Observability is the console view of OpenTelemetry logs, metrics, and traces already ingested for the selected environment. It sits in the sidebar after Audit. Application telemetry is not the audit log: Audit records identity events, Observability records what your services exported.
The top bar time range is stored as &rt= (the same tokens as Audit and the Dashboard). Saved filters and Filters sit with the module.
Overview
?tab=overview summarizes the current window.
| Counter | Meaning |
|---|---|
| Logs | Log records in the window. |
| Metrics | Metric data points in the window. |
| Traces | Distinct traces in the window. |
| Services | Distinct service names in the window. |
A timeline under the counters plots logs, metrics, and traces across the window. Changing the time range recomputes both.
When the window is empty the page says No telemetry in this time range and points at the OpenTelemetry docs and the Settings tab.
Logs
?tab=logs is a log explorer: volume for the window, facets, and a table.
The query box accepts field tokens plus free text. Example: severity:ERROR service:authdog-identity signup.
| Token | Narrows by |
|---|---|
severity: |
Severity text. |
service: |
Service name. |
scope: |
Instrumentation scope. |
trace: |
One trace id. |
Anything that is not a token is searched as message text. Quote a value that contains a space.
Columns are Time, Severity, Service, Message, and Trace. Opening a row shows attributes and resource attributes. A trace id jumps to the Traces tab for that id.
Metrics
?tab=metrics lists data points for the window.
Columns are Name, Type, Unit, Value, and Service. Selecting a metric name charts that series over the current range. Opening a row shows the point detail.
Traces
?tab=traces groups spans into traces. Each group shows the root span, service, duration, and status. Opening a trace lists its spans (Span, Service, Duration, Status) and a parent/child tree. From a focused trace you can open the matching logs.
Settings
?tab=settings is where ingest is configured for this environment.
- Ingest endpoints are OTLP/HTTP JSON. Collectors append
/v1/logs,/v1/metrics, and/v1/tracesto the OTLP base. JSON only. - Authenticate with
Authorization: Bearerand an environment API secret (adenv_…). The secret's scope isotel:ingest. Tenant and environment come from that secret, not from a resource attribute you send. - Create API key mints the secret. The full value is shown once. Copy it then. It is not shown again.
Related
| Read | To learn how to |
|---|---|
| OpenTelemetry | Send OTLP/HTTP JSON from a collector |
| Vault | See environment API secrets |
| Audit | Search identity events, which are not these signals |
| Lidar | Triage security detections |