• /
  • Log in

Organize data with partitions

Data partitions are a way to group or organize log data for faster and more efficient querying. When a query targets a single partition, New Relic Logs:

  • Scans less unrelated data.
  • Returns results faster.

Accounts can have multiple partitions, and multiple partitions can be queried at the same time.

Data partitions also allow data to be mapped to an alternative, or “secondary” namespace with a fixed 30-day retention. This is useful for maintaining compliance with privacy-centric regulations and standards like the General Data Protection Regulation (GDPR).

Plan your partition

Before you start creating partitions, make sure you have the right permissions and a partition plan.

Important

Logs are routed to partitions during the ingestion process, before data is written to NRDB. Partition rules will not affect logs that were ingested before the rule was created.

Required roles and permissions

Users require an Admin role to create and modify partition rules.

Sizing and organizing a partition

You can gain significant performance improvements with proper use of data partitions. Organizing your data into discrete partitions enables you to query them separately or all together. The goals of partitioning your data should be:

  • Create data partitions that align with concepts in your environment or organization that are static or change infrequently (for example, by business unit, team, environment, service, etc.).
  • Ensure each partition remains below 1 TB of daily ingest for optimal performance.

Having more partitions allows for more targeted searches, but creating too many partitions can make logs hard to find and increase administrative overhead. Finding the right balance is important. We support 100 partitions maximum per account, but the optimal number for most accounts is 10 to 15 partitions.

Choosing a namespace

A partition’s namespace determines its retention period. We offer two retention options:

  • Standard: The account’s default retention determined by your New Relic subscription. This is the maximum retention period available in your account and is the namespace you'll select for most of your partitions.
  • Secondary: 30-day retention. All logs sent to a partition that's a member of the Secondary namespace will be purged on a rolling basis 30 days after having been ingested.

Secondary retention is not a cost control mechanism; data is billed on ingest.

Create partition rules

Log data partitions UI

one.newrelic.com > Logs: From the left nav in the Logs UI, select Data partitions, then create a Log_ partition name with the retention namespace, optional description, and matching criteria.

To create a new partition rule:

  1. Go to one.newrelic.com > Logs.
  2. From Manage Data on the left nav of the Logs UI, click Data partitions, then click Create partition rule.
  3. Define a Partition name as an alphanumeric string that begins with Log_.
  4. Add an optional description.
  5. Select the retention namespace for the partition.
  6. Set your rule's Matching criteria: Select EQUALS to target logs that match your criteria exactly, or select LIKE to apply a fuzzy match.
  7. Click the Enable Rule slider, and click Create.

Log data partitions rule

To view a list of data partitions: From Manage Data on the left nav of the Logs UI, click Data partitions.

The default partition for all Logs accounts is Log. Any log that is not affected by a partition rule will be stored in the Log partition by default.

You can query multiple partitions simultaneously. For best performance, select the smallest number of partitions possible.

To search data partitions:

  1. From Views and Attributes on the left nav of the Logs UI, click Select partitions.
  2. Click one or more partitions you want to query, or search for a partition name.
  3. Click Query logs to search your selected partitions.

For more help

If you need more help, check out these support and learning resources:

Create issueEdit page
Copyright © 2021 New Relic Inc.