Documentation forPapertrail

Event Viewer (new)

Introduction

The event viewer, also called the log viewer, is a core part of Papertrail. Please use the "Give Feedback" button to let us know what you think.

For customers that have been with us for a while, you may have access to two event viewers: the new event viewer and a legacy version of the event viewer. SolarWinds recommends you toggle Try our new Events UI to "On". The legacy event viewer will not receive updates or improvements and may eventually be removed in favor of the new event viewer. For information on using the legacy event viewer, see Event Viewer (legacy).

Elements

Screenshot

search-and-tail

Live tail

When you arrive in the log viewer, Papertrail is showing events as they happen. It's realtime, as if you were logged directly into a system (or hundreds of systems). Logs are live.

Pause logs

To pause live logs, scroll up or click PAUSE:

Live tail: pause

Resume live tail

When paused on current logs, click LIVE to resume live tail:

Live tail: resume

Return to current and resume live tail

When viewing older logs, click the down arrow or scroll down to return to current logs and resume live tail.

Live tail: jump to current

Search

Search is integrated into Papertrail's event viewer:

Log viewer: search

Find anything just by typing what you know. If you've used Google search, Papertrail search works much the same way, including phrases ("), logical operators (AND, OR), and exclusion (-).

Click ? just to the left of the Search button to see example searches without leaving the log viewer, or read about the syntax.

Save searches and create alerts

As your team uses Papertrail more, some searches will probably be worth accessing again, receiving in email, graphing, or otherwise retaining.

After entering a search query, click Save Search to retain the query:

Log viewer: save search

Give it a name, and optionally set up a search alert right away: Log viewer: save search form

Alerts can also be added later.

The saved search will be shown on the team-wide Papertrail Dashboard, like these:

Dashboard: saved search

and will be accessible from the event viewer's Saved Searches button:

Log viewer: saved searches

Log velocity graph

When viewing or searching logs, click the graph button to see patterns in the number of messages:

Log viewer: velocity graph button

Velocity graphs help identify patterns or anomalies, reducing the time needed to spot trends or troubleshoot errors. They can also be used to seek to a particular time by clicking a point on the line.

Time seek

To seek directly to any date or time in the searchable history, click the clock icon:

Time picker

The time seek will expand:

Seek to

Enter the desired point and click Seek To. When you enter a time, the time zone in your Papertrail profile is used.

Read more about time zones in distributed environments here or here.

Note: Seeking across a DST boundary will jump to a position that is off by 1 hour (details).

Context

Find a message that could use some background? There are four quick ways to put events in context.

Host or program

Hosts and programs are highlighted with different colors and clickable to allow you to see the event in that context:

Log viewer: context

The log sender link will show that message in context of all messages from that sender (for example, to see a complete error that occurred on a single system).

The log type link will show that message in context of messages from that program (process) in the current group.

After clicking, you'll be looking at the same log message and any search query will be retained.

Event actions

To open the event actions menu, click on the 3-dot icon on the left.

Event actions search option

This menu exposes actions to:

  • copy this event's log line text
  • link to this event, in the same context you're viewing
  • show this event in the command-line interface
  • show this event within events from a system, program, system & program, or group

Event selection

While holding Shift, hover over an event and click on the dot to the right of the event to start a selection. A range can be selected by continuing to hold Shift and clicking a selection dot above or below an existing selected event.

Event selection

When there is an active selection, the event viewer URL will update to reflect which events are selected, so that the URL can be shared.

Selected events

Press Esc to clear a selection.

Click-to-search

You can turn pieces of your log messages into clickable elements. When these are clicked, the event viewer will display all surrounding messages that match the clicked element. This could be an IP, email address, user ID, request ID, domain name, source code filename, or any other part of a log message—you get to decide.

Click to Search Preview

Learn more about how this works →

Navigation

Keyboard shortcuts

Press ? while in the log viewer and all will be revealed.

Multiple companies

You may have access to multiple Papertrail entities representing different companies' logs. Within the log viewer, switch entities at will. See Managing logs from multiple companies.

Customization

Display Preferences

To change your display preferences click on the settings cog. Papertrail provides a multitude of customization options:

Display preferences menu

You can control the density of the logs in the viewer by changing the Font and the line Density.

The Theme option allows you to choose from a number of different color schemes including dark and light themes.

Use Truncate Message to display each message on one line only. This is great for aligning messages to view patterns. Click on a line to expand it.

Use the other options to hide parts of the log message that aren't necessary; for example, Papertrail timestamps (Hide Time) if messages have internal timestamps. Similarly you can Hide System and/or Hide Program to put even more focus on the log message.

If you want to use the full width and height of your screen to see logs you can use Hide Application Chrome.

Use the UTC Timestamps to convert your log timestamps to UTC without the need to modify the time zone in your Profile.

UTC Timestamps option won’t be available on your Display Preferences menu if your profile’s time zone is already set to UTC. This also does not convert internal timestamps of messages.

Filtering

Seeing noisy logs? Although your systems and apps decide which log messages are sent to Papertrail, Papertrail can optionally filter noise on your behalf. See Log filtering.