Log Management Overview
Cloudaware Log Management, also known as Conflux, discovers, collects, enriches, and analyzes logs from cloud providers, operating systems, applications, Kubernetes environments, and network devices.
Conflux uses Cloudaware CMDB context to associate log events with accounts, regions, applications, environments, owners, tags, and infrastructure resources. This context supports log search, dashboards, investigations, operational monitoring, security analysis, and downstream SIEM and SOAR workflows.
- Audience: Security operations, SRE and observability teams, and application owners
- Outcome: Centralized log search and dashboards enriched with CMDB context, with integrations for SIEM and SOAR platforms
Use Cloudaware Log Management when you need:
- Centralize searchable logs across clouds and on-premises environments.
- Investigate changes, access activity, application behavior, and network events.
- Correlate log events with applications, environments, owners, accounts, regions, and related infrastructure.
- Support security investigations, incident response, compliance evidence, and operational troubleshooting.
- Forward or integrate log data and alerts with SIEM, SOAR, monitoring, and automation systems.
- Apply retention and archival policies based on operational, security, and compliance requirements.
Core Capabilities
Cloudaware Log Management provides:
- Multi-source log ingestion – logs from cloud services, operating systems, applications, Kubernetes environments, SaaS systems, identity platforms, and network devices collected through supported ingestion methods.
- Centralized log search – log events from multiple providers, accounts, regions, and environments available through a unified search experience.
- CMDB-based enrichment – events associated with infrastructure resources, applications, environments, owners, accounts, regions, tags, and other business context.
- Dashboards and saved searches – reusable queries, visualizations, dashboards, reports, and investigation views built from indexed log data.
- Monitoring and alerting – log patterns and events used to support operational alerts, security findings, and notification workflows.
- Investigation support – searchable event history and contextual metadata used for incident response, troubleshooting, access reviews, and change analysis.
- Retention and archival – configurable data retention and archival patterns aligned with performance, cost, operational, and compliance requirements.
- Exports and automation – log data and findings delivered to APIs, webhooks, reports, and downstream automation workflows.
How Log Management Works
Log Management (Conflux) follows a discovery-to-analysis pipeline:
- Discovers log sources. Cloudaware CMDB discovery jobs and integrations identify supported log-producing resources, such as cloud services, load balancers, storage resources, databases, hosts, Kubernetes clusters, and network devices.
- Collects log data. Logs are collected through supported cloud-native services, agents, syslog, APIs, file-based methods, and other ingestion patterns.
- Normalizes and enriches events. Conflux parses and indexes log records and enriches them with CMDB attributes, including account, region, application, environment, owner, tags, and related resource context.
- Makes logs available for analysis. Users can search logs, build dashboards, create saved queries, investigate incidents, and export or forward data to connected systems.
- Supports alerts and downstream workflows. Log events can contribute to monitoring, security findings, notifications, incident workflows, and automation in Cloudaware and external tools.
- Retains and archives data. Frequently queried data remains available for fast analysis, while older data can be archived according to the configured retention policy and service agreement.
Relationship to Other Modules and Integrations
Cloudaware Log Management works together with:
- Cloudaware CMDB that provides resource inventory, ownership, relationships, tags, applications, environments, accounts, and regions used to enrich log events.
- SIEM/SOAR integrations that can receive logs, findings, or alerts for centralized security analysis and response.
- Webhooks & Events that route alerts and events to downstream workflows.
- Network and device discovery integrations that provide additional sources for flow, infrastructure, and device logs.
Explore the Log Management Documentation
Use these guides together as the Cloudaware Log Management documentation set.
Prepare Log Management
-
Review requirements. Confirm prerequisites for cloud, host, SaaS, identity, network, and custom log sources.
-
Review the architecture. Understand how CMDB-driven discovery, collection, enrichment, storage, retention, and consumers fit together.
-
Review log sources. Identify supported source categories and how Conflux maps them to CMDB context.
Configure Log Collection
- Ingestion: Configure collection patterns, connectivity requirements, security considerations, and ingestion health checks.
- Integrations: Connect SIEM/SOAR tools, SaaS providers, Cloudaware modules, APIs, and automation workflows.
Search and Analyze Logs
- Dashboards & Reporting: Build dashboards, saved searches, reports, exports, and investigation workflows.
- Playbooks: Follow repeatable procedures for coverage validation, triage, investigations, onboarding, and evidence handling.
Operate Log Management
- Operations: Manage ingestion monitoring, access governance, retention planning, performance, and readiness practices.
- Reference: Review sizing guidance, field mapping, and related reference material.
- FAQ: Find answers about log sources, retention, access, integrations, ingestion, and security.