After configuring log structuring parsing and indexing, you can enter statements to search for log events that contain specific keywords. You can also search for log data by time range to locate events and issues that occur in a specified period.
Search statements are used to define the filter criteria for log query and obtain the logs that meet the criteria. A search statement may be a keyword, a value, a value range, a space, an asterisk (*), or the like. If it is a space or asterisk (*), no filtering criteria is specified. For more information, see Using Search Syntax.
There are three types of time range: relative time from now, relative time from last, and specified time. Select a time range as required.
If the field you click already exists in the search box, it will be replaced by this newly added one. If the field is added for the first time, fields in the search box are searched using the AND operator.
The log highlighting mechanism works as follows: Once a log meets the search criteria, the system identifies the log's strings that match these criteria and applies highlight tags to the matching sections, making them visibly highlighted on the page. However, when the query criteria are complex, particularly involving OR relationships, content that does not actually match the criteria may also be highlighted on the page.
You can perform the following operations on a new layout:
to edit the layout's display name.
and then Yes to delete the layout.
Deleted layouts cannot be restored. Exercise caution when performing this operation.
In the log content display area, you can share and download logs, and view context. For details, see Table 1.
Operation | Description |
|---|---|
Interactive search | Click Interactive Mode in front of the search box. In the displayed Interactive Search dialog box, select fields for index configuration, set the filtering mode, and add associations and groups. After the setting is complete, you can preview the search syntax. |
Creating a quick search | Click |
Sharing logs | Click |
Refreshing logs | You can click
|
Copying logs | Click |
Viewing context of a log | Click You can select Simple View to view the log context. You can also download the context. |
More operations | Click
|
Unfold/Fold | Click |
Downloading logs | Click Direct Download: Download log files to the local PC. Up to 5,000 logs can be downloaded at a time. Select .csv or .txt from the drop-down list and click Download to export logs to the local PC. NOTE:
|
Hiding/Expanding all | Click |
JSON | Move the cursor over Formatting is enabled by default. The default number of expanded levels is 2.
|
Collapse configuration | Move the cursor over If the number of characters in a log exceeds the maximum, the extra characters will be hidden. Click Expand to view all. Logs are collapsed by default, with a default character limit of 400. |
Log time display | Move the cursor over |
Virtual Scrolling | Move the cursor over
|
Invisible fields ( | This list displays the invisible fields configured in the layout settings.
|