Log Explorer
Security Monitoring is now available Security Monitoring is now available

Log Explorer

Overview

The Logs Explorer is your home base for troubleshooting and exploration:

Explore view with comments

Different views offer different types of insights from your log data, matching a search query.

Live Tail

The Live Tail displays logs as they flow into Datadog. Live Tail logs do not persist, but the view provides visibility on all logs, whether they are indexed or not. Find out more in the Log Live Tail section.

Log Livetail

Log Lists

The Log List displays indexed logs and offers privileged tools to navigate individual results. Find out more in the Log List section.

Log Patterns

The Log Patterns automatically aggregate indexed logs into a handful of groups with similar structures. Find out more in the Log Patterns section.

Log Analytics

The Log Analytics graph log queries and see maximums, averages, percentiles, unique counts, and more. Follow the log graphing guide to learn more about all the graphing options.

The Log Side Panel

Datadog displays individual logs following this general side-panel layout:

Log structured information

  • The upper part of the panel displays general context information.
  • The lower part of the panel displays the actual content of the log.

Context refers to the infrastructure and application context in which the log has been generated. Information is gathered from tags—whether automatically attached (host name, container name, log file name, serverless function name, etc.)—or added through custom tags (team in charge, environment, application version, etc.) on the log by the Datadog Agent or Log Forwarder.

Content refers to the log itself. This includes the log message, as well as all structured information extracted and enriched from the logs through Log Pipelines. For logs generated by common components of a technical stack, parsing and enriching comes out-of-the-box:

  • For file log collection, make sure you properly set up the source field, which triggers file log collection. See Datadog’s 100+ Log Integrations for reference.
  • For container log collection, use Autodiscovery.

Some standard fields—for instance, error.stack, http.method, or duration—have specific enhanced displays in the Log Panel for better readability. Make sure you extract corresponding information from your logs and remap your attributes with standard attribute remappers.

A hub to other data sources

Correlation with Infrastructure (Host, Container, Serverless) data

The View in context button updates the search request in order to show you the log lines dated just before and after a selected log—even if they don’t match your filter. This context is different according to the situation, as Datadog uses the Hostname, Service, filename, and container_id attributes, along with tags, in order find the appropriate context for your logs.

Click on the Metrics Tab and access underlying infrastructure metrics in a 30 minutes timeframe around the log.

Interact with Host in the upper reserved attributes section, the related host dashboard or network page. Interact with Container sections to jump to the container page scoped with the underlying parameters.

Hub to Infra

In case logs comes from a serverless source, the Host Section is replaced with a Serverless section that links jump to the corresponding serverless page.

Correlation with APM data

Make sure you enable trace injection in logs and follow our Unified Service Tagging best practices to benefit from all the capabilities of Logs and APM correlation.

Click on the APM Tab and see the log in the context of its whole trace, with upstream and downstream services running. Deep dive in the APM data and the trace in APM.

Interact with the Service section to refocus the search in the log explorer and see all other logs from the same trace.

Hub to APM

Configure your troubleshooting context

Interact with the attributes names and values in the lower JSON section to:

  • Add or remove a column from the logs table.
  • Append the search request with specific values (include or exclude)
Side Panel context
  • Build or edit a facet or measure from an attribute. See Log Facets.
Side Panel Facets

Share a log

Use the Share button to share the log opened in side panel to other contexts.

  • Copy to clipboard or Ctrl+C / Cmd+C copies the log JSON to your clipboard.
  • Share Event shares the log (along with the underlying view) with teammates through email, Slack, and more. See all Datadog notification integrations available.

Troubleshooting Context

Search Filter

Build up a context to explore your logs in your log explorer view. First, select the proper time range. Then, use the search bar to filter your Logstream and Log Analytics.

Time Range

The time range feature allows you to display logs in the Logstream or Log Analytics within a given time period. It appears directly under the search bar as a timeline. The timeline can be displayed or wrapped up with the Show timeline check box in the Logstream option panel.

Quickly change the time range by selecting a preset range from the dropdown (or entering a custom time frame):

Search

Use facets, measures, tags, or even free text search to filter your Logstream and Log Analytics with dedicated context. The search bar and URL automatically reflect your selections.

Follow the guide to search your logs for a detailed explanation of all the Log Explorer search features, including use of wildcards and queries of numerical values.

Saved views

Use saved views to automatically configure your log explorer with a preselected set of facets, measures, searches, time ranges, and visualizations. Check the dedicated saved views documentation to learn more.

Further Reading