Section 3 · Logs Drilldown

Filter by labels, navigate detailed views, search and filter, drill into context

Estimated time: 1 min

Logs investigation workflow

A typical investigation moves through five steps, though you can jump between them or skip the ones you don’t need.

Log investigation workflow showing five steps

StepWhat you doWhat you get
Filter by labelsSelect service, job, instance, etc.Logs from specific sources
Navigate to detailed breakdownsView log list, logs volume, labels, fields, patternsMultiple perspectives on log data
Search and filterUse fields, patterns, and text searchRelevant logs matching criteria
Drill into contextExpand log lines and click field valuesRelated logs and context
Act on itAdd to a dashboard, save the view, or open in ExploreA dashboard panel or saved view, with your query and time range

Open-ended investigation

This workflow supports investigation when you don’t know exactly what you’re looking for:

  • Start broad, for example, all logs from a service.
  • Narrow progressively, for example, errors only, then specific text.
  • Follow interesting findings, for example, click fields to filter further.
  • Build context, for example, expand log lines to see before and after.
  • Watch log volume over time to spot error spikes, rising warnings, or unusual drops.
  • Use the patterns breakdown to group similar lines and include or exclude them.