Sondar documentation
Sondar documentation
Section titled “Sondar documentation”Sondar is an observability platform: collect machine data — logs, metrics, traces and events — from across your estate, search and chart it in one query language, and alert on it. This handbook is the product documentation. Start with Getting started, or jump to the area you need.
Core concepts
Section titled “Core concepts”If you are new to Sondar, read Concepts first — it explains the data model that every other page assumes: what an index is, what a sourcetype is, and how data flows from a machine into a searchable event.
The workflow, end to end
Section titled “The workflow, end to end”- Collect — get data in. Getting started · Agent and machines · Log collection sources · Database sources · Middleware · Web servers and load balancers · Host monitoring · Kubernetes and containers · Listening collection · File upload · Data synchronization (external stores) · Events · vSphere
- Parse and shape — turn raw lines into fields. Indexes and field extraction · Transformers
- Search — ask questions. Interactive search · Search analysis · The SonQL query language · Splunk → SonQL · Log pattern recognition · Search actions and macros · Export · Search jobs
- Visualize — make it glanceable. Dashboards
- Alert — get woken up. Alerts and notifications
- Observe services — traces and service maps. Application performance monitoring
Reference
Section titled “Reference”- Metrics — Metrics and resource groups
- The platform itself — Monitoring console
- Proactive checks — Dial testing
- Account and delivery — User settings and notifications · Roles and permissions
- Integrations — CI/CD monitoring · Database sources · Middleware
- Data management — Data masking · Data archiving · External data and lookups · Datasets
- Automation — The Sondar CLI · The REST API
Extending Sondar
Section titled “Extending Sondar”About Sondar
Section titled “About Sondar”This handbook documents the product. For what Sondar is, what it costs and how it compares to what you are running now, see sondar.dev — pricing, security and architecture, and a Splunk migration guide if that is where you are coming from.