This page describes log observability capabilities and the features that they provide with a DPS subscription.
For information about how usage of a specific capability translates to consumption of your DPS license commit, see
Dynatrace offers
In the usage-based model, Log - Retain and Log - Query are charged separately.
In this case, you pay for each query. This is ideal if you have historical data that you do not access frequently.
What's included with the Ingest & Process data-usage dimension?
| Concept | Explanation |
|---|---|
| Data delivery | Delivery of log data via OneAgent or Log ingestion API (via ActiveGate) |
| Topology enrichment | Enrichment of log events with data source and topology metadata |
| Data transformation | - Add, edit, or drop any log attribute - Perform mathematical transformations on numerical values (for example, creating new attributes based on calculations of existing attributes) - Mask sensitive data by replacing either the whole log record, one specific log record attribute, or certain text with a masked string - Extract business, infrastructure, application, or other data from raw logs. This can be a single character, string, number, array of values, or other. Extracted data can be turned into a new attribute allowing additional querying and filtering. Metrics can be created from newly extracted attributes (see Conversion to time series below) |
| Data-retention control | - Filter and exclude incoming logs based on content, topology, or metadata (filtering generates usage for Ingest & Process, but not for Retain) - Manage data retention periods of incoming logs based on data-retention rules |
| Conversion to time series | Create metrics from log records or attributes (note that creating custom metrics generates additional consumption as described here) |
Apply the following calculation to determine your consumption for the Ingest & Process data-usage dimension:
consumption = (number of GiBs ingested) × (GiB price as per your rate card)
Data enrichment and processing can increase your data volume significantly. Depending on the source of the data, the technology, the attributes, and metadata added during processing, the total data volume after processing can increase by a factor of 2 or more.
Dynatrace reserves the right to work with customers to adjust or disable parsing rules, processors, or pipelines that are experiencing service degradation.
Here's what's included with the Retain data-usage dimension:
| Concept | Explanation |
|---|---|
| Data availability | Retained data is accessible for analysis and querying until the end of the retention period. |
| Retention periods | Choose a desired retention period. For log buckets, the available retention period ranges from 1 day to 10 years. Metrics retention is defined at the bucket level, ensuring tailored retention periods for specific metrics. |
Query data usage occurs when:
What's included with the Query data-usage dimension?
| Concept | Explanation |
|---|---|
| On-read parsing | Use DQL to query historical logs in storage and extract business, infrastructure, or other data across any timeframe, and use extracted data for follow-up analysis |
| Aggregation | Perform aggregation, summarization, or statistical analysis of data in logs across specific timeframes or time patterns (for example, data occurrences in 30-second or 10-minute intervals) |
| Reporting | Create reports or summaries with customized fields (columns) by adding, modifying, or dropping existing log attributes |
| Context | Use DQL to analyze log data in context with relevant data on the Dynatrace platform, for example, user sessions or distributed traces |
Dynatrace version 1.316+
In the Retain with Included Queries model, retained log data within a configured time period can be queried free of charge, as often as you want. This is ideal if you frequently access recent data, or look at highly predictable consumption patterns.
Customers can split a log bucket’s retention period into two parts:
With the Retain with Included Queries model, Log - Ingest & Process consumption continues to be calculated separately and is charged only once for the initial ingestion into your tenant.
Customers who select the Retain with Included Queries option in the bucket configuration are not charged for those queries executed within the scope of the Included Queries retention period. (The retention period is defined on a log bucket within the Dynatrace Platform.) For queries that are executed and include a scope outside of the Included Queries period, only these logs outside of the Retain with Included Queries are billed individually with the usage based Logs - Query model.
Included query usage per day = (GiB of logs within the defined Included Queries retention period) × 15
In any 24-hour period, customers with this licensing option activated are entitled to run queries with an aggregate scanned-GiB volume of up to 15 times the volume of log data that is retained within the Included Queries timeframe at that time. Example: You ingest and retain 1 GiB per day, and set the Included Queries retention period to 10 days. Your query quota is 150 GiB per 24 hours (1 GiB x 10 Days x 15 Multiplier = 150 GiB).
Using this formula, we have included sufficient queries for the majority of customers. In case you exceed the included query volume, the Dynatrace team will reach out and help you to evaluate and optimize query consumption. Alternatively, if the Retain with Included Query option does not meet your use case and requirements, you can reconfigure a bucket at any time to use individually billed on-demand queries without losing data.