku applications. Choose the appropriate method based on your Heroku environment generation and hosting type. - [Heroku logs](https://coralogix.com/docs/integrations/paas-platforms/heroku/heroku-logs.md): Use our logging add-on to seamlessly forward all Heroku logging output to Coralogix. - [Heroku metric logs](https://coralogix.com/docs/integrations/paas-platforms/heroku/heroku-metric-logs.md): Our Heroku integration is configured to automatically detect inbound platform and custom metric logs, and parse them into JSON. To avoid confusion, we'll show some before and after examples, as well as explaining how to parse and generate metrics from these values, once they appear in your account. - [Heroku telemetry drains](https://coralogix.com/docs/integrations/paas-platforms/heroku/heroku-telemetry-drains.md): This guide provides step-by-step instructions for setting up Heroku telemetry drains to collect logs, metrics, and traces from your Heroku Private Space applications into Coralogix. - [Open commerce API](https://coralogix.com/docs/integrations/paas-platforms/open-commerce-api.md): Coralogix provides an easy way to collect your Open Commerce OrderSearch API logs. The preferred and easiest integration method will be to use our app in the AWS Serverless Application Repository. - [Salesforce commerce cloud](https://coralogix.com/docs/integrations/paas-platforms/salesforce-commerce-cloud.md): Coralogix provides an easy way to collect your Salesforce logs. The preferred and easiest integration method will be to use our app in the AWS Serverless Application Repository. - [Prometheus agent](https://coralogix.com/docs/integrations/prometheus/prometheus-agent.md): You can send your data to Coralogix using Prometheus Agent, a new operational mode of running Prometheus, built directly into the Prometheus binary. The agent mode optimizes the remote write use case configuring the Prometheus instance while disabling some of Prometheus' usual features - querying and alerting. - [Prometheus alertmanager data ingestion](https://coralogix.com/docs/integrations/prometheus/prometheus-alertmanager-data-ingestion.md): Sending your Prometheus alerts to Coralogix streamlines alert aggregation, enhances monitoring capabilities, and facilitates comprehensive incident analysis. By directing your Prometheus alerts into Coralogix, you gain a centralized view of your alerting activities, enabling rapid incident detection, proactive troubleshooting, and data-driven decision-making. This integration empowers teams to optimize response workflows, strengthen system reliability, and ensure operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Prometheus alerts and ensure a streamlined and resilient incident response process. - [Prometheus operator](https://coralogix.com/docs/integrations/prometheus/prometheus-operator.md): This guide shows you how to run Prometheus Operator in Kubernetes to export your data to Coralogix. - [Prometheus server](https://coralogix.com/docs/integrations/prometheus/prometheus-server.md): Automatically ship your Prometheus metrics into your Coralogix account and store them without making complex changes to your architecture. - [PagerDuty Bi-directional integration](https://coralogix.com/docs/integrations/pull/pagerduty.md): Connect Coralogix Cases to PagerDuty with two-way sync. Acknowledge, resolve, comment on, and add resolution notes to a PagerDuty incident and the linked Coralogix Case updates automatically, and the reverse. - [Slack access logs](https://coralogix.com/docs/integrations/pull/slack-access-logs.md): Collect Slack access logs into Coralogix by enabling Collect access logs on the Coralogix Slack integration. This capability requires the Slack admin scope. - [Slack Audit logs](https://coralogix.com/docs/integrations/pull/slack-audit-logs.md): Easily collect and analyze your Slack audit logs in Coralogix using our seamless Slack Audit Logs integration package. - [Slack integration](https://coralogix.com/docs/integrations/pull/slack.md): Connect Coralogix Cases to your Slack workspace. Send Case notifications to Slack channels, sync Slack thread replies back into the Case timeline, and surface rich previews of Coralogix Case URLs in Slack. - [Zoom](https://coralogix.com/docs/integrations/pull/zoom.md): Send your Zoom Sign-In/Sign-Out Activity Logs and Operation Logs to Coralogix for centralized monitoring and analysis. - [.NET Deprecated](https://coralogix.com/docs/integrations/sdks/dotnet-logging.md): Deprecation Notice: The Coralogix .NET SDK (Coralogix.SDK, CoralogixCoreSDK) is deprecated in favor of the OpenTelemetry .NET SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Go Deprecated](https://coralogix.com/docs/integrations/sdks/go.md): Deprecation Notice: The Coralogix Go SDK (go-coralogix-sdk) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Go OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Java Deprecated](https://coralogix.com/docs/integrations/sdks/java.md): Deprecation Notice: The Coralogix Java SDK (coralogix-sdk) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Log4j Deprecated](https://coralogix.com/docs/integrations/sdks/log4j.md): Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Log4net Deprecated](https://coralogix.com/docs/integrations/sdks/log4net.md): Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Logback Deprecated](https://coralogix.com/docs/integrations/sdks/logback.md): Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [NLog Deprecated](https://coralogix.com/docs/integrations/sdks/nlog.md): Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Node.js Bunyan Deprecated](https://coralogix.com/docs/integrations/sdks/nodejs-bunyan.md): Deprecation Notice: The Coralogix Bunyan logger package (coralogix-logger-bunyan) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Node.js Winston Deprecated](https://coralogix.com/docs/integrations/sdks/nodejs-winston.md): Deprecation Notice: The legacy Coralogix Node.js Winston integration is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Node.js Deprecated](https://coralogix.com/docs/integrations/sdks/nodejs.md): Deprecation Notice: The Coralogix Node.js SDK (coralogix-logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Python