Querying data in Better Stack

There are three main ways of accessing logs in Better Stack: Live tail, Query API, and Dashboards.

Live tail

Live tail is your main window into logs you sent to Better Stack. We've optimized it to easily handle terabytes of logs, and we also made sure querying them is a breeze.

Query panel

The first thing you'll need to know about Live tail is the Query panel on top. This is how it looks, and we'll walk you through the individual parts you can find on it:

ezgif.com-gif-maker (1).jpg

The first thing in the Query panel is the Source selector. You can mix & match which logs to show on Live tail, making it super easy to switch between apps, or to combine them to see patterns in multiple environments, to name a few use-cases.

Next comes the Query builder prompt, powered by the Live tail Query Language. This is where you filter your logs based on the content of the message, level, or any other attributes you send our way.

The Datetime picker next to the Query prompt gives you an easy way to specify the time range. You can use relative datetimes, like now-3h, that change automatically based on your time, or absolute times, like Monday at 3pm. The datetime picker (and the Scroll to field) also accept unix timestamps and ISO8601 strings, making it extremely straightforward to copy datetimes from your other sources, like error reporting.

You can use the bookmark icon to save views. Think of views as permanent filters unbounded by time - we store your query prompt and selected sources, and you can easily return to them. We found views very useful to keep track of common errors - we utilize them ourselves along with Alerts.

The last interesting action available in the Query panel is the Scroll to button. It accepts the same range of values as the datepicker (relative, absolute, or time described in words), and jumps your context to the given time, querying logs around it. It's very useful to see the context of what happend at a given time, and to drill down for some more context, you can apply additional filters.

Individual log lines

The next element you'll likely see a lot of is the individual log line. Here's an example, with expanded view of all the attributes:

ezgif.com-gif-maker (2).jpg

There are two main parts - the primary fields rendered on top, and the attribute explorer you get when you click on a line.

You can control the row rendered by tweaking the primary fields in the source advanced settings. You may find that the default attributes we render are not the best match for you - feel free to tweak them as you like!

The rendered attributes give you an easy insight into the extra context you sent along with the log.

The entire log line is interactive, and there are multiple actions you can do. Here's a little gallery of the possibilities:

Screenshot 2023-01-12 at 11.23.08.png

Query API

If you prefer to search for logs from your own systems, we have a Query API which you can use. It uses the same backend as the Live tail, so the options should feel familiar if you used it for querying logs.