Appearance
Explore & Search
Explore (under Telemetry) searches your logs, spans and events together, from every Stream in the namespace, newest last like a log tail. Each row says what it is (log, span or event) and which Stream it came from. Metrics have their own builder under Metrics, next to it.
Click a row to see everything it carries. A row with a trace opens the trace's waterfall, with the logs and events from the same trace.
Searching
Type a search and press Enter. Filters show as chips while you type, and the box suggests field names, Stream names and common values as you go.
| Search | Finds |
|---|---|
payment failed | the words anywhere in a log line, span name or event |
level:error | a field's value (any case, partial matches count) |
level:"ERROR" | an exact value |
-level:debug, NOT level:debug | everything else |
level:error AND service:checkout | both (AND is implied between filters) |
level:error OR level:fatal | either |
path:/api*, name:*checkout* | a wildcard |
duration_ms:>250, status:>=500 | a number compared |
duration_ms:[100 TO 500] | a range |
order_id:* | records that have the field |
Streams and signals
| Search | Finds |
|---|---|
stream:checkout | one Stream by name (any case); quote names with spaces: stream:"Checkout API" |
stream:checkout* | Streams whose names match |
streamId:strm_… | one Stream by id |
signal:log, signal:span, signal:event | only logs, spans or events (logs, traces, events work too) |
The Stream menu and the All / Logs / Spans / Events switch next to the search box just add or change these filters, so the search always shows what you're looking at, and a copied link opens the same view.
If no Stream has that name, stream: searches an attribute called stream instead (Docker and Kubernetes logs have stream:stdout).
Fields that mean the same everywhere
Logs, spans and events store different things, so a few names cover all three:
| Field | Log | Span | Event |
|---|---|---|---|
service | service name | service name | the service attribute |
level | severity | status (Error, Ok, Unset) | severity |
name | event name | span name | event name |
body | the log line | status message | body |
duration_ms | duration | duration | |
trace_id, span_id | trace and span | trace and span | trace and span |
Anything else is an attribute: http.route:/cart matches it on whichever records have it. A field a record doesn't have simply doesn't match.
Charts, fields and patterns
- Fields lists what the records you can search carry. Click one to break the chart down by it (
streamworks too). - Complex mode charts an aggregation (
p95ofduration_ms, say) instead of a count. - Patterns groups the log lines and events the search finds into patterns.
- Add to Dashboard and Create Monitor start from the search. A monitor reads one Stream and one signal, which its
stream:andsignal:filters pick.
Monitors and formulas
The same search box is used wherever you filter telemetry: monitors, derived metrics and dashboard widgets. Formulas (a / b * 100) and composite conditions (a && (b || !c)) get their own: each query or monitor they name shows as a chip (hover it to see what it is), and a name that isn't set up is underlined.