Deprecated](https://coralogix.com/docs/integrations/sdks/python-sdk.md): Deprecation Notice: The Coralogix Python SDK (coralogix_logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Python OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details. - [Ruby Deprecated](https://coralogix.com/docs/integrations/sdks/ruby.md): Deprecation Notice: The Coralogix Ruby SDK (coralogix_logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the end-of-life notice for migration details. - [Serilog Deprecated](https://coralogix.com/docs/integrations/sdks/serilog.md): Coralogix customers with Microsoft .NET applications using the Serilog logging library, are able to send logs to Coralogix using OpenTelemetry (OTel). - [Alcide kAudit](https://coralogix.com/docs/integrations/security/alcide-kaudit.md): Stream Alcide kAudit findings to Coralogix, enabling you to view, analyze and monitor your logs using cutting-edge tools. - [Alibaba Cloud ActionTrail](https://coralogix.com/docs/integrations/security/alibaba-cloud-actiontrail.md): The integration of Coralogix with ActionTrail on Alibaba Cloud offers a powerful solution for tracking and analyzing cloud-based actions. - [Beats: Auditbeat](https://coralogix.com/docs/integrations/security/beats-auditbeat.md): Coralogix provides seamless integration with Auditbeat so you can send your audit data from anywhere into Coralogix. - [Beats: Packetbeat](https://coralogix.com/docs/integrations/security/beats-packetbeat.md): Coralogix provides a seamless integration with Packetbeat so you can send your network usage logs from anywhere and parse them according to your needs. - [Bitdefender](https://coralogix.com/docs/integrations/security/bitdefender.md): Iitdefender is a leading cybersecurity company that offers a comprehensive suite of security products and services. Integrate Coralogix with Bitdefenders’ GravityZone service for comprehensive event streaming functionality. - [CrowdStrike Falcon SIEM connector](https://coralogix.com/docs/integrations/security/crowdstrike-falcon-siem-connector.md): Coralogix provides seamless integration with CrowdStrike Falcon, allowing you to correlate security-related events with your application and infrastructure logs and detect and respond to security incidents more effectively. - [CrowdStrike Falcon](https://coralogix.com/docs/integrations/security/crowdstrike-falcon.md): Forward CrowdStrike events into Coralogix to centralize your security data for advanced correlation and analysis across multiple data sources. This holistic security view allows you to become more efficient in detecting and investigating sophisticated threats and reduce time to respond to security incidents. - [Duo Security](https://coralogix.com/docs/integrations/security/duo-security.md): The following tutorial demonstrates how to successfully integrate Duo Security with Coralogix and send us your logs using FluentD. - [Overview](https://coralogix.com/docs/integrations/security/github-enterprise.md): This document explains how to configure the integration, allowing you to read logs from GitHub Enterprise into Coralogix. - [Jira](https://coralogix.com/docs/integrations/security/jira.md): Monitor and track your Jira activities in real-time by integrating Jira with Coralogix using webhooks. - [JumpCloud](https://coralogix.com/docs/integrations/security/jumpcloud-coralogix-integration.md): JumpCloud’s open directory platform allows the user to unify technology stack across identity, access, and device management, in a manner that doesn’t sacrifice security or functionality. - [JumpCloud](https://coralogix.com/docs/integrations/security/jumpcloud-integration.md): JumpCloud is a cloud-based Directory-as-a-Service (DaaS) platform that centralizes the management and security of user identities, devices, and applications within an organization's IT environment. Stream JumpCloud Directory Insights logs to Coralogix to improve observability and strengthen security analytics. This integration centralizes log management and unlocks advanced analysis features. - [JumpCloud SCIM identity management](https://coralogix.com/docs/integrations/security/jumpcloud-scim-identity-management-integration.md): Send your logs to Coralogix using the JumpCloud SCIM Identity Management Integration. - [Kandji](https://coralogix.com/docs/integrations/security/kandji.md): Integrate Kandji into Coralogix via OpenTelemetry (OTel) Collector to send Threat-Details logs. These logs track and record security-related events, including potential threats and vulnerabilities, within an organization's Apple devices managed through Kandji. - [Microsoft 365](https://coralogix.com/docs/integrations/security/microsoft-365.md): Microsoft 365 provides detailed audit logs of user activities, such as file downloads, data access grants, configuration changes, and DLP event logs. You can monitor the logs in the Coralogix platform. - [Microsoft defender](https://coralogix.com/docs/integrations/security/microsoft-defender.md): Microsoft Defender → Coralogix Via Azure Event Hubs - [AWS stale non-human resources Lambda - deployment guide](https://coralogix.com/docs/integrations/security/NHI/aws-stale-resources-lambda.md): This guide provides a step-by-step deployment guide for the AWS Stale Non-Human Resources Lambda. - [OneLogin](https://coralogix.com/docs/integrations/security/onelogin.md): OneLogin, a cloud-based identity and access management solution, streamlines user authentication and authorization processes for organizations. It features single sign-on (SSO) functionality, allowing users to access multiple applications using a single set of login credentials. OneLogin also offers multi-factor authentication options, such as SMS, email, and biometric verification, for enhanced security. Integration between OneLogin and Coralogix is facilitated via Webhook. - [Palo Alto Networks Cortex XDR](https://coralogix.com/docs/integrations/security/palo-alto-network-cortex-xdr.md): Forward Cortex XDR alerts, agent audit, and management audit logs to Coralogix over CEF/syslog through an OpenTelemetry Collector relay. - [Palo Alto Networks Cortex XSOAR](https://coralogix.com/docs/integrations/security/palo-alto-network-cortex-xsoar.md): If