You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何编写Sumo Logic搜索查询查找存储的Ingest Budget数据

Sumo Logic Ingest Budget查询索引说明及实操指引

直接给可落地的结论:

  • 不存在Ingest Budget专属的独立_index,所有采集预算的配置变更、用量消耗、超限拦截相关数据,全部存在Sumo Logic内置的系统索引 sumologic_system_events 中,直接指定该索引检索即可。
  • 检索时需要搭配指定_sourceCategory=ingest_budgets过滤无关系统事件,基础查询语句如下:
_index=sumologic_system_events _sourceCategory=ingest_budgets
  • 上述查询返回的日志包含所有核心字段:预算ID、预算名称、当前统计周期已采集数据量、配额阈值、超限丢弃日志、预算调整操作记录,完全支撑用量统计、超限告警类的定时任务需求。

定时调度配置参考

  • 时间范围选择「最近15分钟」即可,调度频率建议设为10分钟/次,不需要扫描过长时间范围,避免不必要的查询资源消耗。
  • 如果要做预算使用率告警,可以直接在基础查询后拼接统计逻辑,80%阈值告警的参考语句如下:
_index=sumologic_system_events _sourceCategory=ingest_budgets
| json field=_raw "budget_name", "current_usage_bytes", "quota_bytes", "budget_id"
| eval usage_percent = round(current_usage_bytes/quota_bytes*100,2)
| where usage_percent >= 80

排查注意:如果执行查询无返回结果,先确认当前登录账号有sumologic_system_events索引的查询权限,子账号默认没有系统事件查看权限,找租户管理员开通即可。

内容的提问来源于stack exchange,提问作者Ashirwad.nivalkar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 11:48:17