Skip to Main Content
InterSystems Ideas

Have an idea, suggestion, or something that doesn’t work as expected in InterSystems products or services? Share it here on the InterSystems Ideas Portal.

The Ideas Portal is where community members can propose improvements, report bugs, and help influence the product roadmap across InterSystems products and the overall developer experience. 22% of submitted ideas are implemented by InterSystems or members of the Developer Community.

💡 Ideas and bugs are both welcome, no matter how big or small. You can submit feature requests, usability improvements, workflow suggestions, and bug reports. Whether you’re an experienced expert or just getting started, your fresh perspective is valuable.

🛠️ About bugs and fixes. If you have access to InterSystems WRC, please submit bugs there for immediate action. Bug reports submitted through the Ideas Portal are reviewed and tracked, but do not guarantee immediate resolution.

Start by sharing what could be better - the community and our teams will help take it from there.

Status Community Opportunity
Created by Timothy Leavitt
Created on Oct 5, 2021

IRIS Audit Database: Finding Needles in the Haystack and Seeing the Forest for the Trees

Motivating question: Can you look at [IRIS-based internal application] and see if anything unusual happened [while there was possibly an intruder on the network]?

In theory, the IRIS database would help to provide an answer. In practice, this is a challenging data problem in two ways. First, there are so many individual events that combing through them one at a time looking for anything suspicious (by virtue of being different from what's usually there) is tedious and error-prone. On the other hand, "unusual" activity might also include changes in volume of traffic along certain dimensions, and there's no good way to see that from a list of events as is currently available in the Management Portal.

The idea would be to use ML to identify anomalous individual events from a near real-time stream of events from IRIS audit databases (possibly across multiple instances), as well as anomalous aggregates along automatically-discovered dimensions and time buckets.

  • ADMIN RESPONSE
    Feb 13, 2025

    Thank you for submitting the idea. The status has been changed to "Community Opportunity".

    Stay tuned!

  • Benjamin De Boe
    Feb 13, 2025

    This is a great idea, but not something we'll likely add to the near-term roadmap. Now that we've released OpenTelemetry support for metrics, logs, and traces, there should be a lot of opportunity for leveraging existing log mining solutions to accomplish this, hence marking as community opportunity.