Log query – simply retrieve your data

Coralogix brings a whole new approach to machine data analytics with its Loggregation and anomaly detection capabilities, but sometimes all you need is to query your data and get fast reliable results.

Coralogix’s Log query brings an intuitive interface with flexible query and Grid layout options to allow you to query any data in seconds. In addition, Coralogix’s log query uses the unique capabilities of log template identification to enable you to query a log template regardless of its parameters without using any query language or defining regular expressions.

Tutorial:

1- Click the query icon on your dashboard to open the log query interface

dashboard click query

2- Select your query type: Free text search or template search. Free text search will allow you to query your logs by any text or metadata. Template search will enable you to query a log record regardless of its variables and get all the results for that log event without using query language or regular expressions.

Coralogix text/template selection

3-Define the query text and timeframe, note that you can also run queries based on Elastic ‘simple query’, just hover the test-tube icon for instructions. Click ‘GO’ to get results in seconds, or ‘Clear’ to reset the query back to default.

Coralogix supports 3 types of queries: 

1) Google search query – match any log with the combination of words queried on the entire log payload: so querying “Coralogix is” will return both the log “Coralogix is the best” and the log “Coralogix query is flexible”

2) Elastic simple query – with word tokenizing according to Elasticsearch default tokens. So querying /Key_name:first-name/ will return both the log “first-name: John” and “The first participant’s name is John”. Note that you use / before and after your query string. 

3) Keyword search – use ‘Key_name.keyword’ to query data without tokenization so that /Key_name.keyword:first-name/ will return the log “first-name: John” and also “first-name: Bob”. Note that you use / before and after your query string. You can add regex to the keyword query with the following convention: So /Key_name.keyword:/first.*John// will return only the log “first-name: John” 

coralogix-query-criteria

coralogix query language

4-Use Loggregation to view the unique appearances of your logs and their variable models (Note it takes 24H for Loggregation to become active)

coralogix loggregation

5) To query the area of a log on your results simply mark that log, click the ‘query before after’ button, and select the desired timeframe. This will retrieve all logs prior and after the selected log from the same application and subsystem

coralogix query log area

6) To view long text logs, mark a text for querying/alerting, or to visualize JSON fields, simply mark a log and click the 3 dots that will appear or press the ‘space’ button. 

coralogix info panel

Start using Coralogix now and enjoy a whole new world of simple and flexible ways to retrieve your data.

Signup to Coralogix
WordPress Lightbox