- Documentation
- Learning Hub
- Section 3 of 3 Logs Drilldown
The log investigation workflow
Slide 3 of 5
Logs investigation workflow
A typical investigation moves through five steps, though you can jump between them or skip the ones you don’t need.
Open-ended investigation
This workflow supports investigation when you don’t know exactly what you’re looking for:
- Start broad, for example, all logs from a service.
- Narrow progressively, for example, errors only, then specific text.
- Follow interesting findings, for example, click fields to filter further.
- Build context, for example, expand log lines to see before and after.
- Watch log volume over time to spot error spikes, rising warnings, or unusual drops.
- Use the patterns breakdown to group similar lines and include or exclude them.