you ever need to handle security incidents you know how difficult it can be. More often than not, the system that detected the incident lacks the contextual information needed to figure out whether it's a false positive or something that needs to be investigated further. Other systems typically don't contain the full information either about the discovered incident. Also, automation would be of great help to tell the system: "Hey, if you see this particular incident from a similar IP address go to my firewall and block it and then inform me when you're done". This is where Cortex XSOAR comes in. - [Perimeter 81](https://coralogix.com/docs/integrations/security/perimeter-81-integration.md): The following tutorial demonstrates how to integrate Perimeter 81 by sending to an S3 bucket in AWS and sending the logs to Coralogix. - [Proofpoint TAP](https://coralogix.com/docs/integrations/security/proofpoint.md): Stream Proofpoint Targeted Attack Protection (TAP) SIEM events into Coralogix using a native, pull-based managed integration. Get delivered and blocked messages, plus permitted and blocked URL clicks, in your Coralogix account. - [Salesforce](https://coralogix.com/docs/integrations/security/salesforce.md): Integrate Salesforce with Coralogix to gain enhanced visibility and real-time monitoring of system events and logs. Salesforce generates detailed logs encompassing system activities, user interactions, and data changes, thereby offering valuable insights into the platform's operations. By leveraging this integration, you can actively monitor your Salesforce environment, optimize its performance, and ensure adherence to security and compliance standards.Users can choose which types of logs to monitor from a comprehensive list of options, including Platform Event logs and Event Log File logs. This customization empowers organizations to tailor their monitoring strategy according to their specific requirements, ensuring that critical events are promptly detected and addressed. - [SentinelOne (syslog)](https://coralogix.com/docs/integrations/security/sentinelone-syslog.md): This tutorial demonstrates how to seamlessly send SentinelOne logs to Coralogix. The integration requires sending your logs to an interceptive server and then forwarding them from the server to Coralogix. - [SentinelOne](https://coralogix.com/docs/integrations/security/sentinelone.md): SentinelOne logs provide critical insights into your organization's security, including endpoint activities, detected threats, and user and admin actions. Monitor your logs in the Coralogix platform to identify patterns, investigate threats and abnormal actions, and understand the context of potential security breaches. - [Shipping snowflake logs and Audit data to Coralogix with OpenTelemetry](https://coralogix.com/docs/integrations/security/shipping-snowflake-logs-and-audit-data-to-coralogix.md): This tutorial demonstrates how to centralize logging for Snowflake by sending your logs to Coralogix. - [Snyk vulnerability monitoring with Coralogix](https://coralogix.com/docs/integrations/security/snyk-vulnerability-monitoring-with-coralogix.md): This tutorial demonstrates how to conduct Snyk vulnerability monitoring with Coralogix by exporting Snyk's security testing data using Prometheus. - [SURF](https://coralogix.com/docs/integrations/security/surf.md): Seamlessly integrate your SURF logs with Coralogix. - [Integrate Suricata with Coralogix using OpenTelemetry](https://coralogix.com/docs/integrations/security/suricata.md): This guide explains how to integrate Suricata with Coralogix using the OpenTelemetry Collector. It leverages the flexibility and vendor-agnostic design of OpenTelemetry for observability pipelines. - [Tenable Attack Surface Management](https://coralogix.com/docs/integrations/security/tenable-asm.md): Pull external attack surface assets from Tenable Attack Surface Management (ASM) into Coralogix to monitor your internet-facing exposure alongside the rest of your telemetry and retain it long term. - [Tenable Identity Exposure](https://coralogix.com/docs/integrations/security/tenable-identity-exposure.md): Pull identity alerts, attacks, and deviances from your Tenable Identity Exposure (Tenable.ad) deployment into Coralogix for unified Active Directory security investigation and long-term retention. - [Tenable OT Security](https://coralogix.com/docs/integrations/security/tenable-ot-security.md): Pull OT asset inventory, vulnerability findings, and plugin metadata from your on-premise Tenable OT Security appliance into Coralogix for unified security investigation and long-term retention. - [Tenable Security Center](https://coralogix.com/docs/integrations/security/tenable-security-center.md): Pull vulnerabilities, assets, and plugin metadata from your on-premise Tenable Security Center (Tenable.sc) deployment into Coralogix for unified security investigation and long-term retention. - [Tenable](https://coralogix.com/docs/integrations/security/tenable.md): Forward Tenable audit logs, vulnerability findings, asset inventory, plugin catalog metadata, compliance findings, and Web App Scanning data to Coralogix to gain visibility into administrative activity, configuration changes, security risk, and vulnerability management context. - [Upwind webhook integration with Coralogix](https://coralogix.com/docs/integrations/security/upwind.md): Overview - [Wallarm](https://coralogix.com/docs/integrations/security/wallarm.md): Wallarm is an API and application security platform that protects modern web apps, microservices, and APIs from attacks by combining real-time threat detection with deep traffic analysis. It inspects HTTP and API traffic to identify vulnerabilities and malicious behavior such as OWASP Top 10 and API-specific attacks, using both signature-based and behavioral detection. Wallarm integrates with cloud-native environments (Kubernetes, service meshes, CI/CD pipelines) and provides centralized visibility, analytics, and automated response options, helping teams secure applications throughout the development and runtime lifecycle without slowing delivery. - [Wiz](https://coralogix.com/docs/integrations/security/wiz.md): The