Log Explorer
Use Log Explorer to investigate log records in an internal table without leaving the VeloDB Cloud console. You can select a table and time field, narrow the time range, search with indexed fields or a SQL condition, and then inspect matching records, their distribution over time, and the records immediately before and after an event.
Log Explorer is intended for interactive investigation. Use SQL Editor when you need to write a complete SQL statement, join data, create objects, or save and share SQL work.
Before you start
- Select the warehouse that stores the logs. Log Explorer queries tables in the warehouse's internal catalog. It does not browse external-catalog tables.
- Choose a table that has a suitable time field. The console recognizes
DATE,DATEV2,DATETIME,DATETIMEV2, andTIMEfields as time fields. Queries are unavailable until you select one. - Ensure that your warehouse SQL role can read the target database and table. The console can show only data that your role is allowed to query.
- To use Search mode, create an inverted index on at least one field in the table. Otherwise, use SQL mode or add an index before searching.
For help designing indexes for text search, see Inverted Index Overview.
Explore Log Explorer
- Log in to the VeloDB Cloud console.
- Select the warehouse that you want to use.
- In the left navigation pane, click Log Explorer.
After you open Log Explorer, use the following areas to investigate logs:
- The data and time controls at the top of the page select the cluster, table, time field, and time range for the investigation.
- The query bar lets you use Search mode for indexed keyword searches or SQL mode for a filter expression. The Query button runs the investigation.
- The left field panel and Filter bar help you choose result columns and narrow the matching records.
- The histogram shows how matching records are distributed over the selected time range.
- The results panel lists matching records. Expand a record to inspect its fields, view its JSON representation, or start a contextual search for nearby records.
Select the log data and time range
At the top of the page, select the data that you want to investigate:
- If the Cluster selector is shown, select the cluster that runs the query.
- In Table, select a database and table from the internal catalog.
- In Time, select the field that represents the event time. When a table has multiple supported time fields, confirm that you selected the field that matches the investigation.
- Select a preset or custom time range. Choose the narrowest range that can contain the event to reduce the amount of data scanned and make results easier to investigate.
- Choose Search or SQL, enter an optional condition, and click Query. You can also press Enter in the condition box.
When you select a table, Log Explorer loads its fields and selects the first supported time field. Review the automatically selected field before running a query. The selected table, time field, time range, and query conditions determine the results, hit count, and histogram.
Search logs
Log Explorer provides two query modes.
- Use Search to find keywords or phrases in selected inverted-index fields.
- Use SQL to add a SQL filter expression when you need comparisons, ranges, or conditions that Search mode does not express.
Both modes apply the selected time range and any filters in the Filter bar.
Keyword search mode
Use Search for keyword or phrase search over selected inverted-index fields.
- Select Search from the query-mode menu.
- Select the indexed fields that you want to search. Limit the selection to fields that can contain the term you are investigating.
- Enter a keyword or phrase and click Query.
For an unquoted search term, Log Explorer performs a keyword search on the selected indexed fields. To search for an exact phrase, enclose the entire phrase in quotation marks, for example, "connection refused". Search-mode results are constrained by the selected time range and any filters that you add.
If the selected table has no inverted index, Search is unavailable and the console shows: Please create an inverted index for this table first. Create an inverted index on the appropriate field, then return to Log Explorer and select the table again.
Note:
Search mode builds the appropriate search predicate for the selected index fields. It is not a search across every column in the table. Use SQL mode when you need a condition on a non-indexed field or more control over the predicate.
SQL mode
Use SQL mode to add a SQL filter expression. Enter a condition, not a complete SELECT statement. Log Explorer combines your condition with the selected time range and filters before it queries the table.
For example, use the following condition to find records whose event_type is ForkApplyEvent and whose action is none:
event_type = 'ForkApplyEvent' AND action = 'none'
As you type, the console suggests fields from the selected table and common SQL operators. Use SQL mode for comparisons, ranges, and combinations of conditions. Keep the condition focused on the selected table and time range.
Filter and shape the results
You can use the left field panel and the Filter bar to focus the result set.
In the field panel, you can:
- Search the field list to find a field by name. The list separates Selected fields, which become result-table columns, from Available fields.
- Add an available field to the table, or remove a selected field when it is no longer useful. If you do not select fields, the result table shows the
_sourcerepresentation of each record.
Use the field-panel filter to narrow the available fields by searchability, aggregatability, or field type as follows:
- Click the add button beside Filter to create a filter. Select a field, operator, and value. The available operators adapt to the field type, for example, comparison and range operators for numeric and time fields.
- Custom label is disabled by default. Enable it when you create or edit a filter, then enter a label to identify that condition in the Filter bar. The label changes how the filter chip is displayed, not the condition that Log Explorer applies.
- Select an existing filter chip next to the Filter bar to edit it, or close the chip to remove it.
When you hover over a scalar field value in a result, use the plus or minus action to add an equal or not-equal filter. You can also add that field to, or remove it from, the result table. Complex values do not provide the equal and not-equal quick-filter actions.
Use the histogram
The histogram shows the number of matching records over the selected time range. It updates when the query, time range, time field, or filters change.
- Hover over a bar to inspect its time bucket and matching-record count.
- Use the Time interval selector to choose automatic or fixed bucket intervals.
- Drag across a portion of the histogram to replace the current time range with that interval and focus the investigation on the selected period.
The result area also shows the total number of hits and supports pagination. Timestamps are displayed in the console's configured time-zone context.
Inspect records and surrounding events
Expand a record in the result table to inspect it in either format:
- Table presents field names and values, with quick actions for applicable fields.
- JSON shows the complete record as JSON.
To investigate an event in sequence, click Contextual Search on the right side of the expanded record. The panel retrieves records immediately before and after the selected record according to the selected time field. You can:
- Add filters that apply only to the contextual result set.
- Select fields to display as columns, or inspect a record in Table or JSON format.
- Click Load 5 items to retrieve older or newer records. Choose the number of items to retrieve for each direction.
Troubleshoot Log Explorer
Query is unavailable
Select a table and a valid Time field. Log Explorer enables Query only after it has a supported time field. If the table has no DATE, DATEV2, DATETIME, DATETIMEV2, or TIME field, use a table with an event-time field or investigate the data in SQL Editor.
Search mode is unavailable
The target table has no inverted index that Log Explorer can use. Create an inverted index for the field you need to search, then reselect the table. For a one-off investigation that does not use an index, choose SQL mode and add a filter condition instead.
No results are returned
First widen the time range and confirm the selected time field. Then remove or simplify keyword, SQL, and filter conditions one at a time. If data is still not visible, verify that your warehouse SQL role has access to the database and table.
The expected table is not listed
Log Explorer lists tables in the internal catalog only. Verify that the table is in the selected warehouse and that you have the necessary read privilege. To query an external-catalog table, use SQL Editor.