Skip to content

LOG List


Global Configuration

Note

This feature entry is only visible to members with management permissions.

On the Global Configuration page, you can centrally manage the following three core functions at the workspace level:

  • Quick Filter Configuration: Customize the universal quick filter panel within the Explorer;

  • Top Field Configuration: Configure the fields displayed at the top of each log in stack mode. Indices without individual configurations will use the global default configuration;

  • Index Key Field Configuration: Define the default priority display fields for each index in the data list;

  • Query Acceleration Configuration: Enable acceleration for fields under an index to significantly improve query performance.

Quick Filter

Quick filter items configured here will be applied to the quick filter panel on the left side of all Explorers in the workspace and will be visible to all members.

All filter fields added here will automatically enable Query Acceleration for their respective indices to ensure filtering performance. This association is mandatory by default and cannot be disabled.

You can configure two types of fields:

  • Filter Fields (currently active fields)

    • You can edit or delete a single field;
    • Delete all filter fields with one click.
  • Optional Fields (including business fields, system fields, others)

    • Add as filter fields

If there are many fields, you can directly search for fields. If no exact match is found in the query results, you can directly create and add it to the "Filter Fields".

Empty value (no data) entries in the quick filter are not displayed by default. You can enable this here. After enabling, a "No Data" option will appear at the bottom of each filter group, allowing you to filter data where the field value is empty. This configuration can only be operated by administrators and custom roles with "Global Configuration" permissions.

Global Quick Filter

Workspace administrators can uniformly configure global filter items in Management > Quick Filter. After saving the configuration, all members can refresh or re-enter the LOG Explorer to synchronize the latest global filter items.

Global filter items and personal custom filter items are saved independently and do not overlap:

  • Administrators adding, editing, reordering, or disabling global filter items will not affect existing personal filter items of members;
  • In the quick filter bar, global filter items are displayed before personal filter items by default;
  • If a global filter item has the same name as a personal filter item, both will be displayed simultaneously, and the source can be distinguished by the field identifier.

When the global configuration changes, after you refresh the page, the system will prompt "The quick filter has been automatically updated following the global configuration." The same Explorer and the same version will only prompt once.

Top Field Configuration

Configure the fields displayed at the top of each log in Stack Mode. Indices without individual configurations will use the global default configuration.

Global Default Top Fields

When an index does not have a dedicated top field configuration, the global default fields will be used. Click "Edit" to adjust the globally default displayed fields.

Default fields include: source, host, service, pod_name, container_name, duration.

Index Top Field Configuration

Configure dedicated top fields for a specific index, with priority higher than the global default configuration.

  1. Click "+ Add Index Configuration", select an index, and configure the top fields (up to 8 fields can be selected);
  2. Top fields support selecting existing fields or manually entering field names. Press Enter to add custom fields;
  3. After saving, logs under that index will display the top fields according to the configuration in stack mode.

Added index configurations support editing and deletion.


Index Key Fields

Configure a set of "key fields" for different data indices. After configuration, when viewing the data list corresponding to that index, the system will preferentially display these fields in this order, helping to quickly focus on core information.

  • Left side: Index column;
  • Right side: Select optional fields under each index listed by the system as key fields.

For the current key field configuration, you can choose whether to synchronize all key fields to query acceleration.

Note

This configuration defines the default display template for the data list, used to optimize the initial viewing experience. Members can still customize the list fields by adding or removing them in the Explorer through the "Display Columns" feature, which is not limited by this default configuration.

Query Acceleration Configuration

Enabling acceleration for fields that are frequently used for filtering, grouping, or sorting under an index can greatly improve the query response speed for these fields. This configuration is based on the index level.

  • Left side: Index column;
  • Right side: Select optional fields under each index listed by the system for acceleration. You can later view them in the "Accelerated Fields" list above.

After configuration changes, it takes about 5 minutes to take effect throughout the system. Once effective, the fields will be automatically added to the "Accelerated Fields" list.

