> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Search and filter log data

> Learn how to search and filter logs in Palo Alto Networks Cortex XCOR.

export const AddToDashboardIcon = props => {
  return <svg viewBox="0 0 20 20" className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }} {...props}>
      <path fillRule="evenodd" clipRule="evenodd" d="M3 3H9V9H3V3ZM11 3H17V9H11V3ZM3 11H9V17H3V11ZM13.25 11H14.75V13.25H17V14.75H14.75V17H13.25V14.75H11V13.25H13.25V11ZM12.5 4.5V7.5H15.5V4.5H12.5ZM4.5 4.5V7.5H7.5V4.5H4.5ZM4.5 12.5V15.5H7.5V12.5H4.5Z" />
    </svg>;
};

export const CollectionIcon = props => {
  const drawPath = "M21 6.5c-1.66 0-3 1.34-3 3 0 .07 0 .14.01.21l-2.03.68c-.64-1.21-1.82-2.09-3.22-2.32V5.91C14.04 5.57 15 4.4 15 3c0-1.66-1.34-3-3-3S9 1.34 9 3c0 1.4.96 2.57 2.25 2.91v2.16c-1.4.23-2.58 1.11-3.22 2.32l-2.04-.68C6 9.64 6 9.57 6 9.5c0-1.66-1.34-3-3-3s-3 1.34-3 3 1.34 3 3 3c1.06 0 1.98-.55 2.52-1.37l2.03.68c-.2 1.29.17 2.66 1.09 3.69l-1.41 1.77C6.85 17.09 6.44 17 6 17c-1.66 0-3 1.34-3 3s1.34 3 3 3 3-1.34 3-3c0-.68-.22-1.3-.6-1.8l1.41-1.77c1.36.76 3.02.75 4.37 0l1.41 1.77c-.37.5-.59 1.12-.59 1.8 0 1.66 1.34 3 3 3s3-1.34 3-3-1.34-3-3-3c-.44 0-.85.09-1.23.26l-1.41-1.77c.93-1.04 1.29-2.4 1.09-3.69l2.03-.68c.53.82 1.46 1.37 2.52 1.37 1.66 0 3-1.34 3-3S22.66 6.5 21 6.5zm-18 4c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1zM6 21c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1zm5-18c0-.55.45-1 1-1s1 .45 1 1-.45 1-1 1-1-.45-1-1zm1 12c-1.38 0-2.5-1.12-2.5-2.5S10.62 10 12 10s2.5 1.12 2.5 2.5S13.38 15 12 15zm6 4c.55 0 1 .45 1 1s-.45 1-1 1-1-.45-1-1 .45-1 1-1zm3-8.5c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1z";
  return <svg viewBox="0 0 24 25" data-testid="CollectionIcon" aria-label="CollectionIcon" {...props} className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }}>
      <path d={drawPath} />
    </svg>;
};

export const CollectionNavIcon = props => {
  const drawPath = "M8.4 18.2C8.8 18.7 9 19.3 9 20C9 21.7 7.7 23 6 23S3 21.7 3 20 4.3 17 6 17C6.4 17 6.8 17.1 7.2 17.3L8.6 15.5C7.7 14.5 7.3 13.1 7.5 11.8L5.5 11.1C5 11.9 4.1 12.5 3 12.5C1.3 12.5 0 11.2 0 9.5S1.3 6.5 3 6.5 6 7.8 6 9.5V9.7L8 10.4C8.6 9.2 9.8 8.3 11.2 8.1V5.9C10 5.6 9 4.4 9 3C9 1.3 10.3 0 12 0S15 1.3 15 3C15 4.4 14 5.6 12.8 5.9V8.1C14.2 8.3 15.4 9.2 16 10.4L18 9.7V9.5C18 7.8 19.3 6.5 21 6.5S24 7.8 24 9.5 22.7 12.5 21 12.5C19.9 12.5 19 11.9 18.5 11.1L16.5 11.8C16.7 13.1 16.3 14.5 15.4 15.5L16.8 17.3C17.2 17.1 17.6 17 18 17C19.7 17 21 18.3 21 20S19.7 23 18 23 15 21.7 15 20C15 19.3 15.2 18.7 15.6 18.2L14.2 16.4C12.8 17.2 11.2 17.2 9.8 16.4L8.4 18.2Z";
  return <svg viewBox="0 0 24 24" data-testid="Collections" aria-label="Collections" {...props} className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }}>
      <path d={drawPath} />
    </svg>;
};

