**Observability** is the console view of OpenTelemetry logs, metrics, and traces already ingested for the selected environment. It sits in the sidebar after [Audit](/docs/console/audit). Application telemetry is not the audit log: Audit records identity events, Observability records what your services exported.

The top bar time range is stored as `&rt=` (the same tokens as Audit and the Dashboard). Saved filters and Filters sit with the module.

## Overview

`?tab=overview` summarizes the current window.

| Counter | Meaning |
|---------|---------|
| **Logs** | Log records in the window. |
| **Metrics** | Metric data points in the window. |
| **Traces** | Distinct traces in the window. |
| **Services** | Distinct service names in the window. |

A timeline under the counters plots logs, metrics, and traces across the window. Changing the time range recomputes both.

When the window is empty the page says **No telemetry in this time range** and points at the [OpenTelemetry docs](/docs/opentelemetry) and the Settings tab.

## Logs

`?tab=logs` is a log explorer: volume for the window, facets, and a table.

The query box accepts field tokens plus free text. Example: `severity:ERROR service:authdog-identity signup`.

| Token | Narrows by |
|-------|------------|
| `severity:` | Severity text. |
| `service:` | Service name. |
| `scope:` | Instrumentation scope. |
| `trace:` | One trace id. |

Anything that is not a token is searched as message text. Quote a value that contains a space.

Columns are **Time**, **Severity**, **Service**, **Message**, and **Trace**. Opening a row shows attributes and resource attributes. A trace id jumps to the Traces tab for that id.

## Metrics

`?tab=metrics` lists data points for the window.

Columns are **Name**, **Type**, **Unit**, **Value**, and **Service**. Selecting a metric name charts that series over the current range. Opening a row shows the point detail.

## Traces

`?tab=traces` groups spans into traces. Each group shows the root span, service, duration, and status. Opening a trace lists its spans (**Span**, **Service**, **Duration**, **Status**) and a parent/child tree. From a focused trace you can open the matching logs.

## Settings

`?tab=settings` is where ingest is configured for this environment.

- **Ingest endpoints** are OTLP/HTTP JSON. Collectors append `/v1/logs`, `/v1/metrics`, and `/v1/traces` to the OTLP base. JSON only.
- Authenticate with `Authorization: Bearer` and an environment API secret (`adenv_…`). The secret's scope is `otel:ingest`. Tenant and environment come from that secret, not from a resource attribute you send.
- **Create API key** mints the secret. The full value is shown once. Copy it then. It is not shown again.

## Related

| Read | To learn how to |
|------|-----------------|
| [OpenTelemetry](/docs/opentelemetry) | Send OTLP/HTTP JSON from a collector |
| [Vault](/docs/console/vault) | See environment API secrets |
| [Audit](/docs/console/audit) | Search identity events, which are not these signals |
| [Lidar](/docs/console/lidar) | Triage security detections |
