Skip to content

Sondar documentation

Sondar is an observability platform: collect machine data — logs, metrics, traces and events — from across your estate, search and chart it in one query language, and alert on it. This handbook is the product documentation. Start with Getting started, or jump to the area you need.


If you are new to Sondar, read Concepts first — it explains the data model that every other page assumes: what an index is, what a sourcetype is, and how data flows from a machine into a searchable event.

  1. Collect — get data in. Getting started · Agent and machines · Log collection sources · Database sources · Middleware · Web servers and load balancers · Host monitoring · Kubernetes and containers · Listening collection · File upload · Data synchronization (external stores) · Events · vSphere
  2. Parse and shape — turn raw lines into fields. Indexes and field extraction · Transformers
  3. Search — ask questions. Interactive search · Search analysis · The SonQL query language · Splunk → SonQL · Log pattern recognition · Search actions and macros · Export · Search jobs
  4. Visualize — make it glanceable. Dashboards
  5. Alert — get woken up. Alerts and notifications
  6. Observe services — traces and service maps. Application performance monitoring

This handbook documents the product. For what Sondar is, what it costs and how it compares to what you are running now, see sondar.devpricing, security and architecture, and a Splunk migration guide if that is where you are coming from.