With Sumo Logic, what is the difference between 'cluster' and '_sourceCategory'?
I've tried looking at the documentation but am not finding anything for cluster itself. If you know, please share the knowledge.
There is nothing like cluster in sumo logic.
It is _sourceCategory and _sourceHost.
_sourceCategory basically just means the name of categories to which these logs belong. For example: If you are ingesting logs of a service named X, you can put its _sourceCategory as X and then search for it with query _sourceCategory=X
If you cluster name is Y and your nodes are numbered Y-1,Y-2 ... Y-10, then you can search it like _sourceHost=Y*. This would give you all the logs for cluster Y.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With