Scheduled Views

A scheduled view is a pre-aggregated dataset Kloudfuse generates by running a FuseQL query on a fixed interval (every minute by default) and storing the result separately from the raw logs it was computed from. Querying the view instead of running the same aggregation against raw logs every time is faster, uses far less storage, and can outlive your log retention window since the aggregated result is retained on its own schedule.

Rules

  • The query must use an aggregate operator.

  • Always aggregate by a timeslice operator — without one, Kloudfuse uses evaluation time instead.

  • You cannot create a scheduled view from another scheduled view.

  • You cannot use the cat operator in a scheduled view query.

  • A view name must start with a letter and contain only letters, numbers, $, and _ — no spaces.

Access Scheduled Views

Click Logs in the top navigation, then Scheduled Views in the dropdown.

Table columns

Column What it shows

View name

The unique name you assigned. Query it with _view=<name>.

Folder

Where the view is organized — used to manage access when RBAC is enabled.

Status

RUNNING (actively evaluating), Catching Up (processing historical data to reach current time), Paused, or Stopped (progress reset via the API — see Scheduled Views API Reference).

Query

The FuseQL query evaluated at each interval.

Interval

How often the view evaluates — 1m by default.

Start Time

When the view began processing data — you can backdate this at creation to backfill history.

Lag

How far behind current time the view is — lower is more current.

Retention

How long the view’s own pre-aggregated data is kept, independent of your raw log retention — 14 DAYS by default.

Last evaluated / Next evaluation / Created at

Timestamp columns hidden by default; add them from Columns.

Hover a row for its actions: Copy query, View Logs (open the view’s results in the Logs Explorer), Change folder, Pause/Resume, and Delete. Select multiple rows with the checkboxes to Pause, Resume, Move to folder, or Delete them together.

Create a scheduled view

From the Scheduled Views page, click Create scheduled view and specify:

View Name

Must start with a letter; letters, numbers, $, and _ only, no spaces.

Folder (optional)

Organizes the view and scopes RBAC permissions; create a new one from the folder icon if needed.

Start Time

When the view should begin processing — set this in the past to backfill historical data. Cannot be in the future.

FuseQL Query

The aggregation that defines the view, for example:

* | timeslice 1m | count by _timeslice, source
none

Click Create. The view appears in the list and starts processing from the specified start time.

View a scheduled view’s results

Hover a view in the list and click View Logs to open its results in the Logs Explorer, pre-filtered to _view=<name>. The default time interval is the preceding 5 minutes — adjust it with the time picker like any other Explorer query.

Pause, resume, and delete

Pausing stops a view from processing new data without deleting it; resuming restarts it and the status shows Catching Up while it processes the backlog. Deleting a view stops it permanently — you can still query its already-computed data until the view’s own retention period expires, but no new data will be added. All three actions are available per-row (hover → icon) or in bulk (checkboxes → toolbar button → confirm).

Organize with folders

Move a view to a folder from its row’s Change folder action, or select multiple views and use Move to folder in bulk. Folders scope access when RBAC is enabled.

Query a scheduled view

Prefix a FuseQL query with the view name (no quotes) to query its pre-aggregated data instead of raw logs:

| _view=<view_name>
none

Query more than one view at once by OR-ing view names together:

_view=<view1> or _view=<view2> or _view=<view3> ...
none

Example: log volume by source over time

Tracking log volume by source for capacity planning directly against raw logs looks like this:

*
| timeslice 1h
| count by _timeslice, source
none

That’s slow over a wide time range, and bounded by your log retention. Define a scheduled view that pre-aggregates the same thing every minute instead:

*
| timeslice 1m
| count by _timeslice, source
none

Then query the view — fast, and not bounded by log retention:

_view=logVolumeBySource
| timeslice 1h
| sum(_count) by _timeslice, source
none

Managing scheduled views programmatically

Everything on this page — listing, creating, editing, pausing, resuming, stopping, and deleting a scheduled view — is also available over the GraphQL API, including one operation not exposed in the UI: stopScheduledView, which resets a view’s progress rather than just pausing it. See Scheduled Views API Reference for the full operation reference, parameters, and example requests.