integration of Coralogix and Wiz empowers development teams to take complete ownership of their services, with full visibility into the performance and resource vulnerabilities, simplifying the analysis of the impact on their code and infrastructure. - [Zeek](https://coralogix.com/docs/integrations/security/zeek.md): In order to ship Zeek logs to Coralogix, we need to first install Filebeat. - [Zscaler Internet Access (ZIA)](https://coralogix.com/docs/integrations/security/zscaler-internet-access-zia.md): With Coralogix integration, ZIA and Zscaler's Nanolog Streaming Service (NSS) offer real-time visibility into internet traffic, user activity, and log streaming. This allows organizations to monitor and analyze network traffic for security threats and compliance purposes. - [Zscaler Secure Private Access (ZPA)](https://coralogix.com/docs/integrations/security/zscaler-secure-private-access-zpa.md): Configure Zscaler Secure Private Access (ZPA) to seamlessly send logs to Coralogix. - [Querying Coralogix with SQL](https://coralogix.com/docs/integrations/sql-tools/querying-coralogix-with-sql.md): Java Database Connectivity (JDBC) is a common standard for database drivers, and many popular querying tools support it. This tutorial explains how to use the Coralogix JDBC driver with the popular tools DataGrip, DBeaver, and Tableau. - [Configuring TLS on rsyslog](https://coralogix.com/docs/integrations/syslog/configuring-tls-on-rsyslog.md): This document explains how to configure TLS on rsyslog, which is necessary for sending logs to Coralogix syslog endpoints. - [Custom syslog](https://coralogix.com/docs/integrations/syslog/custom-syslog.md): Seamlessly send Coralogix your logs using a syslog template with a custom format. - [Rsyslog](https://coralogix.com/docs/integrations/syslog/rsyslog.md): Seamlessly send Coralogix your logs with Rsyslog using TCP (recommended), UDP, or manual installation. - [Syslog using OpenTelemetry](https://coralogix.com/docs/integrations/syslog/syslog-using-opentelemetry.md): This tutorial demonstrates how to use custom syslog to send your logs to Coralogix using OpenTelemetry. - [Syslog](https://coralogix.com/docs/integrations/syslog/syslog.md): Whether your system generates syslog messages in rfc3164 or rfc5424 format, or lets you transform them to a custom format, seamlessly send your syslogs to Coralogix. - [SyslogNG](https://coralogix.com/docs/integrations/syslog/syslogng.md): Determining syslog type ### OpenTelemetry - [AWS ECS-EC2 OpenTelemetry integration](https://coralogix.com/docs/opentelemetry/aws-ecs-ec2/ecs-ec2-integration.md): The OpenTelemetry integration for AWS ECS on EC2 provides complete observability for workloads running on ECS clusters backed by Amazon EC2 instances. - [AWS ECS-EC2 OpenTelemetry instrumentation](https://coralogix.com/docs/opentelemetry/configuration-options/amazon-web-services-aws-ecs-ec2-opentelemetry-instrumentation.md): This tutorial demonstrates how to deploy OpenTelemetry to ECS to facilitate the collection of logs, metrics, traces, and profiles, and send them to Coralogix. - [AWS ECS-EC2 using OpenTelemetry](https://coralogix.com/docs/opentelemetry/configuration-options/aws-ecs-ec2-using-opentelemetry.md): This guide shows you how to create a Docker image that is based on v0.62.0 release of OpenTelemetry Collector and send your data to Coralogix. By creating a specific image that forwards your metrics and traces to Coralogix, Coralogix allows you to run your application on ECS together with our container image. - [AWS ECS-EC2 (Windows) using OpenTelemetry](https://coralogix.com/docs/opentelemetry/configuration-options/aws-ecs-ec2-windows-using-opentelemetry.md): Deploy the Coralogix OpenTelemetry Collector as a Daemon on AWS ECS with Windows EC2 container instances. Includes parameters, configuration sources, and comparison to the Linux ECS-EC2 integration. - [Install OpenTelemetry on an EC2 instance](https://coralogix.com/docs/opentelemetry/configuration-options/install-opentelemetry-on-an-ec2-instance.md): This tutorial demonstrates how to set up an EC2 instance with OpenTelemtry Collector. - [OpenTelemetry using Docker](https://coralogix.com/docs/opentelemetry/configuration-options/opentelemetry-using-docker.md): This tutorial demonstrates how to configure OpenTelemetry (OTel) Collector to send your logs and metrics to Coralogix using Docker. - [Windows event logs & OpenTelemetry](https://coralogix.com/docs/opentelemetry/configuration-options/windows-event-logs-and-opentelemetry.md): Utilizing OpenTelemetry in conjunction with the Windows Event Log receiver is an excellent method for collecting Windows Event Logs. To implement this solution, it is essential to deploy an Opentelemetry Collector directly onto the Windows Server and configure it as a service to enable seamless integration with the Windows Event Log receiver. - [Logs](https://coralogix.com/docs/opentelemetry/data-sources/logs.md): OpenTelemetry log collection paths into Coralogix. - [Metrics](https://coralogix.com/docs/opentelemetry/data-sources/metrics.md): OpenTelemetry metrics collection paths into Coralogix. - [Profiling](https://coralogix.com/docs/opentelemetry/data-sources/profiling.md): OpenTelemetry profiling collection paths into Coralogix. - [Traces](https://coralogix.com/docs/opentelemetry/data-sources/traces.md): OpenTelemetry trace collection paths into Coralogix. - [Getting started](https://coralogix.com/docs/opentelemetry/getting-started.md): OpenTelemetry is a vendor-neutral, open-source observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Use OpenTelemetry's collection of APIs, SDKs, and tools to collect and export observability data from your environment to Coralogix. - [.NET OpenTelemetry instrumentation](https://coralogix.com/docs/opentelemetry/instrumentation-options/dotnet-opentelemetry-instrumentation.md): This tutorial demonstrates how to instrument .NET applications to capture logs, metrics and traces using OpenTelemetry, and send them to Coralogix. - [OBI as a collector receiver](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/collector-receiver.md): Run OBI as a receiver component inside the OpenTelemetry Collector to combine zero-code