export const ServiceIcon = props => {
  return <svg viewBox="0 0 22 20" {...props} className="inline-block h-5 w-5" aria-label="ServiceIcon" style={{
    fill: "#28a561"
  }}>
      <path fillRule="evenodd" clipRule="evenodd" d="M10.7339 0.0766817C10.8966 -0.0255606 11.1034 -0.0255606 11.2661 0.0766817L16.2661 3.21954C16.4117 3.31104 16.5 3.47092 16.5 3.64286V8.35714C16.5 8.52908 16.4117 8.68896 16.2661 8.78046L11.2661 11.9233C11.1034 12.0256 10.8966 12.0256 10.7339 11.9233L5.73391 8.78046C5.58834 8.68896 5.5 8.52908 5.5 8.35714V3.64286C5.5 3.47092 5.58834 3.31104 5.73391 3.21954L10.7339 0.0766817ZM6.5 4.54772V8.08086L10.5 10.5951V7.062L6.5 4.54772ZM11.5 7.062V10.5951L15.5 8.08086V4.54772L11.5 7.062ZM15.0605 3.64286L11 6.19514L6.93955 3.64286L11 1.09057L15.0605 3.64286Z" />
      <path fillRule="evenodd" clipRule="evenodd" d="M5.73391 8.07668C5.89657 7.97444 6.10343 7.97444 6.26609 8.07668L11.2661 11.2195C11.4117 11.311 11.5 11.4709 11.5 11.6429V16.3571C11.5 16.5291 11.4117 16.689 11.2661 16.7805L6.26609 19.9233C6.10343 20.0256 5.89657 20.0256 5.73391 19.9233L0.733914 16.7805C0.588344 16.689 0.5 16.5291 0.5 16.3571V11.6429C0.5 11.4709 0.588344 11.311 0.733914 11.2195L5.73391 8.07668ZM1.5 12.5477V16.0809L5.5 18.5951V15.062L1.5 12.5477ZM6.5 15.062V18.5951L10.5 16.0809V12.5477L6.5 15.062ZM10.0605 11.6429L6 14.1951L1.93955 11.6429L6 9.09057L10.0605 11.6429Z" />
      <path fillRule="evenodd" clipRule="evenodd" d="M15.7339 8.07668C15.8966 7.97444 16.1034 7.97444 16.2661 8.07668L21.2661 11.2195C21.4117 11.311 21.5 11.4709 21.5 11.6429V16.3571C21.5 16.5291 21.4117 16.689 21.2661 16.7805L16.2661 19.9233C16.1034 20.0256 15.8966 20.0256 15.7339 19.9233L10.7339 16.7805C10.5883 16.689 10.5 16.5291 10.5 16.3571V11.6429C10.5 11.4709 10.5883 11.311 10.7339 11.2195L15.7339 8.07668ZM11.5 12.5477V16.0809L15.5 18.5951V15.062L11.5 12.5477ZM16.5 15.062V18.5951L20.5 16.0809V12.5477L16.5 15.062ZM20.0605 11.6429L16 14.1951L11.9395 11.6429L16 9.09057L20.0605 11.6429Z" />
    </svg>;
};

