Authdog

Observability

Last updated Oct 4, 2026
View as Markdown

Observability is the console view of OpenTelemetry logs, metrics, and traces already ingested for the selected environment. It sits in the sidebar after Audit. Application telemetry is not the audit log: Audit records identity events, Observability records what your services exported.

The top bar time range is stored as &rt= (the same tokens as Audit and the Dashboard). Saved filters and Filters sit with the module.

Overview

?tab=overview summarizes the current window.

Counter Meaning
Logs Log records in the window.
Metrics Metric data points in the window.
Traces Distinct traces in the window.
Services Distinct service names in the window.

A timeline under the counters plots logs, metrics, and traces across the window. Changing the time range recomputes both.

When the window is empty the page says No telemetry in this time range and points at the OpenTelemetry docs and the Settings tab.

Logs

?tab=logs is a log explorer: volume for the window, facets, and a table.

The query box accepts field tokens plus free text. Example: severity:ERROR service:authdog-identity signup.

Token Narrows by
severity: Severity text.
service: Service name.
scope: Instrumentation scope.
trace: One trace id.

Anything that is not a token is searched as message text. Quote a value that contains a space.

Columns are Time, Severity, Service, Message, and Trace. Opening a row shows attributes and resource attributes. A trace id jumps to the Traces tab for that id.

Metrics

?tab=metrics lists data points for the window.

Columns are Name, Type, Unit, Value, and Service. Selecting a metric name charts that series over the current range. Opening a row shows the point detail.

Traces

?tab=traces groups spans into traces. Each group shows the root span, service, duration, and status. Opening a trace lists its spans (Span, Service, Duration, Status) and a parent/child tree. From a focused trace you can open the matching logs.

Settings

?tab=settings is where ingest is configured for this environment.

  • Ingest endpoints are OTLP/HTTP JSON. Collectors append /v1/logs, /v1/metrics, and /v1/traces to the OTLP base. JSON only.
  • Authenticate with Authorization: Bearer and an environment API secret (adenv_…). The secret's scope is otel:ingest. Tenant and environment come from that secret, not from a resource attribute you send.
  • Create API key mints the secret. The full value is shown once. Copy it then. It is not shown again.
Read To learn how to
OpenTelemetry Send OTLP/HTTP JSON from a collector
Vault See environment API secrets
Audit Search identity events, which are not these signals
Lidar Triage security detections