Accelerated Fields That Cannot Be Disabled

The following three types of fields will automatically appear in the "Accelerated Fields" list and cannot be disabled:

  • Official Default Accelerated Fields: Key fields preset by the system;

  • Quick Filter Fields: Fields from the quick filter configuration;

  • Synchronized Key Fields: When the synchronization switch in the key field configuration is enabled, all key fields will automatically be accelerated.

Enabling acceleration for fields that are frequently used for filtering, grouping, or sorting under an index can greatly improve the query response speed for these fields. This configuration is based on the index level.

Go to LOG Explorer > Display Columns > Query Acceleration Configuration, with the index list on the left and the accelerated fields list for the current index on the right.

Add Accelerated Fields

Click "+ Add Accelerated Field", a row for adding appears above the accelerated fields list:

  1. Select a field from the dropdown, supporting fuzzy search; or directly enter a field name;
  2. After clicking "Add", the field is added to the accelerated fields list below;
  3. Click "Cancel" to exit the adding state without adding a new field.

Delete Accelerated Fields

  • Delete a single entry: Click "Delete" on the corresponding field in the accelerated fields list;
  • Batch delete: Click "Delete All Accelerated Fields" to clear all accelerated fields for the current index.
Accelerated Fields That Cannot Be Deleted

The following three types of fields will automatically appear in the "Accelerated Fields" list and cannot be deleted:

  • Official Default Accelerated Fields: Key fields preset by the system;
  • Quick Filter Fields: Fields from the quick filter configuration;
  • Synchronized Key Fields: When the synchronization switch in the key field configuration is enabled, all key fields will automatically be accelerated.
Note
  • Only fields of type string can be enabled for query acceleration;
  • Each index supports up to 200 query accelerated fields. When the limit is reached, the system will prevent adding more and prompt: "The query acceleration field limit has been reached. Each index supports up to 200 fields."

After configuration changes, it takes about 5 minutes to take effect throughout the system. Once effective, the fields will be automatically added to the "Accelerated Fields" list.

Index

By setting up LOG Multi-Index, you can store logs that meet specific conditions into different indices and choose an appropriate data storage strategy for each index, effectively saving log data storage costs.

The index list uses a scrolling load mechanism. It displays the first 50 indices by default and automatically loads the next 50 when scrolling to the bottom. This loading method only applies to the index selection list, not to the paging or scrolling of the log data list.

You can perform the following operations:

  • Select all indices (❗May cause slow queries due to large data volume);

  • Multi-select indices;

  • Pin an index to the top;

  • Search and locate by index name. Press Enter after entering a keyword to execute the search, the index list will not refresh automatically during input;

  • Set the index display area to small, medium, or large.

  • Click the jump icon at the end of an index to open the corresponding index in a new tab.

After configuration, you can switch between different indices in the Explorer to view the corresponding log content.

Quick Filter

For more details, refer to Filter.

Display Columns

On the Display Columns page, two categories of fields are displayed overall:

  • Display Fields: Fields displayed in the quick filter;

  • Optional Fields: All fields cached for the current data type.

You can perform the following operations:

  • Search for fields; if no exact match is found in the query results, you can directly create and add it to the "Filter Fields";

  • Edit field aliases;

  • Drag to adjust field order;

  • Delete (all) fields;

  • Reset to default fields;

  • Set whether to display field aliases and the time column.

When you reopen the Display Columns configuration, the system will restore the position where you last stayed. After adding, deleting, or reordering fields, you do not need to start searching from the top of the list when you re-enter the configuration page.

Reset to Default Fields

When performing the "Reset to Default Fields" operation, the system displays fields according to the following rules:

  • If you have not configured key fields: After resetting, only the time and message fields are displayed (❗Whether the time column is displayed is also controlled by another independent "Display Time Column" switch);
  • If you have configured key fields: After resetting, the fields will be displayed exactly according to your custom field list, and the message field will not be automatically added;
  • The message field can be manually removed when displayed.

