---
title: Search BYOC Logs
description: Learn how to query and analyze your BYOC Logs data in Datadog
breadcrumbs: Docs > BYOC Logs > Operate BYOC Logs > Search BYOC Logs
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Search BYOC Logs

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Explore BYOC Logs in Log Explorer{% #explore-byoc-logs-in-log-explorer %}

BYOC (Bring Your Own Cloud) Logs index names follow this format:

```text
byoc--<CLUSTER_NAME>--<INDEX_NAME>
```

To search your BYOC Logs indexes:

1. Go to the [Datadog Log Explorer](https://app.datadoghq.com/logs).
1. On the left facet panel, under BYOC INDEXES, select one or more indexes to search.

You can select a specific index to narrow your search, or select all indexes in a cluster to search across them.

You can also search a specific index from the search bar by using its qualified name. For example, to search the `application` index in `cluster-1`:

```text
index:byoc--cluster-1--application
```

## Search across BYOC Logs clusters{% #search-across-byoc-logs-clusters %}

Use Log Explorer, dashboards, log monitors, or the public Logs API to search across multiple BYOC Logs clusters with a single query. Results from the selected clusters are combined.

### Use Log Explorer{% #use-log-explorer %}

In the [Log Explorer](https://app.datadoghq.com/logs) search bar, prefix each cluster name with `byoc--`. Group the names in parentheses after `index:`, separated by `OR`. For example:

```text
index:(byoc--cluster-1 OR byoc--cluster-2)
```

Replace `cluster-1` and `cluster-2` with your BYOC Logs cluster names.

Matching logs from the selected clusters appear in a single list. Changes to search filters and the time range apply to all selected clusters.

### Use dashboards and log monitors{% #use-dashboards-and-log-monitors %}

Enter a cross-cluster query, such as `index:(byoc--cluster-1 OR byoc--cluster-2)`, in the log search query of a [dashboard widget](https://docs.datadoghq.com/dashboards/widgets.md) or [log monitor](https://docs.datadoghq.com/monitors/types/log.md).

- In dashboards, visualize logs across multiple BYOC Logs clusters, such as tracking a service's errors across regions.
- In log monitors, alert on conditions that span multiple BYOC Logs clusters.

### Use the Logs API{% #use-the-logs-api %}

Send a request to the [Search logs endpoint](https://docs.datadoghq.com/api/latest/logs.md#search-logs) (`POST /api/v2/logs/events/search`). Set `filter.query` to a query that specifies multiple BYOC Logs clusters. For example:

```json
{
  "filter": {
    "from": "now-15m",
    "to": "now",
    "query": "index:(byoc--cluster-1 OR byoc--cluster-2)"
  }
}
```

## Search limitations{% #search-limitations %}

You cannot query BYOC Logs indexes alongside other Datadog log indexes. Additionally, Flex Logs is not supported with BYOC Logs.

## Further reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Ingest logs to BYOC Logs](https://docs.datadoghq.com/byoc-logs/ingest.md)
- [Troubleshooting BYOC Logs](https://docs.datadoghq.com/byoc-logs/operate/troubleshooting.md)
- [Log Search Syntax](https://docs.datadoghq.com/logs/explorer/search_syntax.md)
