View, search or export logs
| Your goal | Where to go | What you get |
|---|---|---|
| Check whether logs are arriving now | Live logs on the location page | Messages received in the displayed stream. |
| Find an event from the current day | Hot search | Matches in that location’s active files for today. |
| Find an event from a previous day | Archives → Search | Matches in the archives for one date and one location. |
| Download one day’s files | Archives → Export by day | Original compressed files, downloaded individually. |
| Retrieve several days or locations | Period export | One or more ZIP files prepared in the background, available in My exports. |
| Find who changed a setting or requested an export | Audit logs | Application events, separate from syslogs. |
Search for lines or retrieve files
Section titled “Search for lines or retrieve files”A search selects lines matching a criterion. Its results may be limited by processing time or by the number of files and matches.
A daily or period export retrieves original archived files. Search terms do not filter these files.
To investigate several days, search each day separately or export the period’s files to analyze with your own tools.
Understand incomplete results
Section titled “Understand incomplete results”A partial or truncated notice means that the search may not provide every event. The total number of detected matches can also exceed the number of returned lines. Displaying more results on the page does not scan the files again.
To check a period thoroughly, retrieve the available original files. Today’s archives may be incomplete: more files can still be added.
Access and availability
Section titled “Access and availability”Owner, Member and Reader roles can view and export logs in their organization, subject to service access. My exports shows your own account’s requests for the selected organization.
Check archive retention and download exports before their expiration date.