eBPF instrumentation with the Collector's processing pipeline. - [Distributed tracing](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/distributed-tracing.md): OBI enables distributed tracing for applications. - [Exposed metrics](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/exported-metrics.md): Metrics exported by OBI in OTel and Prometheus formats. - [Getting started](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/getting-started.md): Get started with eBPF automatic application instrumentation with OBI. - [eBPF application auto-instrumentation with OBI](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/overview.md): Enjoy eBPF with OBI for automatic application instrumentation. - [OBI service discovery](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/service-discovery.md): Configure OBI to instrument either a single service or a group of related services. - [Trace-log correlation](https://coralogix.com/docs/opentelemetry/instrumentation-options/ebpf-auto-instrumentation/trace-log-correlation.md): Enrich JSON application logs with trace context using OBI, enabling direct correlation between traces and logs without code changes. - [Golang OpenTelemetry instrumentation](https://coralogix.com/docs/opentelemetry/instrumentation-options/golang-opentelemetry-instrumentation.md): This tutorial demonstrates how to instrument Golang applications to capture logs, metrics and traces using OpenTelemetry, and send them to Coralogix. - [Java](https://coralogix.com/docs/opentelemetry/instrumentation-options/java-opentelemetry-instrumentation.md): This tutorial demonstrates how to instrument your Java applications to capture OpenTelemetry traces and send them to Coralogix.OpenTelemetry-Java automatic instrumentation is the most efficient method for adding instrumentation to Java applications. Requiring minimal modifications to the code, it uses a Java agent that can be attached to any Java 8+ application and dynamically injects bytecode to capture telemetry from a number of popular libraries and frameworks. - [Node.js](https://coralogix.com/docs/opentelemetry/instrumentation-options/nodejs-opentelemetry-instrumentation.md): This tutorial demonstrates how to instrument Node.js applications to capture metrics and traces using OpenTelemetry and send them to Coralogix. - [Lambda](https://coralogix.com/docs/opentelemetry/instrumentation-options/opentelemetry-lambda-auto-instrumentation.md): Coralogix offers coralogix-*-wrapper-and-exporter-* Lambda layers that enable you to generate logs, metrics, and traces, providing insights into triggers, invocation times, and interconnections. These features work out-of-the-box, without requiring any modification of the monitored Lambda functions' code. Once configuration is complete, view your data using our cutting-edge Serverless Monitoring feature. This tutorial demonstrates how to set up Lambda monitoring to get full telemetry, including traces. - [PHP](https://coralogix.com/docs/opentelemetry/instrumentation-options/php-opentelemetry-instrumentation.md): This tutorial demonstrates how to instrument PHP applications to capture logs, metrics, and traces using OpenTelemetry and send them to Coralogix. It relies on a Slim micro framework application, but other web frameworks – such as WordPress, Symfony, or Laravel – can also be used. - [Python](https://coralogix.com/docs/opentelemetry/instrumentation-options/python-opentelemetry-instrumentation.md): This section demonstrates how to instrument your Python applications to capture OpenTelemetry traces and send them to Coralogix. - [APM using OpenTelemetry as a unified shipper with Kubernetes](https://coralogix.com/docs/opentelemetry/integrations/apm-kubernetes-open-telemetry-opentelemetry.md): When we refer to OpenTelemetry as a Unified Shipper, we are describing architecture where by OpenTelemetry is leveraged to collect all the required data (logs, metrics & traces) to facilitate application performance monitoring (APM) functionality. - [APM using OpenTelemetry collector with Kubernetes](https://coralogix.com/docs/opentelemetry/integrations/apm-kubernetes.md): Coralogix now offers certain features of application performance monitoring (APM) for modern, cloud-native environments for those customers using OpenTelemetry collector with a Kubernetes processor. Our new features decorate all pillars of observability with additional information that extends beyond system availability, service performance, and response times. - [Collect Kubernetes events using OpenTelemetry](https://coralogix.com/docs/opentelemetry/integrations/collect-kubernetes-events-using-opentelemetry.md): The following tutorial demonstrates how to collect Kubernetes Events using OpenTelemetry. - [OpenTelemetry ECS fargate](https://coralogix.com/docs/opentelemetry/integrations/ecs-fargate.md): Seamlessly stream logs, metrics, and traces generated by AWS ECS Fargate containers to Coralogix for optimal monitoring, analysis, and visualization. - [Host observability](https://coralogix.com/docs/opentelemetry/integrations/host-observability.md): The Coralogix Host integration uses OpenTelemetry to collect logs, metrics, and traces from Linux hosts, including virtual machines, bare-metal servers, and cloud instances. - [Introduction to Kubernetes observability using OpenTelemetry](https://coralogix.com/docs/opentelemetry/integrations/introduction-to-kubernetes-observability-using-opentelemetry.md): Coralogix offers Kubernetes Observability using OpenTelemetry for comprehensive Kubernetes and application observability. Using our OpenTelemetry Chart, the integration enables you to simplify the collection of logs, metrics, and traces from the running application in pods to the cluster-level components of your Kubernetes cluster. - [Kubernetes complete observability: advanced configuration](https://coralogix.com/docs/opentelemetry/integrations/kubernetes-complete-observability-advanced-configuration.md): Coralogix offers Kubernetes Observability using OpenTelemetry for comprehensive Kubernetes and application observability. This tutorial will guide you through advanced configuration options for Kubernetes clusters. - [Running OpenTelemetry as a CLI