> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Analyze logs usage

> Learn about utility scores and analyzing volume for log data in Cortex XCOR.

export const MicroscopeIcon = props => <svg viewBox="0 0 24 24" {...props} className="inline-block h-5 w-5" aria-label="Microscope" style={{
  fill: "#28a561"
}}>
    <path d="M9.46,6.28L11.05,9C8.47,9.26 6.5,11.41 6.5,14A5,5 0 0,0 11.5,19C13.55,19 15.31,17.77 16.08,16H13.5V14H21.5V16H19.25C18.84,17.57 17.97,18.96 16.79,20H19.5V22H3.5V20H6.21C4.55,18.53 3.5,16.39 3.5,14C3.5,10.37 5.96,7.2 9.46,6.28M12.74,2.07L13.5,3.37L14.36,2.87L17.86,8.93L14.39,10.93L10.89,4.87L11.76,4.37L11,3.07L12.74,2.07Z" />
  </svg>;

Palo Alto Networks Cortex XCOR provides usage data and utility scores for your
log data. Usage analysis gives you insight into *patterns*, which are frequent
combinations of specific `service` and `message` fields in your log data. The
**Logs Usage** page displays the volume of data each pattern consumes, and where and
how often each pattern gets queried. The more a pattern is queried, included in
assets like dashboards, and referenced by unique users, the higher its utility score.

Utility scores are relative, and aren't mapped to any scale. For example, a utility
score of 18 is more than twice that of a utility score of 8, but isn't scored against
a maximum. Lower utility scores indicate patterns that are candidates for reducing,
augmenting, or routing log data to lower costs.

## View log patterns

View log patterns in the **Logs Usage** page to analyze which patterns have greater
utility, and those patterns you can potentially eliminate.

To view log patterns:

1. In the navigation menu, click **<Icon icon="shield-user" /> Go to Admin**
   and then select
   **<MicroscopeIcon /> Analyzers <span aria-label="and then">></span> Logs Usage**.

   The **Logs Usage** page displays all patterns found in your log data.

2. Click any pattern to view more detailed information, such as the number of queries
   that reference the pattern across [Logs Explorer](/investigate/querying/query-logs)
   and in [dashboards](/investigate/querying/dashboard-query).

   In the **Pattern Details** drawer, expand the **Executions** column to see which
   users have executed a query containing this pattern.

3. To view the underlying query for the pattern in Logs Explorer, hold the pointer
   over any pattern, and then click **View in Logs Explorer**.

## Create optimization rules

When viewing a log pattern in Cortex XCOR, you can create a log
[optimization rule](/control/shaping/shape-logs/control-logs) for the selected
pattern. This capability lets you manage log data by transforming, reshaping,
retaining, or excluding data before it's stored.

To create optimization rules:

1. In the navigation menu, click **<Icon icon="shield-user" /> Go to Admin**
   and then select
   **<MicroscopeIcon /> Analyzers <span aria-label="and then">></span> Logs Usage**.

   The **Logs Usage** page displays all patterns found in your log data.

2. Click a pattern from the list, or use the
   [query syntax](/investigate/querying/query-logs/query-syntax) to filter on
   attributes in your data, such as a particular environment or cluster name.

   Cortex XCOR returns patterns that include at least one log matched by
   the filter.

3. Press `Ctrl+Enter` (`Command+Return` on macOS) to submit the filter.

4. Click the pattern to open the **Pattern Details** drawer.

5. In the **Pattern Details** drawer, click **Create optimization rule for this pattern**.

   The **Create optimization rule** page opens with the filter for the log pattern.

   <Note>
     This rule applies to logs that match only this filter at the time the log
     data was ingested.
   </Note>

6. Review the returned data from the preview filter, and make changes as necessary.

7. Enter additional information for the specified action. See
   [Create optimization rules](/control/shaping/shape-logs/control-logs#create-optimization-rules)
   for information about each of the required fields.

8. Click **Done** to save the optimization rule definition.

9. In the **Code config** tab,
   [use the Code config tool](/tooling/gitops#use-the-code-config-tool) to apply
   the definition.


## Related topics

- [Analyze metrics usage](/investigate/analyze/usage.md)
- [Analyze data](/investigate/analyze.md)
- [Analyze consumption](/control/consumption/analyze.md)
- [Cortex XCOR concepts](/overview/concepts.md)
- [Optimize your telemetry data](/control.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.