Fractals
Performance
CPU Usage
Query Duration
Memory per Query
Running Queries
0No active queries
Recent Queries
0No recent queries
Settings
System Status
User Management
Add New User
Tenant Admins have full system access. Users can query and comment. Assign fractal-level permissions (viewer/analyst/admin) separately via fractal management.
A one-time invite link will be generated for the user to set their password.
Groups
Groups let you assign fractal permissions to multiple users at once.
Create New Group
Members
System Limits
Maximum time an alert query can run. Alerts that exceed this are automatically disabled to protect system health.
Maximum time a user search query can run before being cancelled.
Context Links
Context links add lookup icons next to matching field values in the log detail panel. When clicked, they open external services like VirusTotal or AlienVault OTX.
Create Context Link
Comma-separated field names (case-insensitive)
Only show the link when the field value matches this pattern
Use <ATTR_VALUE> as placeholder for the field value
Normalizers
Normalizers transform field names during log ingestion. Attach them to ingest tokens to standardize field names across log sources.
Create Normalizer
Map source field names to a target name. Sources are matched after transforms are applied.
Configure which fields to check for timestamps and their Go time format. If no match is found, ingest time is used.
Edit Source Fields
One source field per line.