Search

Find events across all collected data with augmented search and out-of-the-box parsing.

What you will do: run a first search, narrow it with parsed fields and save it for reuse.

Search is the centre of XpoLog. Collected data is parsed out of the box — common log formats arrive with fields already extracted — and augmented search adds suggestions and context on top of plain text matching.

  1. Open the search view in the XpoLog console:
Console path: <placeholder>
  1. Type a word that appears in your logs, for example an error string or a host name, and run the search.
  2. Narrow the time range to the window you care about.
  3. Use the parsed fields in the result panel to filter: click a value to add it to the query, or exclude it.
  4. Save the search with a name. Saved searches feed dashboards and monitoring rules.

Search syntax basics

Free text:        <placeholder>
Field match:      <placeholder>
Boolean:          <placeholder>
Time expression:  <placeholder>

While you type, XpoLog suggests fields, values and related searches based on what is in the data. Results highlight matches and show the parsed structure of each event so you can pivot from a line to a field without writing a parser.

Out-of-the-box parsing

Common technologies are parsed as they arrive. When a source is unknown, XpoLog proposes a pattern; accept it to get fields for that source going forward. Custom patterns can be defined for in-house formats.

Hot and cold data

Searches run against hot data. Older data in the archive/cold tier can be brought back into scope for a search when needed, at the cost of longer query times.

Next: Monitoring

Verify with XPLG engineering before publishing.