application](https://coralogix.com/docs/opentelemetry/integrations/running-opentelemetry-as-a-cli-application.md): This tutorial demonstrates how to configure OpenTelemetry (OTEL) Collector to send your logs and metrics to Coralogix when running OpenTelemetry as a CLI application or service. - [Advanced configuration](https://coralogix.com/docs/opentelemetry/kubernetes-observability/advanced-configuration.md): Coralogix offers Kubernetes Observability using OpenTelemetry for comprehensive Kubernetes and application observability. This tutorial will guide you through advanced configuration options for Kubernetes clusters. - [FAQs](https://coralogix.com/docs/opentelemetry/kubernetes-observability/faqs.md): Check out these frequently asked questions regarding Kubernetes Observability using OpenTelemetry. - [Basic](https://coralogix.com/docs/opentelemetry/kubernetes-observability/kubernetes-complete-observability-basic-configuration.md): Coralogix’s Kubernetes Complete Observability provides a comprehensive solution for full-stack observability in your Kubernetes environment. - [Kubernetes observability using OpenTelemetry](https://coralogix.com/docs/opentelemetry/kubernetes-observability/kubernetes-observability-using-opentelemetry.md): Coralogix offers Kubernetes Observability using OpenTelemetry for comprehensive Kubernetes and application observability. Using our OpenTelemetry Chart, the integration enables you to simplify the collection of logs, metrics, and traces from the running application in pods to the cluster-level components of your Kubernetes cluster. - [OpenTelemetry AutoInstrumentation](https://coralogix.com/docs/opentelemetry/kubernetes-observability/opentelemetry-autoinstrumentation.md): Inject OpenTelemetry auto-instrumentation into Kubernetes workloads by using the Coralogix OpenTelemetry Integration Helm chart. - [Tail sampling with OpenTelemetry using Kubernetes](https://coralogix.com/docs/opentelemetry/kubernetes-observability/tail-sampling-with-opentelemetry-using-kubernetes.md): This tutorial demonstrates how to configure a Kubernetes cluster and deploy OpenTelemetry to collect logs, metrics, and traces, as well as enable trace sampling. - [Integration troubleshooting](https://coralogix.com/docs/opentelemetry/kubernetes-observability/troubleshooting.md): Troubleshoot any issues with the setup or configuration of the Kubernetes Observability using OpenTelemetry. - [Validation](https://coralogix.com/docs/opentelemetry/kubernetes-observability/validation.md): Validate that you have enabled Kubernetes Observability using OpenTelemetry and are sending cluster telemetry to Coralogix. - [Monitoring Windows server using OTel & Prometheus](https://coralogix.com/docs/opentelemetry/monitoring/monitoring--windows-server-using-otel-and-prometheus.md): This tutorial demonstrates how to monitor Windows Server - including IIS and MSSQL - for logs, metrics, and traces using OpenTelemetry Collector and Prometheus Windows Exporter. - [Product](https://coralogix.com/docs/opentelemetry/product.md): How OpenTelemetry data flows into Coralogix product features. - [Getting started](https://coralogix.com/docs/opentelemetry/standalone-installation/standalone-complete-observability-configuration.md): Coralogix's Standalone Complete Observability provides a comprehensive solution for full-stack observability on standalone hosts. - [Tail sampling with Coralogix & OpenTelemetry](https://coralogix.com/docs/opentelemetry/tail-sampling/tail-sampling-with-coralogix-and-opentelemetry.md): Coralogix offers a number of tutorials demonstrating how to use the OTel Collector in a load-balanced configuration with tail sampling enabled on the collector nodes using the OTel Demo App. By sampling your traces, you can significantly reduce the amount of data ingested into Coralogix, maintaining full visibility into your services without incurring heavy charges. - [Tail sampling with OpenTelemetry using AWS ECS EC2](https://coralogix.com/docs/opentelemetry/tail-sampling/tail-sampling-with-opentelemetry-using-aws-ecs-ec2.md): This tutorial demonstrates how to configure an AWS ECS EC2 cluster, deploy OpenTelemetry to collect logs, metrics, and traces, and enable intelligent trace sampling using CloudFormation templates. - [Tail sampling with OpenTelemetry using Docker compose](https://coralogix.com/docs/opentelemetry/tail-sampling/tail-sampling-with-opentelemetry-using-docker-compose.md): The following tutorial demonstrates how to use the OTel Collector in a load-balanced configuration with tail sampling enabled on the collector nodes using the OTel Demo App and Docker. - [OpenTelemetry workshops & reference implementations](https://coralogix.com/docs/opentelemetry/workshops.md): Coralogix provides a community-maintained collection of workshops and reference implementations designed to help users quickly test and explore OTEL and Coralogix integrations. ### Developer Portal - [OpenTelemetry custom logs](https://coralogix.com/docs/developer-portal/apis/data-ingestion/opentelemetry-custom-logs.md): Send your custom logs to Coralogix using our OpenTelemetry-compatible endpoint. - [OpenTelemetry custom metrics](https://coralogix.com/docs/developer-portal/apis/data-ingestion/opentelemetry-custom-metrics.md): Coralogix provides a scalable Prometheus-compatible managed service for time-series data. Employ our custom metric endpoint, including serverless computing and quick cURL-like calls, to send counters, gauges, and histograms to Coralogix. - [OpenTelemetry custom traces](https://coralogix.com/docs/developer-portal/apis/data-ingestion/opentelemetry-custom-traces.md): Send your custom traces to Coralogix using our OpenTelemetry-compatible endpoint. - [Alert Suppression Rules API](https://coralogix.com/docs/developer-portal/apis/data-management/alert-suppression-rules-api.md): Alert Suppression Rules allow you to automatically mute alerts according to your specific parameters. You can set what to suppress (what group-by keys), when to suppress (specific times and dates, recurring times and dates, one-time suppressions), and which alerts to suppress during those times. - [Alerts API v1/v2](https://coralogix.com/docs/developer-portal/apis/data-management/alerts-api/alerts-api-v1-v2.md): This