Logs Explorer

The Logs Explorer is where you search, filter, and read individual log lines. This page walks through using the screen end to end; for the exact search-bar syntax see Logs Search Syntax, and for how the pieces fit together architecturally see Logs Explorer Architecture.

Access the Explorer

Click Logs in the top navigation. The Explorer opens on the Logs view — a live row-per-line table for whatever time range and filters are currently active.

Logs table

Above the table, a histogram plots log volume over the selected time range, broken down by level (color-coded, with a legend showing the count per level). Each row below it is one log line:

Column What it shows Timestamp When the log was recorded.

Level

A color-coded severity badge (INFO, WARN, ERROR, DEBUG, TRACE, and so on).

Source

The service or component that produced the log.

Total docs (top right of the histogram) is how many records exist in the current time range before any filter; Scanned is how many the query actually had to read. Use COLUMNS to add or remove columns, and the download icon to export the current result set. Click any row to open its detail pane.

The left sidebar narrows the table without typing a query:

  • level and source — checkbox lists with live counts, always shown first.

  • LABELS — three collapsible groups: Cloud (availability zone, provider, region, and so on), Kubernetes (cluster, namespace, pod, container), and Additional (every other label present on your data, so this list varies by environment).

  • FACETS — auto-extracted and custom fields, starting with a Recents group. Manage the full catalog of known facets — favorite groups, folders — from Logs in the top navigation → Facets.

Checking a value here and typing the equivalent filter into the search bar are the same action; each one updates the other. See Facets, labels, and tags — and why the distinction matters for search for what makes a field a facet versus a label.

Type a query directly, or build one by checking sidebar values — see Logs Search Syntax for the complete operator reference (term search, substring/regex match, comparisons, facet operators, and how to combine them). The bar has two modes:

Builder

The default — autocompletes field names as you type and shows an operator cheat-sheet.

Code

A raw query editor with a Run button, for queries more complex than the Builder’s autocomplete covers.

Time range

The time range control (top right) accepts quick ranges (Last 5/15/30 minutes, Last 1/3/6/12/24 hours, Last 2/7 days) or an absolute From/To range using relative expressions like now-15m. A timezone selector controls how absolute times are displayed. The same control is where you switch to Live tail.

Switching views

The tab strip above the search bar (Logs · Timeseries · Table · Top List · Pie Chart · Stat · Fingerprints) re-renders the same filtered result set as a different shape — it doesn’t change what you searched for. Logs is the raw table described above; Timeseries, Table, Top List, Pie Chart, and Stat are aggregation views built with a shared query builder — see Logs Analytics. Fingerprints clusters the results by message template — see Fingerprints view.

Detail pane

Click any row in the Logs view to open a detail pane for that specific line:

Message

The raw log text, with a Show in context control to see the surrounding lines from the same source without losing your place.

Fingerprint

The line’s template, with the variable parts of the message replaced by placeholders — the same pattern used to group it in the Fingerprints view.

Facets

Fields Kloudfuse extracted from this message specifically.

Cloud / Kubernetes

The structured collection-time labels for this log — cloud metadata and Kubernetes pod/namespace/cluster identity.

Additional labels

Every other label attached to the line.

A search box at the top of the pane filters a long Facets/Labels list by name; use the arrows next to the row counter (for example 1 / 200) to step through adjacent results without closing the pane.

Live tail

Open Live tail from the time range control to replace the fixed range with a streaming feed — new matching logs append to the top as they arrive. A pause control freezes the stream in place (without losing your filter) so you can read a burst of activity without it scrolling away. Live tail uses the same search bar and sidebar filters as every other view; only the time dimension changes.