export const ServiceNavIcon = props => {
  return <svg viewBox="0 0 20 20" {...props} className="inline-block h-5 w-5" aria-label="Services" style={{
    fill: "#28a561"
  }}>
      <path d="M0 13.5463C0 13.3708 0.157997 13.2607 0.284979 13.3478L4.18974 16.0263C4.24909 16.067 4.28571 16.1427 4.28571 16.2248V19.7709C4.28571 19.9465 4.12772 20.0566 4.00074 19.9695L0.0959735 17.291C0.0366259 17.2503 0 17.1745 0 17.0925V13.5463Z" />
      <path d="M5.2381 16.2248C5.2381 16.1427 5.27472 16.067 5.33407 16.0263L9.23883 13.3478C9.36581 13.2607 9.52381 13.3708 9.52381 13.5463V17.0925C9.52381 17.1745 9.48718 17.2503 9.42784 17.291L5.52307 19.9695C5.39609 20.0566 5.2381 19.9465 5.2381 19.7709V16.2248Z" />
      <path d="M4.85641 15.0372L8.75079 12.3658C8.87876 12.2781 8.87876 12.0566 8.75079 11.9688L4.85641 9.29746C4.79785 9.25729 4.72596 9.25729 4.6674 9.29746L0.773017 11.9688C0.645052 12.0566 0.645052 12.2781 0.773016 12.3658L4.6674 15.0372C4.72596 15.0774 4.79785 15.0774 4.85641 15.0372Z" />
      <path d="M5.23804 4.279C5.23804 4.10344 5.39603 3.99337 5.52302 4.08048L9.42778 6.75893C9.48713 6.79964 9.52375 6.8754 9.52375 6.95746V10.5036C9.52375 10.6792 9.36575 10.7892 9.23877 10.7021L5.33401 8.02368C5.27466 7.98297 5.23804 7.90721 5.23804 7.82515V4.279Z" />
      <path d="M10.4761 6.95746C10.4761 6.8754 10.5128 6.79964 10.5721 6.75893L14.4769 4.08048C14.6039 3.99337 14.7618 4.10344 14.7618 4.279V7.82515C14.7618 7.9072 14.7252 7.98297 14.6659 8.02368L10.7611 10.7021C10.6341 10.7892 10.4761 10.6792 10.4761 10.5036V6.95746Z" />
      <path d="M10.0944 5.76985L13.9888 3.09851C14.1168 3.01073 14.1168 2.78924 13.9888 2.70147L10.0944 0.0301261C10.0359 -0.010042 9.964 -0.010042 9.90544 0.0301261L6.01105 2.70147C5.88309 2.78924 5.88309 3.01073 6.01105 3.09851L9.90544 5.76985C9.964 5.81002 10.0359 5.81002 10.0944 5.76985Z" />
      <path d="M10.4761 13.5463C10.4761 13.3708 10.6341 13.2607 10.7611 13.3478L14.6658 16.0263C14.7252 16.067 14.7618 16.1427 14.7618 16.2248V19.7709C14.7618 19.9465 14.6038 20.0566 14.4768 19.9695L10.572 17.291C10.5127 17.2503 10.4761 17.1745 10.4761 17.0925V13.5463Z" />
      <path d="M15.7142 16.2248C15.7142 16.1427 15.7508 16.067 15.8101 16.0263L19.7149 13.3478C19.8419 13.2607 19.9999 13.3708 19.9999 13.5463V17.0925C19.9999 17.1745 19.9633 17.2503 19.9039 17.291L15.9991 19.9695C15.8722 20.0566 15.7142 19.9465 15.7142 19.7709V16.2248Z" />
      <path d="M15.3325 15.0372L19.2269 12.3658C19.3548 12.2781 19.3548 12.0566 19.2269 11.9688L15.3325 9.29746C15.2739 9.25729 15.202 9.25729 15.1435 9.29746L11.2491 11.9688C11.1211 12.0566 11.1211 12.2781 11.2491 12.3658L15.1435 15.0372C15.202 15.0774 15.2739 15.0774 15.3325 15.0372Z" />
    </svg>;
};

