Search logs with SPL in Log Explorer

The SPL editor supports the current SPL1 command set. Eligible customers in every realm can use the editor without a customer-managed feature flag or separate allowlist step.

Your selected Logs connection and its existing access permissions determine which logs and indexes you can query.

Choose a search mode

Log Explorer provides the following search modes:

  • Builder provides the guided search experience.
  • SPL provides an editor for queries that use the current SPL1 command set.

Builder and SPL retain their own query and result state. You can move between the modes without losing completed search results.

When you open an empty SPL workspace for the first time, Log Explorer initializes the editor with the selected Builder indexes. Builder filters, generated aliases, eval expressions, and other Builder-specific transformations do not transfer to the SPL editor. After this initial transfer, changes in one mode do not update the other mode.

Requirements

Before you search logs with SPL, confirm the following requirements:

  • Your organization has a Log Observer Connect connection.
  • You have access to the connection and the indexes that you want to query.
  • The selected connection contains the logs that you want to query.