Skip to content

Log Explorer


After log data is collected into the system, you can view all log data reported in the current workspace under Logs > Explorer.

Note

If the role of the currently logged-in account has set Logs > Data Access to "Only show rules related to me", the queried log content will be affected accordingly.

View Modes

To meet viewing and analysis needs in different scenarios, the Explorer supports multiple display modes:

List

Stacked List

Chart

List

Each field of a log occupies a column, fully displaying all field content, allowing you to view the detailed information of each log intuitively.

In text or expanded content that supports fragment operations, you can click Chinese or mixed Chinese-English fragments to filter, inverse filter, or copy. Plain text is separated by whitespace and common punctuation; identifiers, paths, IPs, times, URLs, and similar content are recognized according to their own rules. See Selecting Log Fragments for details.

Stacked List

Except for the time field (time), all other fields are merged into a single column and displayed in multiple lines within the cell:

In stacked mode, you can perform the illustrated operations on specific fields:

The Original Log in the stacked list and other text values that support fragment operations also support selecting Chinese and mixed Chinese-English fragments for filtering or copying. The selection ranges may differ between hover word selection in the list, JSON display, and the log detail body; follow the current selection range when operating.

If a field's content is in JSON structure, the stacked list supports hierarchical expansion for viewing. You can configure the default expansion mode for JSON fields in Preferences, including no expansion or full expansion, to quickly locate fields in multi-level structures.

Chart

Filters data under a by condition based on count, last, first, and count_distinct aggregation modes:

  • Top List

  • Time Series

  • Pie Chart

  • Treemap

  • Grouped Table

View Switching and Configuration Retention

After configuring the analysis dimension, aggregation method, Top/Bottom, and return count in the Top List, switching to List or Stacked List does not clear the analysis configuration. When you return to the Top List, the system restores the last configuration.

  • If the current log index, time range, query mode, search conditions, and quick filter conditions remain unchanged, existing query results are reused;
  • If the query context changes, the original analysis configuration is retained, and the query is re-run against the new context;
  • When advanced query is combined with page analysis configuration, the BY condition in the query statement is ignored, and the page analysis dimension takes precedence.

Data Display

All Logs

By default, normal log indexes in the current workspace are queried; cloned indexes are not automatically included. To query cloned data, explicitly select the corresponding cloned index in the index list on the left.

Browse Mode

The log data list supports two browse modes: paginated browsing and scroll loading. You can select the corresponding mode in Preferences.

Use page numbers to switch between different ranges of log data, suitable for browsing and locating within large volumes of logs.

With paginated browsing, you can perform the following operations:

  • Switch to the previous or next page;
  • Enter or select a target page number;
  • Adjust the number of items displayed per page.

Keeps the original continuous browsing mode. When you scroll to the bottom of the current data list, the system continues loading subsequent logs.

Switching browse modes does not change the current workspace, log index, time range, search conditions, or quick filter conditions.

Wrap

In the stacked list, if a single log contains many data elements, click the "Wrap" button to display the message part of the log independently.

Pattern

The Log Explorer provides an efficient clustering capability that performs similarity analysis on logs based on the message field and automatically displays the most recent 50 logs. You can also customize the clustering fields. After selecting a time range in the time widget, the system analyzes 10,000 logs within that period and aggregates similar entries.

In the Pattern list, you can manage the data with the following operations:

  • Click & to sort by document count (descending by default);

  • Click to choose to display 1 line, 3 lines, 10 lines, or all content;

  • Click to export all clustered log data.

Feedback

Is this page helpful?