export const CSharpIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="m11.5 15.97.41 2.44c-.26.14-.68.27-1.24.39-.57.13-1.24.2-2.01.2-2.21-.04-3.87-.7-4.98-1.96C2.56 15.77 2 14.16 2 12.21c.05-2.31.72-4.08 2-5.32C5.32 5.64 6.96 5 8.94 5c.75 0 1.4.07 1.94.19s.94.25 1.2.4l-.58 2.49-1.06-.34c-.4-.1-.86-.15-1.39-.15-1.16-.01-2.12.36-2.87 1.1-.76.73-1.15 1.85-1.18 3.34 0 1.36.37 2.42 1.08 3.2.71.77 1.71 1.17 2.99 1.18l1.33-.12c.43-.08.79-.19 1.1-.32M13.89 19l.61-4H13l.34-2h1.5l.32-2h-1.5L14 9h1.5l.61-4h2l-.61 4h1l.61-4h2l-.61 4H22l-.34 2h-1.5l-.32 2h1.5L21 15h-1.5l-.61 4h-2l.61-4h-1l-.61 4h-2m2.95-6h1l.32-2h-1l-.32 2Z" style={{
  fill: "#28a561"
}} />
  </svg>;

export const PipeIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="M22 14h-2v2h-6v-3h2v-2h-2V6a2 2 0 0 0-2-2H4V2H2v8h2V8h6v3H8v2h2v5a2 2 0 0 0 2 2h8v2h2" style={{
  fill: "#28a561"
}} />
  </svg>;

export const AiMessageIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="M2.5 3C2.08782 3.00012 1.73499 3.14696 1.44141 3.44043C1.14766 3.73418 1 4.0875 1 4.5V19L4 16H15.5C15.9124 16 16.2659 15.8532 16.5596 15.5596C16.8533 15.2658 17.001 14.9125 17.001 14.5V10H15.5V14.5H3.375L2.5 15.375V4.5H10V3H2.5Z" style={{
  fill: "#28a561"
}} />
    <path fillRule="evenodd" clipRule="evenodd" d="M14.1154 3.11538L11 4.5L14.1154 5.88461L15.5 9L16.8846 5.88461L20 4.5L16.8846 3.11538L15.5 0L14.1154 3.11538Z" style={{
  fill: "#28a561"
}} />
  </svg>;

export const MicroscopeIcon = props => <svg viewBox="0 0 24 24" {...props} className="inline-block h-5 w-5" aria-label="Microscope" style={{
  fill: "#28a561"
}}>
    <path d="M9.46,6.28L11.05,9C8.47,9.26 6.5,11.41 6.5,14A5,5 0 0,0 11.5,19C13.55,19 15.31,17.77 16.08,16H13.5V14H21.5V16H19.25C18.84,17.57 17.97,18.96 16.79,20H19.5V22H3.5V20H6.21C4.55,18.53 3.5,16.39 3.5,14C3.5,10.37 5.96,7.2 9.46,6.28M12.74,2.07L13.5,3.37L14.36,2.87L17.86,8.93L14.39,10.93L10.89,4.87L11.76,4.37L11,3.07L12.74,2.07Z" />
  </svg>;

Logs Explorer lets you filter log data to focus your search. When you first open Logs
Explorer, results display for all log data received in the last hour.

To normalize data for consistent filtering, Palo Alto Networks Cortex XCOR maps your data to the
`service`, `severity`, and `message` fields. Expand any of the displayed logs to show
these fields, along with any custom fields your data contains.

By default, the **Summary** column displays the contents of the `message` field. If
the `message` field isn't normalized, then the entire payload for each log displays
in the **Summary** column. To parse the payload and direct certain contents into the
`message` field,
[create a field parser](/control/shaping/shape-logs/parse-logs#create-field-parsers).

To filter your data, start with [basic queries](#filter-data-with-basic-queries). You
can then use the [query syntax](/investigate/querying/query-logs/query-syntax) to
filter on attributes in your data, such as a particular environment or cluster name.
If you know details about the data you're searching for, try using
[advanced queries](#filter-data-with-advanced-queries).

<Note>
  For optimal performance, Cortex XCOR recommends always including a primary
  [key](/investigate/querying/query-logs/query-syntax#keys) in your filter, such as
  `service` or `severity`.
</Note>

## Filter data with basic queries

Use this method of selecting individual keys or values to query logs from a broad
scope to a narrow focus. The following steps are recommended methods of querying. You
can choose to start with a different key or value based on what you're searching for.

To use basic querying:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.

