Docs: Search and filtering
Documentation / Query & analyse

Search and filtering

Find specific log lines across your services from the console, read them in context, and watch a service live.

OBSESC keeps every raw event. The Search page in the console finds the lines you are looking for across your services and time range, and shows what happened around them.

Searching

  1. Open Search from the console navigation.
  2. Type a word, identifier or phrase into the search bar, for example an order ID, an error code or an IP address.
  3. Choose a service, or leave All services selected to search across every service.
  4. Pick a time window. A narrower window returns faster.
  5. Select Run Search.

Before a large search runs, the console shows you how much it may need to read.

If a search covers a lot of data, OBSESC may stop early and tell you the results are incomplete. Narrow the time window or pick a service, then search again.

Reading the results

  • Results lists the matching events with their time, service and message.
  • Related events shows what was logged just before and after the events you pick, either in the same service or across all services, so you can read a hit in context.
  • Patterns groups the matching lines by their shape, so you can see at a glance which kinds of line matched and how often.

From the results you can open your search in Explore to continue with your own SQL, or run What changed? on the period you found.

Saving searches

Use Save search to keep a search you run often. Saved searches appear in the Saved searches tab.

Live tail

The Live tail tab streams new events as they arrive, filtered by your search. You can pause it to investigate and resume it later. Live tail does not slow down ingestion. If the view falls behind, it may skip some events, and tells you when it does.

Filtering in SQL

For exact filters and aggregates across fields, use SQL over the raw_events table in Explore:

SELECT timestamp_ns, service, host, body
FROM raw_events
WHERE service = 'checkout'
  AND env = 'prod'
  AND attributes['region'] = 'ap-southeast-2'
  AND timestamp_ns >= 1767225600000000000
  AND timestamp_ns <  1767229200000000000
LIMIT 100;

See the SQL reference for the table and tips for fast queries.

Choosing a tool

You want to…Use
Find a word or ID and see the linesSearch
See what happened around a matchRelated events
Filter and aggregate across fieldsSQL in Explore
Watch a service right nowLive tail