<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Serverless Workspace Observability in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/serverless-workspace-observability/m-p/132046#M4045</link>
    <description>&lt;P&gt;I’m setting up &lt;STRONG&gt;observability for a Databricks &lt;EM&gt;serverless&lt;/EM&gt; workspace&lt;/STRONG&gt; on AWS and need some guidance.&lt;BR /&gt;I know we can configure &lt;STRONG&gt;audit logs&lt;/STRONG&gt; for S3 delivery, but I’m unsure if that alone is sufficient.&lt;/P&gt;&lt;P&gt;For a complete observability setup especially when integrating with CloudWatch, Splunk, or Kibana&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Do we only need to enable &lt;STRONG&gt;audit-log delivery to S3&lt;/STRONG&gt;, or&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there &lt;STRONG&gt;other logs&amp;nbsp;&lt;/STRONG&gt;that should also be routed to S3 for best practices?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If anyone has implemented observability in a serverless Databricks workspace, I’d love to hear what log sources you included and any reference docs or patterns you followed.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Sep 2025 20:01:19 GMT</pubDate>
    <dc:creator>APJESK</dc:creator>
    <dc:date>2025-09-15T20:01:19Z</dc:date>
    <item>
      <title>Serverless Workspace Observability</title>
      <link>https://community.databricks.com/t5/administration-architecture/serverless-workspace-observability/m-p/132046#M4045</link>
      <description>&lt;P&gt;I’m setting up &lt;STRONG&gt;observability for a Databricks &lt;EM&gt;serverless&lt;/EM&gt; workspace&lt;/STRONG&gt; on AWS and need some guidance.&lt;BR /&gt;I know we can configure &lt;STRONG&gt;audit logs&lt;/STRONG&gt; for S3 delivery, but I’m unsure if that alone is sufficient.&lt;/P&gt;&lt;P&gt;For a complete observability setup especially when integrating with CloudWatch, Splunk, or Kibana&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Do we only need to enable &lt;STRONG&gt;audit-log delivery to S3&lt;/STRONG&gt;, or&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there &lt;STRONG&gt;other logs&amp;nbsp;&lt;/STRONG&gt;that should also be routed to S3 for best practices?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If anyone has implemented observability in a serverless Databricks workspace, I’d love to hear what log sources you included and any reference docs or patterns you followed.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 20:01:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/serverless-workspace-observability/m-p/132046#M4045</guid>
      <dc:creator>APJESK</dc:creator>
      <dc:date>2025-09-15T20:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Serverless Workspace Observability</title>
      <link>https://community.databricks.com/t5/administration-architecture/serverless-workspace-observability/m-p/132430#M4067</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/170854"&gt;@APJESK&lt;/a&gt;&amp;nbsp;- thanks for reaching out!&amp;nbsp;&lt;/P&gt;
&lt;DIV class="RJPOee EIJn2"&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&lt;SPAN data-huuid="12364198788019133179"&gt;&lt;SPAN data-huuid="12364198788019133179"&gt;For comprehensive observability in a Databricks serverless workspace on AWS, particularly when integrating with tools like CloudWatch, Splunk, or Kibana, enabling audit log delivery to S3 is a crucial first step, but it is not the only log source to consider. As you noted, it is a good idea to&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;not rely solely on audit logs—external cloud logs help detect issues Databricks can’t see alone.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&lt;SPAN data-huuid="12364198788019133179"&gt;Logs you can route to S3:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&lt;STRONG style="color: #1b3139; font-family: inherit;"&gt;- Databricks Audit Logs (you've got these):&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Enable delivery to S3 to capture detailed platform-level activity (user actions, resources, permissions).&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&lt;STRONG style="color: #1b3139; font-family: inherit;"&gt;- AWS Cloud-Native Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Include CloudTrail, S3 access logs, and VPC flow logs for visibility into cloud-level actions like authentication, data access, and network traffic.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="rPeykc" data-hveid="CAQQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIBBAB"&gt;&lt;STRONG style="color: #1b3139; font-family: inherit;"&gt;- Job, Pipeline, and Query Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Monitor Databricks event logs (for jobs, pipelines, and SQL warehouse activity) using system tables or metrics endpoints for operational health and anomaly detection.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="RJPOee EIJn2"&gt;
&lt;DIV class="rPeykc" data-hveid="CEIQAQ" data-ved="2ahUKEwjS1da-quKPAxXhElkFHWMFNd4Qo_EKegQIQhAB"&gt;
&lt;P&gt;So, it is best practice to aggregate and monitor all these log types for comprehensive security and operational insight. You can integrate logs into SIEM or monitoring systems (CloudWatch, Splunk, Kibana) using ETL pipelines or native AWS integrations.&lt;/P&gt;
&lt;P&gt;You can find more information in the docs for&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/lakehouse-architecture/operational-excellence/best-practices#use-native-and-external-tools-for-platform-monitoring" target="_self"&gt;Operational Excellence&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I hope this is helpful!&lt;/P&gt;
&lt;P&gt;Sarah&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Sep 2025 12:50:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/serverless-workspace-observability/m-p/132430#M4067</guid>
      <dc:creator>sarahbhord</dc:creator>
      <dc:date>2025-09-18T12:50:17Z</dc:date>
    </item>
  </channel>
</rss>

