Skip to content

Cold search in archived logs

Cold search helps you find events in archived logs. For recent logs that are still active, see hot search.

  1. Open the relevant location’s Archived Logs page.
  2. Select the Search tab.
  3. Choose a date from the available archive days.
  4. Enter your search text and start the search.

Search currently covers one day and one location at a time. To investigate several days, repeat the search for each date or export the date range to analyze the files with your own tools.

Advanced options let you choose text or regular expression matching and a response mode: summary, sample, full results or an export of matches. The number of returned or exported lines may be capped by the search settings.

Processing time depends on the volume of archives and the search you request. Follow progress and review the result when processing finishes.

If a result is partial or truncated, check the indicated reason. A processing time, file count or scanned volume limit may prevent the whole day from being scanned. The detected match total can exceed the number of returned or exported lines; a sample is not an exhaustive result.

To understand the difference between these results and complete files, see View, search or export logs.

The Export a period tab prepares the original files for your selected dates. It does not apply criteria entered in Search. Its result is available from My exports in the sidebar.

See Export logs for a date range to download several days of complete files.