Search
Find events across all collected data with augmented search and out-of-the-box parsing.
What you will do: run a first search, narrow it with parsed fields and save it for reuse.
Search is the centre of XpoLog. Collected data is parsed out of the box — common log formats arrive with fields already extracted — and augmented search adds suggestions and context on top of plain text matching.
Steps: a first search
- Open the search view in the XpoLog console:
Console path: <placeholder>
- Type a word that appears in your logs, for example an error string or a host name, and run the search.
- Narrow the time range to the window you care about.
- Use the parsed fields in the result panel to filter: click a value to add it to the query, or exclude it.
- Save the search with a name. Saved searches feed dashboards and monitoring rules.
Search syntax basics
Free text: <placeholder> Field match: <placeholder> Boolean: <placeholder> Time expression: <placeholder>
Augmented search
While you type, XpoLog suggests fields, values and related searches based on what is in the data. Results highlight matches and show the parsed structure of each event so you can pivot from a line to a field without writing a parser.
Out-of-the-box parsing
Common technologies are parsed as they arrive. When a source is unknown, XpoLog proposes a pattern; accept it to get fields for that source going forward. Custom patterns can be defined for in-house formats.
Hot and cold data
Searches run against hot data. Older data in the archive/cold tier can be brought back into scope for a search when needed, at the cost of longer query times.
Next: Monitoring
Verify with XPLG engineering before publishing.