Logs Explorer
The Logs Explorer is where you search, filter, and read individual log lines. This page walks through using the screen end to end; for the exact search-bar syntax see Logs Search Syntax, and for how the pieces fit together architecturally see Logs Explorer Architecture.
Access the Explorer
Click Logs in the top navigation. The Explorer opens on the Logs view — a live row-per-line table for whatever time range and filters are currently active.
Logs table
Above the table, a histogram plots log volume over the selected time range, broken down by level (color-coded, with a legend showing the count per level). Each row below it is one log line:
| Column | What it shows | Timestamp | When the log was recorded. |
|---|---|---|---|
Level |
A color-coded severity badge ( |
Source |
The service or component that produced the log. |
Total docs (top right of the histogram) is how many records exist in the current time range before any filter; Scanned is how many the query actually had to read. Use COLUMNS to add or remove columns, and the download icon to export the current result set. Click any row to open its detail pane.
Sidebar: tags and labels
The left sidebar narrows the table without typing a query:
-
level and source — checkbox lists with live counts, always shown first.
-
LABELS — three collapsible groups: Cloud (availability zone, provider, region, and so on), Kubernetes (cluster, namespace, pod, container), and Additional (every other label present on your data, so this list varies by environment).
-
FACETS — auto-extracted and custom fields, starting with a Recents group. Manage the full catalog of known facets — favorite groups, folders — from Logs in the top navigation → Facets.
Checking a value here and typing the equivalent filter into the search bar are the same action; each one updates the other. See Facets, labels, and tags — and why the distinction matters for search for what makes a field a facet versus a label.
Search bar
Type a query directly, or build one by checking sidebar values — see Logs Search Syntax for the complete operator reference (term search, substring/regex match, comparisons, facet operators, and how to combine them). The bar has two modes:
- Builder
-
The default — autocompletes field names as you type and shows an operator cheat-sheet.
- Code
-
A raw query editor with a Run button, for queries more complex than the Builder’s autocomplete covers.
Time range
The time range control (top right) accepts quick ranges (Last 5/15/30 minutes, Last 1/3/6/12/24 hours, Last 2/7 days) or an absolute From/To range using relative expressions like now-15m. A timezone selector controls how absolute times are displayed. The same control is where you switch to Live tail.
Switching views
The tab strip above the search bar (Logs · Timeseries · Table · Top List · Pie Chart · Stat · Fingerprints) re-renders the same filtered result set as a different shape — it doesn’t change what you searched for. Logs is the raw table described above; Timeseries, Table, Top List, Pie Chart, and Stat are aggregation views built with a shared query builder — see Logs Analytics. Fingerprints clusters the results by message template — see Fingerprints view.
Detail pane
Click any row in the Logs view to open a detail pane for that specific line:
- Message
-
The raw log text, with a Show in context control to see the surrounding lines from the same source without losing your place.
- Fingerprint
-
The line’s template, with the variable parts of the message replaced by placeholders — the same pattern used to group it in the Fingerprints view.
- Facets
-
Fields Kloudfuse extracted from this message specifically.
- Cloud / Kubernetes
-
The structured collection-time labels for this log — cloud metadata and Kubernetes pod/namespace/cluster identity.
- Additional labels
-
Every other label attached to the line.
A search box at the top of the pane filters a long Facets/Labels list by name; use the arrows next to the row counter (for example 1 / 200) to step through adjacent results without closing the pane.
Live tail
Open Live tail from the time range control to replace the fixed range with a streaming feed — new matching logs append to the top as they arrive. A pause control freezes the stream in place (without losing your filter) so you can read a burst of activity without it scrolling away. Live tail uses the same search bar and sidebar filters as every other view; only the time dimension changes.