2. On the **Logs Explorer** page, use the
   [time range selector](/navigate/time-ranges) to select a time
   window to display logs for. The default time window is the last hour.

3. Define your query. You can use the sidebar, query box, or a combination of both to
   specify your query criteria. You can also click individual keys or values within
   a selected log.

   * **Sidebar**: Expand the key you want to query on. Hold the pointer over the
     value you want to include or exclude from your filter. Click the equals operator
     (`=`) to include the value, or the does not equal operator (`!=`) to exclude the
     value.

     For example, expand the `severity` key and click the equals operator next to
     **ERROR**, which adds that expression to your filter.

     ```text theme={null}
     severity = "ERROR"
     ```

     For additional options, click the <Icon icon="ellipsis-vertical" /> three
     vertical dots icon next to a field name. For example, click
     **Pin this field to top of field list** to pin the selected field to the top of
     the list of fields, which makes the field always visible.

     You can also pin entire logs to the top of the query results. See
     [group and visualize queries](#group-and-visualize-queries) for information about
     how to pin logs.

   * **Query box**: Use the [query syntax](/investigate/querying/query-logs/query-syntax)
     to enter the key you want to query on. The autocomplete syntax suggests
     operators and matching values for keys you enter as you type to help you
     construct your query.

     ```text theme={null}
     severity = "ERROR" AND service = "nginx"
     ```

     <Note>
       If you're unsure what syntax to use, click in the query box and press
       `Control+Space` to display values for a key or available operators.
     </Note>

   * **Attributes**: After expanding an individual log, click any key or value to
     display a menu with the following options:

     * **Add field to summary**: Include the selected key or value in the **Summary**
       column of the individual log results.
     * **Add field as column**: Adds the selected field as a column in the query
       results.
     * **Add to group and visualize**: Adds the selected key or value to the query
       box as a [`summarize`](/investigate/querying/query-logs/query-syntax#summarize)
       query, and selects a visualization that best matches the data type.
     * **Show matching logs**: Return logs containing only the selected key or value.
     * **Hide matching logs**: Return logs that don't contain the selected key
       or value.
     * **Copy field name**: Copy the selected key or value.

4. To submit your query, either click **<Icon icon="refresh-cw" />Run** or press
   `Control+Enter` (`Command+Return` on macOS).

5. Expand your query by either adding additional key-value pairs or entering a
   full-text string such as `"failed query token"` to find logs that contain the
   expression anywhere in the log. For example:

   ```text theme={null}
   severity = "ERROR" and service = "gateway" AND "failed query token"
   ```

   <Note>
     The operators `AND` plus `OR` are case insensitive, so you can use `AND`,
     `and`, `OR`, and `or` interchangeably.
   </Note>

6. To display an AI summary of a log, click **Summarize log**.

7. As you refine your filter, click and select a portion of the time chart to zoom in
   to view a smaller time window.

The results update to include only logs that contain the key-value pairs you enter.

## Filter data with advanced queries

If you know details about the log you're searching for, or are carrying context to
Logs Explorer from a [services page](/observe/services/service-pages), use the
[query syntax](/investigate/querying/query-logs/query-syntax) to construct your query.

For example, if you know there's an issue with the `gateway` service in your
production environment, create a query to help you locate which Kubernetes cluster is
experiencing issues.

To use advanced filtering:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.

2. In the query box, construct a query to include any logs with `ERROR` as the
   `severity` for the `gateway` service:

   ```text theme={null}
   service = "gateway" AND severity = "ERROR"
   ```

   The results include 8,700 logs.

3. To submit your query, click **<Icon icon="refresh-cw" />Run** or press
   `Control+Enter` (`Command+Return` on macOS).

   You notice that several logs in the results contain `"Failed to query user by token"`
   in the **Summary** column.

4. Add a full-text string to your search to narrow the scope of your query, and then
   click **<Icon icon="refresh-cw" />Run**:

   ```text theme={null}
   service = "gateway" AND severity = "ERROR" AND "failed to query user by token"
   ```

   The results include 5,400 logs, which is fewer, but still too many.

