Skip to content

Logs table

The logs table is the default results view in Explore. It displays individual log entries as rows, with fields rendered as columns. Use the table to scan results, compare field values across entries, sort by specific columns, and open individual logs for deeper inspection.

Logs table displaying log entries with Timestamp, Content, Application, Subsystem, and Severity columns

Configure content column fields

The content column is the primary display column for each log entry. It shows the log message or a subset of key-value pairs depending on your configuration.

To configure which fields appear in the content column:

  1. Select Manage columns in the table header.
  2. In the column management panel, find the Content section.
  3. Add or remove fields to control what appears in each row's content cell.

Changes apply immediately to all rows in the table.

Manage columns

Add, remove, reorder, and reset columns to customize what information appears in the table.

Add columns from column management

  1. Select Manage columns in the table header.
  2. Search for a field by name, or browse the list.
  3. Select the field to add it as a column.
  4. Drag the field to reorder it in the column list.
  5. Select Apply or close the panel to save changes.

Add a column from a log entry

You can also add a column directly from an individual log entry without opening the column management panel:

  1. Select a log row to open the log details panel.
  2. Find the field you want to add as a column.
  3. Open the field's context menu (three dots or hover actions).
  4. Select Add as a column.

The column appears immediately in the table.

Reset column layout

To restore the default column configuration:

  1. Select Manage columns.
  2. Select Reset to default.

This removes any custom columns and restores the original layout.

Sort or remove columns

  • Sort: Select a column header to sort by that column. Select again to reverse the sort order. An indicator shows the active sort column and direction.
  • Remove: Hover over a column header and select the remove icon, or open Manage columns and deselect the field.

Change row format

The logs table supports different row display formats to match your workflow:

  • Compact: Shows one line per log entry. Use this to scan high volumes of results quickly.
  • Expanded: Shows multiple lines per entry to display more of the log message. Use this when log messages are long and you need to read more without opening the details panel.

Toggle the row format using the display options control in the table header.

Row format menu with options for 1 line, 2 lines, JSON, Condensed, and List formats

Export logs

Export the current results to a file for offline analysis or sharing:

  1. Select Export in the table header or Explore actions menu.
  2. Choose the export format (for example, CSV or JSON).
  3. Confirm the export.

The export includes the logs matching your current query and time range, up to the supported export limit.

Export table dialog with options for file name, format, structure, row limit, and column selection

Row actions

Open the more actions menu next to any log row to access actions scoped to the whole log entry:

  • Custom Actions: opens a list of custom actions configured for your account.
  • Copy log: copies the full log entry to the clipboard.
  • Copy log ID: copies the log's unique ID. Use this to share a permalink, correlate with an external system, or paste the ID into a query.
  • Open info panel: opens the log details panel for the selected entry.
  • View surrounding logs: opens a list of duration presets — 5 Seconds, 30 Seconds, 1 Minute, 5 Minutes, or 10 Minutes — to load logs from the same source within ± that interval of the selected event. The action drops any active filters and rebuilds the query with only a scoping clause: applicationName and subsystemName for logs, serviceName and operationName for spans, and session_context.session_id for the rum.events dataset. On the rum.events dataset, the action label changes to View surrounding events.
  • Copy permalink: copies a URL that recreates the current query, time range, and selected log.

Fields sidebar actions

Actions available from the Fields sidebar apply to the table view and modify the query or column layout.

Show the graph for the key

Entry pointResult
Fields sidebar context menu (three dots on any field)Opens a time-series bar chart grouped by the selected field
Log details panel — key menuOpens the same time-series bar chart

The chart appears above the results table. Each bar segment represents a distinct value for the selected field. Select any segment to drill down into the underlying logs or filter the value in or out of your query.

This action is equivalent to adding the field as a Group by with a Count aggregation and visualizing the result as a stacked bar chart.

Actions inside the panel

The graph-for-key panel and any other slide-in log panel that opens from a chart drilldown share the same row and cell actions as the main logs table:

  • Open the more actions menu on any row to access Open info panel, View surrounding logs (or events on rum.events), Copy log, Copy permalink, and Custom Actions.
  • Select a value in a row to open the same field-level context menu listed in Value menu, including Custom Actions. These panels skip the Value across time action since it points back to a panel you're already viewing.

Add as Grouping

Select Add as Grouping from the Fields sidebar context menu to add the field to the Group by clause in the Query Builder. The table switches from individual log rows to aggregated groups, showing each unique value and its count.

Key-value context menu

Select a key or value in a log row to open a context menu of field-level actions. The available actions differ based on whether you selected a key or a value.

Key menu

Select a field name in a log row:
ActionDescription
Custom ActionsOpens a list of custom actions scoped to the selected field.
Include in queryAdds the field as a filter on the current query.
Exclude from queryAdds the field as an exclusion filter on the current query.
Add as a columnAdds the field as a column in the logs table.
Add to favorite fieldsPins the field to the top of the Fields sidebar for the current source and dataset.
Copy full pathCopies the field's full path.
Copy the key's valueCopies the field's current value for this log.
Copy the key:valueCopies the full key:value pair.
Show the graph for the keyOpens a time-series bar chart grouped by this field. See Show the graph for the key for chart behavior.

Value menu

Select a field value in a log row:
ActionDescription
Custom ActionsOpens a list of custom actions scoped to the selected value.
Include in queryAdds the field-value pair as an inclusion filter on the current query.
Exclude from queryAdds the field-value pair as an exclusion filter on the current query.
Query valueReplaces the entire query with a single filter for this value. Use this to pivot to a fresh search on the selected value without keeping prior filters.
Copy full pathCopies the field's full path (for example, cx_rum.session_context.session_id).
Copy value to the clipboardCopies the field value.
Copy keyCopies the field name.
Value across timeOpens a time-series chart of how often this field-value combination appears across the query's time range.
Live tailOpens Live tail filtered to the selected field-value pair.

Next steps

Inspect a single log event in depth — and use the per-field Row actions menus for keys and values — in the Log details panel.