guide demonstrates how to define, query, and manage Coralogix Alerts using our v1/v2 Alerts API. - [Alerts API v3](https://coralogix.com/docs/developer-portal/apis/data-management/alerts-api/alerts-grpc-api.md): Use the Alerts API v3 to define, query, and manage Coralogix Alerts. - [Migrating from alerts v2 to v3](https://coralogix.com/docs/developer-portal/apis/data-management/alerts-api/alerts-v2-v3-migration.md): Coralogix Alerts API v3 introduces advanced alert management features such as multiple conditions, anomaly detection sensitivity customization and custom evaluation delays. Migrating to v3 is recommended to take advantage of these and future capabilities, as well as to streamline your alerting configurations. This guide offers migration options for UI, Terraform, and API users. - [Cases API](https://coralogix.com/docs/developer-portal/apis/data-management/cases-api.md): The Cases API manages Cases throughout their lifecycle, the events on a Case timeline, and notification deliveries routed for Cases. Use it to list, update, assign, acknowledge, resolve, and close Cases programmatically. - [Data usage service API](https://coralogix.com/docs/developer-portal/apis/data-management/data-usage-service-api.md): Coralogix provides an API in support of our Detailed Data Usage Report, which presents you with all data sent, per policy, for either the current month or retroactively 30 or 90 days. The API allows you to query your data consumption in given a time period. - [Incident management API](https://coralogix.com/docs/developer-portal/apis/data-management/incident-management-api.md): The Incident Management API includes various methods for managing incidents, such as retrieving incident details, listing incidents, aggregating incidents, assigning and unassigning incidents and acknowledging or resolving incidents. - [Insights API](https://coralogix.com/docs/developer-portal/apis/data-management/insights-api.md): This tutorial describes how you can retrieve "New", "Suspected", and "Top" errors using the Coralogix Insight API calls. - [Metrics cardinality API](https://coralogix.com/docs/developer-portal/apis/data-management/metrics-cardinality-api.md): The Coralogix Metrics Cardinality API is deprecated in favor of the Metrics Usage API and will no longer be supported. - [Metrics cost optimizer API](https://coralogix.com/docs/developer-portal/apis/data-management/metrics-cost-optimizer-api.md): Overview - [Metrics optimizer API](https://coralogix.com/docs/developer-portal/apis/data-management/metrics-optimizer-api.md): Overview - [Metric usage API](https://coralogix.com/docs/developer-portal/apis/data-management/metrics-usage-api.md): With Coralogix you can retrieve detailed usage for your metrics (bytes volume, series/cardinality, samples, and derived unit usage) over calendar dates in multiple categories. Our API returns usage statistics by dates* in 4 categories: - [Recording Rules API](https://coralogix.com/docs/developer-portal/apis/data-management/recording-rules-api.md): Recording rules allow you to pre-process and derive new time series from existing ones. The rules are defined in a configuration file and are executed in the background at a regular interval, specified in the configuration file. - [Send-Your-Data management API](https://coralogix.com/docs/developer-portal/apis/data-management/send-your-data-management-api.md): Coralogix provides an API that allows you to manage your Send-Your-Data API keys. - [Service removal gRPC API](https://coralogix.com/docs/developer-portal/apis/data-management/service-removal-grpc-api.md): We are introducing the APM Service Removal API for customers who want to regularly maintain their APM Service Catalog. Even if services no longer exist on your side, the catalog in Coralogix lists all previously imported services indefinitely. With the Service Removal API, you can manually remove one or more unused services from your Coralogix subscription. - [Service retention period gRPC API](https://coralogix.com/docs/developer-portal/apis/data-management/service-retention-period-grpc-api.md): Adjust your service retention period with the Service Retention Period gRPC API. - [SLO management API](https://coralogix.com/docs/developer-portal/apis/data-management/slo-management-alerts-api.md): We are introducing the SLO Management API to enable teams, particularly those not utilizing a UI, to efficiently manage their SLOs programmatically. This API will let you retrieve, read, create, update and delete your SLOs. - [SLO management API](https://coralogix.com/docs/developer-portal/apis/data-management/slo-management-api.md): We are introducing the SLO API to enable teams, particularly those not utilizing a UI, to efficiently manage their SLOs programmatically. This API will let you retrieve, read, create, update and delete your SLOs. - [Getting started with Coralogix APIs](https://coralogix.com/docs/developer-portal/apis/getting-started/getting-started-with-coralogix-apis.md): Unlock the full power of Coralogix’s observability platform with our suite of APIs. Use them to send data, build dashboards, manage resources, and run advanced queries across logs, metrics, traces, and more. This guide will help you get started by covering authentication, core concepts, and API categories—so you can integrate, automate, and scale with confidence. - [Hosted Grafana API](https://coralogix.com/docs/developer-portal/apis/grafana/hosted-grafana-api.md): Coralogix provides a secure Grafana API for creating, editing, exporting, importing, querying, and other Grafana API operations. Through Grafana APIs, you can manage your hosted Grafana dashboards. - [Limitations](https://coralogix.com/docs/developer-portal/apis/limitations.md): Coralogix API limitations - [Coralogix REST API /singles](https://coralogix.com/docs/developer-portal/apis/log-ingestion/coralogix-rest-api-singles.md): Send your logs using the Coralogix REST API /singles. - [Coralogix REST API](https://coralogix.com/docs/developer-portal/apis/log-ingestion/coralogix-rest-api.md): Send us your logs using our Rest API /singles endpoint. - [Olly REST API](https://coralogix.com/docs/developer-portal/apis/olly.md): Drive