Search today’s logs
Hot search scans the open location’s active files for the current UTC day. It does not scan the entire archive history. Around midnight in your time zone, check the UTC date you are investigating.
Run a search
Section titled “Run a search”- Open your organization, then the relevant location.
- Expand Hot search.
- Enter text such as an IP address,
deniedor the markerLOGCENTRAL_TEST. - Choose Text for a literal search or Regular expression for a pattern.
- Run the search and review the matching lines, their file and line number.
To find either of two terms, use denied|blocked in regular expression mode. In text mode, the | character is part of the text being searched.
Read the results
Section titled “Read the results”The current search defaults are case-insensitive matching, two context lines, a maximum of 1,000 returned matches, 1,000 files and 60 seconds of processing. The service may apply additional limits based on the volume read.
The page displays results progressively. Show more reveals lines already returned; it does not search additional files.
If a result is partial or truncated, read the indicated reason. The detected total may differ from the number of available lines. A download offered by the search contains the prepared results, subject to their limits; it does not replace an export of original files.
Hot search and live logs
Section titled “Hot search and live logs”Live logs show incoming messages. Hot search scans active files when you run it. Run it again to include new messages; it does not update automatically like the live stream.
No results?
Section titled “No results?”- Check the location and simplify the search text.
- Confirm log receipt using the test guide.
- Check whether the files have already been archived: use Archives → Search.
- For a past date, use archive search.
View, search or export logs helps you choose the right tool for your date range.