Log Analysis Runbook

1
2
3
4
SELECT * FROM logs 
WHERE level = 'error'
  AND _timestamp > now() - interval '1 hour'
ORDER BY _timestamp DESC

2. Filter by Domain

1
2
3
SELECT * FROM logs 
WHERE sea_domain = 'governance'
  AND sea_concept = 'PolicyEvaluation'

3. Correlate with Traces

1
2
3
SELECT * FROM logs 
WHERE trace_id = '12345...'
ORDER BY _timestamp

4. Pattern Detection