Status Distribution Chart

Based on the selected time range, the system will automatically divide multiple time points and display the count of different log statuses in a stacked bar chart, facilitating efficient statistical analysis.

When filtering logs, the bar chart will synchronously display the filtered results in real time.

  • You can hover to export the chart, exporting it to a dashboard, notes, or copying it to the clipboard;

  • You can customize the selection of time intervals.

Query Mode

After the workspace enables LOG Long-term Storage, a switch between Standard Query and Long-term Query will appear in the upper right corner. This switch is used to toggle queries between different storage tiers of data, and the specific usage depends on your data storage strategy configuration.

Query Mode Data Source Use Cases Query Limitations
Standard Query Logs within the standard storage range High-frequency analysis, real-time monitoring, arbitrary time range retrieval None
Long-term Query Logs within the long-term storage range Historical log backtracking, low-frequency auditing Single query time range up to 24 hours, no status distribution chart displayed

If the workspace has not enabled LOG long-term storage, the Explorer will not display this switch.

Click to view More Details on LOG Query Modes.

Usage Instructions

  1. The default mode when entering the Explorer is Standard Query, supporting arbitrary time range queries and real-time response.

  2. After switching to Long-term Query, click the time input box to open the time selection panel:

  3. Select a date: Choose the start date on the left;

  4. Set start and end times: Use the scroll wheels on the right to select the start time and end time respectively. If the end time is earlier than the start time, the system will automatically recognize it as the next day, and the input box will display as 2026-05-19 23:00:00 ~ Next Day 05:00:00;
  5. You can also drag the blue range on the timeline to pan it as a whole, or drag the left and right endpoints to fine-tune the start and end times. During dragging, crossing midnight of the current day is allowed, and the cross-day boundary is marked as "Next Day 00:00".

  6. Below the timeline, the currently selected query interval and total duration are displayed in real time. After confirming, click "Query" to trigger the retrieval.

In the LOG Explorer search bar, multiple search and filter methods are supported.

After entering a search or filter condition, you can preview the effect and copy the condition to apply it to charts or query tools.

LOG Search Tips

. will no longer be used as a word separator. It is recommended to enter the full class name or full path for searching.

Manual Configuration

Click the toggle button on the right side of the search box to enter the manual input query mode.

JSON Field Retrieval

Note

This feature is only available for user roles with DQL query permissions.

DQL queries support extracting nested values from JSON fields in log data. You only need to add a field path with the @ symbol in the DQL query statement, and the system will automatically recognize this configuration and display the extracted value as an independent field in the query results. For example:

  • Normal query:

  • Query after extracting embedded fields:

In the LOG Explorer, if you want to directly view the values extracted from the JSON text of each log's message in the data list, add a field in the format @targer_fieldname in the display columns. As shown below, we added the configured @fail_reason from the DQL query statement to the display columns:

Log Color Highlighting

To help quickly locate key information in logs, the system uses color highlighting to display log content. When you enter a keyword in the search bar, only the matched keywords will be highlighted.

Single Log Expansion and Copy

  • Click the button in a log entry to view the full content of that log. If the log supports JSON format, it will be displayed in JSON format; otherwise, the content will be displayed normally;

  • Click the button to copy the entire log content to the clipboard.

Display Lines

In the log data list, the trigger time and content of each log are displayed by default. You can use the "Display Lines" option to choose to display "1 Line", "3 Lines", "10 Lines", or "All Content" to view the complete log information.

Explanation of "Scanned Volume" and "Count"

  1. Scanned Volume: Indicates the size of data scanned during the actual execution of this query, used to measure query consumption. The larger the scanned volume, the larger the data range that needs to be retrieved and processed for this query.
  2. Count: Indicates the number of results ultimately returned by this query, used to measure the scale of query results. The count only represents the number of matched results and is not equivalent to the amount of data scanned during the query process.