   In the sidebar, you notice that 75% of the results are for the
   `production-east` Kubernetes cluster.

5. In the sidebar, click `production-east` and then click **Show matching logs**.
   Cortex XCOR adds the selected key-value to your query:

   ```text theme={null}
   service = "gateway" AND severity = "ERROR" AND "failed to query user by token"
   AND kubernetes.cluster = "production-east"
   ```

   The results include 4,000 logs. To reduce scope, begin drilling in to individual logs.

6. Expand individual logs to find commonalities across the data. You realize that the
   same Kubernetes pod is included in many of the logs, so you add that key-value
   pair to your filter:

   ```text theme={null}
   service = "gateway" AND severity = "ERROR" AND "failed to query user by token"
   AND kubernetes.cluster = "production-east"
   AND kubernetes.pod_name = "gateway-6agg9df321-o89ef"
   ```

   The results include less than 700 logs, which is 8,000 fewer than your initial
   query.

You identified the individual Kubernetes pod containing the majority of errors for
the `gateway` service so you can inform your team and begin fixing the issue.

## Generate queries from natural language prompts

Cortex XCOR provides
[generative artificial intelligence](/overview/generative-ai) (AI) tools to generate
queries from natural language prompts. Using natural language, you write what you
want Cortex XCOR to query, and Cortex XCOR generates the query
that returns relevant data.

You can generate and refine queries from natural language prompts in Logs Explorer.
Text entry fields that support natural language prompts include an **Edit with AI**
button. To manually edit the generated query, see
[Filter data with basic queries](#filter-data-with-basic-queries).

For more information on how to generate and refine queries with AI, see
[Generate queries using natural language](/investigate/querying/natural-language).

[Operator](/navigate/operator) also queries your logs. Unlike query
generation, it discovers log fields and their values in your tenant, samples raw
logs to confirm what's present, and summarizes the results rather than only
returning a query. Click **<AiMessageIcon /> Ask Operator** in the page header or
press <kbd>A</kbd>, and then describe what you're looking for. For example:

<Prompt description="What are the most common error messages in the shopping-cart service logs over the last hour?">
  What are the most common error messages in the shopping-cart service logs over the last hour?
</Prompt>

<Warning>
  Generative AI features can produce incorrect results, hallucinate data, and deliver
  inaccurate analysis. Use generative AI features with care, and independently verify
  all information produced by generative AI tools before applying it.

  Certain prompts, data, or other inputs might produce irrelevant content. Don't rely on
  generative AI features or responses for any uses that exceed their designed scope.
</Warning>

## Group and visualize queries

When exploring log data, you might want to group logs by one or more fields. This
capability helps to answer questions such as,
*What are the error rates across environments for my service?*.

Cortex XCOR lets you group logs and visualize the results within Logs
Explorer. You can explicitly use the
[`summarize`](/investigate/querying/query-logs/query-syntax) operator in a query,
select a key or value in the sidebar, or choose attributes in an individual log to
group your query results by.

To group and visualize query results:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.

2. Select a field or value to group by, or create a query with the `summarize`
   operator:

   * **Sidebar**: In the sidebar list of fields, expand the key you want to group by,
     hover the pointer over a value, click the <Icon icon="ellipsis-vertical" /> three
     vertical dots icon, and then click **Add to group and visualize**.

   * **Attributes**: Expand an individual log, click any key or value, and then click
     **Add to group and visualize**.

   * **Query box**: Use the [query syntax](/investigate/querying/query-logs/query-syntax)
     to create a query that includes the `summarize` operator. For example, the
     following query searches for logs in a Kubernetes cluster in
     `production-us-west` that contain errors, and then groups the results by
     `service` and `environment`:

     ```text theme={null}
     severity = "ERROR"
     AND kubernetes.cluster_name = "production-us-west"
     | summarize by service, environment
     ```

     Logs Explorer inserts the key or value you selected into a `summarize`
     query and visualizes the results.

