Archive Query enables you to directly query your logs and spans from your S3 archive using any text or a wide range of syntax queries. Query data irrespective of priority, daily quota, or its time frame.
Archive Query enables you to directly query your logs and spans from your S3 archive.
Use this feature to:
STEP 1. In your Coralogix toolbar, navigate to Data Flow > Archive Queries.
STEP 2. Click ARCHIVE QUERY.
STEP 3. Define a New Archive Query.
Notes:
Query Examples
1. A query to find logs with the field ClientIP_geoip.continent_name:”Europe” and the field ClientIP_geoip.country_name with values other than: Czechia, United Kingdom or Germany:ClientIP_geoip.continent_name:”Europe” NOT (ClientIP_geoip.country_name:”Czechia” OR ClientIP_geoip.country_name:”United Kingdom” OR ClientIP_geoip.country_name:”Germany”)
2. A query to find logs with words status and get:status get
3. A query to find only logs with HTTP method post:“http_method”:”post” </aside>
STEP 4. Click RUN ARCHIVE QUERY. Once you have set up and run your query, a test will be run to validate your setup.
View your query results in one of three formats: Logs Preview, Download TSV, or Clone.
This option allows you to view your logs without ever indexing your data.
Download a TSV file to view query results.
Duplicate your current query by clicking on the Clone button. In the new duplicated query, click RUN ARCHIVE QUERY.
If you wish to share an archive query with another teammate, click on the chain-link icon in the query of choice. This will copy to your clipboard the link to that same archive query.
After some time, the archive query you created will expire so you can no longer view or download the data. Click Clone and duplicate the same query with the same criteria instead of recreating the query from scratch.
The limitations placed on queries are described below.
Limitation | Description |
---|---|
Bytes processed | Up to 30% of daily ingested bytes |
Parquet files scanned | Up to 500k files |
Clone results | Up to results 1M results while running Archive Query |
Time out | Up to 5 min of query execution |
Once a limit is reached, a warning message is displayed. Refine your query results to avoid reaching a limit.
Refine your query results using any of the following methods:
Documentation | Archive Query from the Explore Screen |
Need help?
Our world-class customer success team is available 24/7 to walk you through your setup and answer any questions that may come up.
Feel free to reach out to us via our in-app chat or by sending us an email at [email protected]