Note that there is no fixed conversion relationship between the scanned volume and the count. Since the size of a single log is not fixed, and a query may scan a large amount of data but only return a few results, it is not possible to directly infer the scanned volume from the count, nor deduce the returned count from the scanned volume.

Settings

Create Monitor

When filtering log data, if you need to further set up alert monitoring for the filtered results, you can create a monitor with one click. The system will automatically apply your selected index, data source, and search conditions, simplifying the configuration process.

Note
  • If you have selected another workspace in the upper left corner of the LOG Explorer, the search conditions will not be synchronized to the monitor configuration page, and the monitor configuration page will be empty by default;

  • In the standard Commercial Plan, the site-level left* query feature is enabled by default. You only need to enable the workspace-level left* query to support the monitor's left* query. For the Deployment Plan, you can enable or disable the site-level left* query independently. Only when both the site-level and workspace-level left* queries are enabled can the monitor perform left* queries. Otherwise, if the LOG Explorer is configured with a left* query, a query error may occur when jumping to the monitor.

Copy as cURL

In the LOG Explorer, you can obtain log data via the command line. In the Settings on the right side of the log data list, click the Copy as cURL button to copy the corresponding cURL command. Paste the command into the host terminal and execute it to obtain log data that matches the filter and search conditions within the current time period.

Example

After copying the cURL command line, as shown below: <Endpoint> needs to be replaced with the domain name, and <DF-API-KEY> needs to be replaced with the Key ID in API Management.

For more related parameter descriptions, refer to DQL Data Query.

For more information about the API, refer to Open API.

curl '<Endpoint>/api/v1/df/query_data?search_after=\[1680226330509,8572,"L_1680226330509_cgj4hqbrhi85kl1m6os0"\]&queries_body=%7B%22queries%22:\[%7B%22uuid%22:%222eb41760-cf6e-11ed-a983-7d559044c3fc%22,%22qtype%22:%22dql%22,%22query%22:%7B%22q%22:%22L::re(%60.*%60):(%60*%60)%7B+%60index%60+IN+\[%27default%27\]+%7D%22,%22highlight%22:true,%22limit%22:50,%22orderby%22:\[%7B%22time%22:%22desc%22%7D\],%22_funcList%22:\[\],%22funcList%22:\[\],%22disableMultipleField%22:false,%22disable_slimit%22:false,%22is_optimized%22:true,%22offset%22:0,%22search_after%22:\[1680226330509,8572,%22L_1680226330509_cgj4hqbrhi85kl1m6os0%22\],%22timeRange%22:\[1680187562081,1680230762081\],%22tz%22:%22Asia%2FShanghai%22%7D%7D\]%7D' \
- H 'DF-API-KEY: <DF-API-KEY>' \
- -compressed \
- -insecure
Note

Only Standard Members and above can perform the copy command line operation.

In addition to this export path, you can also use other log data export methods.

Set Status Color

The system has preset default colors for status values. If you need to customize the display colors of different statuses in the Explorer, click Set Status Color to modify them.

Formatting Configuration

Note

Only administrators and above can perform Explorer formatting configuration.

Through formatting configuration, you can hide sensitive log content, highlight important log content, or achieve quick filtering by replacing log content.

  1. Click the Settings in the upper right corner of the Explorer list;

  2. Click Formatting Configuration;

  3. Add a mapping rule, enter the following content and save:

    • Field: Specify the log field (e.g., content);

    • Match Method: Select the match method (currently supports =, !=, match, not match);

    • Match Content: Enter the content to match (e.g., DEBUG);

    • Display as Content: Enter the replacement display content (e.g., **).

Log Data Export

In logs, you can first filter out the desired data and then export it as a CSV, JSONL, TXT file, or export it to a dashboard or notes.

If you need to export a specific log, open the details page of that log and click the icon in the upper right corner.

Advanced Linkage Configuration

For more details, refer to Advanced Linkage Configuration.