3. To display results with a different visualization, select one of the
   [available options](#visualization-options). When you select an option, the query
   text is rewritten to match the operator that the visualization requires:

   * Selecting **Bar chart**, **Pie / Sunburst**, **Table** or **Stat** appends the
     [`summarize`](/investigate/querying/query-logs/query-syntax#summarize) operator to
     your query.
   * Selecting **List** or **Patterns** strips all aggregation
     [operators](/investigate/querying/query-logs/query-syntax#operators) from your
     query to produce the intended visualization.

   When using a chart, see [common panel elements](/observe/dashboards/panels#common-panel-elements)
   for an explanation of the available tools in the <Icon icon="ellipsis-vertical" />
   three vertical dots menu.

If the results include interesting logs that you want to keep, you can pin those logs
to the top of the query results. Hover the pointer over the log you're interested in
and click the **<Icon icon="pin" /> pin icon**. The log is pinned to the top of
the query results and persists across queries. You can change the time range and
modify your query without losing pinned query results.

### Visualization options

The following visualization options are available in Logs Explorer to change how your
query results display.

| Option | Displayed visualization |
| - | - |
| **List** | Shows individual log lines in a scrollable, paginated table ordered by timestamp. Each row is a single log event with expandable details. |
| **Time chart** | Displays a line chart with time on the x-axis, showing how a metric (such as `count()`) changes over the selected time range, optionally grouped by a `by` field into multiple series. |
| **Bar chart** | Displays horizontal or vertical bars, where each bar represents a group (from the `by` clause) and bar length represents the aggregated value (such as count per service). Limited to 100 bars. |
| **Pie / Sunburst** | Displays hierarchical rings when a query groups results by two or more fields. Otherwise, displays a pie chart. |
| **Table** | Displays a columnar table of aggregated results displaying one row per unique combination of `by` fields, with columns for each computed metric. Supports sorting and CSV export. Returns the top 100 results by default. To return more results, include the [`limit`](/investigate/querying/query-logs/query-syntax#limit) operator and specify the number of results to return. |
| **Stat** | Shows large single-number tiles, displaying one per group. Ideal for Key Performance Indicators (KPIs) like total error count or request volume per service. |
| **Patterns** | Groups log messages by structural similarity, showing a [log usage pattern](/investigate/analyze/logs-usage), the count of matching logs, and a filter expression to drill into. The displayed patterns are based on available results from the current query in Logs Explorer. To use the pattern in a query, click a pattern and then choose one of these options: <br /><br /> - **Show matching logs** returns all logs that match the pattern. <br /> - **Hide matching logs** returns all logs that don't match the pattern. |

## Save and share queries

You can save queries that you run frequently, capture query results in a dashboard
or notebook, and share links to queries or individual logs to help focus results when
investigating issues.

### Access recent and saved queries

When investigating issues, you might use the same query frequently. Rather than
redefining the query, use recent and saved queries to access previously defined
queries in Cortex XCOR. You can apply a fully defined query from a
previous time period by clicking a query from the **Examples** tab.

Recent query are available globally to all users in Cortex XCOR and
persist for 14 days.

To access recent and saved queries:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.
2. Click **<Icon icon="text-align-start" /> View queries** to display all available queries.
3. Click either the **My recent queries** tab or the **Saved queries** tab to display
   the queries you want to view.
4. Locate the query you want to apply and click it.

The parameters in the query override any parameters in the query box.

### Save a query

You can save queries that you access frequently so they're always available in
Cortex XCOR. Saved queries are like bookmarks you can reference when you
need them.

To save a query:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.

2. In the query box, [construct your query](#filter-data-with-basic-queries).
   The **Save query** button is unavailable until you run your query.

3. Click **<Icon icon="refresh-cw" />Run** to run your query.

4. Optional: To include summary fields and columns in your saved query, click the
   <Icon icon="ellipsis-vertical" /> three vertical dots icon and select from the
   following options:

   * **Add field to summary**: Include the selected key or value in the **Summary**
     column of the individual log results.
   * **Add field as column**: Adds the selected field as a column in the query
     results.

5. Click **Save query** to save your query.

6. In the **Queries** window, enter a name for your query.

7. If you added fields to the **Summary** column or added a field as a column in the
   query results, enable the **Include summary fields and columns** toggle to include
   those selections in the saved query.

