Jump to Content
DevOps & SRE

Announcing new simple query options in Cloud Logging

April 25, 2022
Charles Baer

Product Manager, Google Cloud

When you’re troubleshooting an issue, finding the root cause often involves finding specific logs generated by infrastructure and application code. The faster you can find logs, the faster you can confirm or refute your hypothesis about the root cause and resolve the issue. Today, we’re pleased to announce a simpler way to find logs in Logs Explorer. 

Making querying even easier

Over the past 2 years, we heard feedback that many users needed simple free text search to find their logs. We also heard that users wanted to build a query using the dropdown selectors. We took all that feedback to heart and made many critical changes to the Logs Explorer to address this feedback and make searching logs even easier.

  1. Simple text search – a new simple text search box for global text searches

  2. Advanced query – a new toggle to show/hide the Logging query language for the query

  3. Date/time picker – the date/time range picker is now a part of the query builder

  4. Date/time preferences – the date/time display now respects date/time preferences set in the Cloud Console settings

  5. Dropdown selectors – prominently display the resource, logName and severity dropdown selectors

  6. Dropdown selector state – maintain the state in the resource, logName, severity, and free text search boxes whether building query via dropdown or by editing the Logging query language

  7. Default summary fields – a new option to disable default summary fields for a more basic log view

https://storage.googleapis.com/gweb-cloudblog-publish/original_images/01.logs_explorer_simple_mode_query.gif

Simple text search

The new text search box performs global free text searches across your logs for the strings added to the text search box. For example, a simple “POST OR GET” will find any logs including the text “POST” or “GET” in any log field.  

https://storage.googleapis.com/gweb-cloudblog-publish/images/02.simple_text_search.max-2000x2000.jpg

Additionally, you’ll see your query results highlighted both in the log summary line and the individual log entry itself. 

https://storage.googleapis.com/gweb-cloudblog-publish/images/03.log_results_text_highlight.max-1600x1600.jpg

Show/hide query toggle

The new features simplify the query experience for many users, but the Logs Explorer still needs to allow users to to write complex queries for advanced use cases. That’s why we added the Show/hide query toggle which expands and closes the Logging query language behind the query. 

You can use the Show/hide query toggle when the dropdowns just don’t cut it for your use case and you need to build conditional logic or regexes into your queries. You can update the Logging query language directly by selecting the Show/hide query toggle.

https://storage.googleapis.com/gweb-cloudblog-publish/original_images/04.logs_explorer_simple_query_mode_show_query.gif

Date/time picker

We moved the date/time picker location to be featured prominently as the first item in the query builder which makes it easier to find. While this move represents a relocation in the Logs Explorer user interface, we have a series of improvements that the team is actively developing to make it even easier to find the right logs for a date/time range.

https://storage.googleapis.com/gweb-cloudblog-publish/images/05.date_time_range_selector.max-1100x1100.jpg

Date/time display based on Cloud Console settings

Whether you’re a developer, DevOps engineer, SRE, or anywhere in between, working with dates can be difficult because of the different representations. With this change, the Jump to time and Enter custom range options in the date/time range selector will now respect your date and time format preferences set in the Cloud Console settings. This means, if you select mm/dd/yyyy or dd/mm/yyyy in your Cloud Console settings, you’ll see the date/time options in that format. When you select a 24-hour time format or an AM/PM time format, you’ll see the time options in your selected format.

https://storage.googleapis.com/gweb-cloudblog-publish/images/06.date_time_preferences.max-1400x1400.jpg

Resource, logName, and severity dropdown selectors

The Logs Explorer now prominently displays the dropdown selectors for resources, logNames and severity. These dropdown selectors have also been improved so that they run the query each time a selection is made. This makes it easier to narrow logs quickly with each dropdown selection. Together, these changes make the dropdown selectors easier to find and more responsive.

https://storage.googleapis.com/gweb-cloudblog-publish/original_images/07.logs_explorer_simple_query_mode_resource_selectors.gif

Keeping the Logging query language and dropdowns in sync

When you use the resource, logName, severity dropdowns or add search text, Logs Explorer now builds a Logging query language query for you. For basic queries you don’t even need to look at the Logging query language. For more complex queries, you can edit the query language directly. 

Here’s the interesting part: when you edit the query directly, the resource, logName, severity dropdowns and search text will be updated to match the Logging query language terms if they can be parsed and don’t include complex logical conditions. 

For example, if you use the Show logs toggle to show the Logging query language and add the severity=ERROR, the severity dropdown is updated to show that ERROR is selected.

https://storage.googleapis.com/gweb-cloudblog-publish/images/08.show_query_severity_selector.max-1100x1100.jpg

Next, if you select  “DEBUG” from the severity dropdown, the query is updated to severity=(ERROR OR DEBUG).

https://storage.googleapis.com/gweb-cloudblog-publish/images/09.severity_selectors.max-1100x1100.jpg

Maintaining the query state regardless of whether you’re selecting from the dropdowns or typing in queries means there is one less detail to remember when you’re querying your logs.

Disabling default summary fields for a basic log view

The Logs Explorer adds default summary fields to the log results to highlight useful information and make it easy to take action directly from the log line. For example, on App Engine logs, the default summary field chips highlight the latency which can help you more easily filter logs.

https://storage.googleapis.com/gweb-cloudblog-publish/images/10.custom_summary_fields.max-1000x1000.jpg

Logs Explorer also enables you to add your own custom summary fields to the log lines so you can view what’s most important to you about the log lines. 

We’ve heard feedback that sometimes all that’s needed is the raw text of logs. To show raw text logs, we’ve added a toggle to turn off/on the default summary fields for your log results for the duration of your session. By turning off the default summary fields, you’ll see only the raw text logs summary. To turn the summary fields back on, simply enable the toggle or start a new Logs Explorer session in a new tab.

https://storage.googleapis.com/gweb-cloudblog-publish/original_images/11.logs_explorer_simple_query_mode_hide_default_summary_fields.gif

The road ahead

We’re committed to making Logs Explorer where you can troubleshoot your applications running on Google Cloud. Over the coming months, we have many more changes planned to make Logs Explorer both easier and more powerful for users. If you haven’t already, get started with the Logs Explorer and join the discussion in our Cloud Operations page on the Google Cloud Community site.

Posted in