Olly chats from your own backend with the Olly REST API — trigger investigations, send prompts, and retrieve the query results Olly generates. - [Platform as a service (PaaS)](https://coralogix.com/docs/developer-portal/apis/platform-as-a-service.md): Skip manual API integration by using our automated tools: the Coralogix Terraform Provider and Kubernetes Operator. Easily manage resources without writing custom code. - [Archive setup gRPC API](https://coralogix.com/docs/developer-portal/apis/tco-controls/archive-setup-grpc-api.md): This tutorial will demonstrate how to use our Archive Setup API to view bucket definitions and set a target bucket (Get target / Set target), as well as to define archive retentions (Get, Update, Activate). - [TCO Optimizer HTTP API](https://coralogix.com/docs/developer-portal/apis/tco-controls/tco-optimizer-http-api.md): Use the TCO Optimizer HTTP API to define, query, and manage your TCO policy overrides, used exclusively for logs. - [TCO tracing policy gRPC API](https://coralogix.com/docs/developer-portal/apis/tco-controls/tco-tracing-policy-grpc-api.md): This tutorial demonstrates how to use our TCO Optimizer gPRC API to define, query, and manage your TCO policy criteria, used both for spans and logs. - [Argo CD Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/argo-cd-version-tags.md): Coralogix provides seamless integration with Argo CD so you can push tags from your pipelines. - [Bitbucket Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/bitbucket-version-tags.md): Coralogix supports integration with BitBucket webhooks, use webhooks to inform Coralogix when a new build is issued. - [cURL Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/curl-version-tags.md): You can add version tags in Coralogix per Application and Subsystem using cURL - [GitHub Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/github-version-tags.md): GitHub Actions allows you to perform numerous tasks automatically, including using the cURL command to insert a new tag when a release is made or when a pull request is closed for example.This tutorial demonstrates how to build an automation that will create a new tag in Coralogix upon publishing a new release of your code. - [GitLab Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/gitlab-version-tags.md): Coralogix supports integration with GitLab webhooks, use webhooks to inform Coralogix when a new build is issued. - [Microsoft Azure DevOps Server version tags](https://coralogix.com/docs/developer-portal/apis/version-tags/microsoft-azure-devops-server-version-tags.md): Coralogix supports integration with Azure DevOps Server webhooks, use webhooks to inform Coralogix when a new build is issued. - [Spinnaker Version Tags](https://coralogix.com/docs/developer-portal/apis/version-tags/spinnaker-version-tags.md): Coralogix provides seamless integration with Spinnaker so you can push tags from your pipelines. - [Coralogix CLI (legacy)](https://coralogix.com/docs/developer-portal/infrastructure-as-code/cli/cxctl-legacy.md): This page has moved. You will be redirected to cli.coralogix.dev. - [SAML management via CLI (legacy)](https://coralogix.com/docs/developer-portal/infrastructure-as-code/cli/cxctl-legacy/saml-management.md): This page has moved. You will be redirected to cli.coralogix.dev. - [Team management via CLI (legacy)](https://coralogix.com/docs/developer-portal/infrastructure-as-code/cli/cxctl-legacy/team-management.md): This page has moved. You will be redirected to cli.coralogix.dev. - [Coralogix OpenAPI](https://coralogix.com/docs/developer-portal/infrastructure-as-code/coralogix-openapi.md): The Coralogix API conforms to the OpenAPI specification. Here's a list of the available endpoints, operations, and parameters. - [Coralogix Terraform Provider](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/coralogix-terraform-provider.md): The Coralogix Terraform provider lets you manage Coralogix resources—alerts, dashboards, TCO policies, recording rules, SLOs, webhooks, enrichment, and more—as infrastructure code. It requires Terraform v1.3.0 or later. - [AWS metrics from CloudWatch](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/aws-metrics-collector.md): Overview - [Azure metrics](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/azure-metrics-collector.md): Overview - [CrowdStrike](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/crowd-strike-collector.md): Overview - [GCP logs](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/gcp-logs-collector.md): Overview - [GCP metrics](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/gcp-metrics-collector.md): Overview - [GCP resources](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/gcp-resources.md): Overview - [GCP traces](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/gcp-traces-collector.md): Overview - [GitHub enterprise](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/github-enterprise-collector.md): Overview - [Google workspace alert center](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/google-alert-center-collector.md): Overview - [Google workspace](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/google-workspace-audit-logs-collector.md): Overview - [Google workspace users](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/google-workspace-users.md): Overview - [Microsoft 365](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/microsoft-365-collector.md): Overview - [Okta users](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/okta-users.md): Overview - [Proofpoint](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/proofpoint-collector.md): Overview - [Salesforce](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/salesforce-events-collector.md): Overview - [SentinelOne](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/sentinel-one-collector.md): Overview - [Wiz](https://coralogix.com/docs/developer-portal/infrastructure-as-code/terraform-provider/integrations/wiz-collector.md): Overview ### search - [Search the documentation](https://coralogix.com/docs/search.md) ### static - [query_service v1](https://coralogix.com/docs/static/swagger.md): {/ Generator: Widdershins v4.0.1 /}