graylog2-server icon indicating copy to clipboard operation
graylog2-server copied to clipboard

Log canceled user-created searches

Open damianharouff opened this issue 5 months ago • 0 comments

The new ability to cancel long-running user searches: https://github.com/Graylog2/graylog2-server/pull/18308 will present a notice to the user in the web UI when a search is canceled, however it would be a good idea to log these cancellations to server.log (or maybe generate a system event?) so that the Graylog admin can have awareness that searches are being canceled.

In a very busy Graylog environment with hundreds of users generating searches, the Graylog admin will likewise want awareness of this so that they can both assist their users, and understand if a user repeating an unreasonable search is impacting their service quality.

This stems from a situation encountered by a strategic customer where they have awareness that a user search is impacting their search cluster, but have no ability to understand which specific query is causing this without asking users currently logged into their system, and this may be hundreds of searches at a time. They have to assess each and every one of them manually, which is very time consuming. ZD 940 has more details too.

damianharouff avatar Sep 17 '24 17:09 damianharouff