8. Click **Save** to save your query.

Your query displays in the **Saved queries** tab of the **Queries** window. You can
[access your saved queries](#access-recent-and-saved-queries) and apply them at any
time.

### Add query results to a dashboard or notebook

To capture the current query state, including the visualization and time range, use
the page actions above the query results. **Add to dashboard** and **Add to notebook**
are disabled until the query field contains text.

* Click **Add to dashboard** to add the current visualization as a panel on a
  dashboard. For the target dashboard and panel group selection flow, see
  [Copy a panel to a dashboard](/observe/dashboards/panels#copy-a-panel-to-a-dashboard).
* Click **Add to notebook** to add a log volume histogram and a panel that matches
  the selected visualization. See [From Logs Explorer](/navigate/notebooks#from-logs-explorer),
  and [Share a notebook](/navigate/notebooks#share-a-notebook) to give teammates
  access to the same captured state.

### Share a URL to a query

When investigating issues, you might want to share a defined query with other users,
or include a URL to a defined query in monitor annotations, runbooks, or other
on-call tools. Logs Explorer lets you copy a short URL to a defined query using
either a relative or absolute time range.

Relative time can help you understand the results of a query in a past period of
time relative to the current time, such as in the past 30 minutes. Absolute time is
better suited for comparing results across a fixed point in time, such as the results
of a query from last Monday at 8:00 AM versus that same query run today.

To copy a URL to a defined query:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.
2. [Construct a query](#filter-data-with-basic-queries) that returns the log data
   you want to view.
3. In the main header next to **Logs Explorer**, click
   <Icon icon="link-2" /> **Copy URL** and choose type of time range to use for the URL:

   * **Copy with absolute time range**: Create a link that runs a query against the
     date and time interval from when you copied the link. For example, if your query
     uses `1h` as the time interval, the time range is exactly one hour ago, based on
     the date and time you ran the query.

   * **Copy with relative time range**: Create a link that runs a query against the
     current time. For example, if your query uses `1h` as the time interval, the
     time range is exactly one hour ago from the current time.

The URL is copied to your clipboard based on your selection.

### Share a URL to a specific log

When troubleshooting issues, you might want to share a link to a specific log with
other users, rather than to a [defined query](#share-a-url-to-a-query).

To copy a URL to a specific log:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.
2. [Construct a query](#filter-data-with-basic-queries) that returns the log data
   you want to view.
3. Expand an individual log you want to share, and then click <Icon icon="link-2" />
   **Copy URL** to copy a URL to the selected log.

The URL is compressed to a short URL and copied to your clipboard. When another user
opens this URL, the results in Logs Explorer focus on the selected log only.

### Download logs

You can download logs from Logs Explorer with or without defining a
[search query](#filter-data-with-basic-queries). Each download includes up to
10,000 logs, and each log includes the `timestamp` and `_payload` fields.

To customize columns and rows in the downloaded data, use the
[`project`](/investigate/querying/query-logs/query-syntax#project) operator in a
query to display results in tabular format. To customize the tabular data and
complete aggregations in your query, use the
[`summarize`](/investigate/querying/query-logs/query-syntax#summarize) operator. Make
changes as needed, and then download the data.

To download logs:

1. In the navigation menu select
   **<Icon icon="compass" /> Explorers <span aria-label="and then">></span> Logs Explorer**.
2. Optional: [Construct a query](#filter-data-with-basic-queries) that returns
   the log data you want to view.
3. In the logs **Summary**, click the <Icon icon="ellipsis-vertical" /> three
   vertical dots icon, and then click **Download logs**.
4. Select the format for the data you want to download, then click **Download logs**.


## Related topics

- [Exploring Logs](/academy/courses/exploring-logs.md)
- [Exploring Logs 201](/academy/courses/exploring-logs-201.md)
- [Search and filter trace data](/investigate/querying/traces.md)
- [Search and query telemetry data](/investigate/querying.md)
- [Logging query syntax](/investigate/querying/query-logs/query-syntax.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.