On This Page

Home / Search/ Explore/Inspect Your Cribl Search Log Datasets

Inspect Your Cribl Search Log Datasets ​

Understand your logs before searching, so you can pick the right Log Datasets, know their fields, and build on previous analyses.


Highlights ​
  • From the Logs page, select a Log Dataset to see its contents, statistics, history, and more.
  • Use that info to pick a starting point for an investigation, reuse trusted queries, or spot ingest issues.
  • Cribl-hosted Log Datasets give you richer insights into fields than federated Datasets.

Explore Your Log Datasets Before Running a Search ​

Reviewing your Log Datasets beforehand lets you:

  • Decide what fields matter most for your investigation.
  • Reuse searches, Dashboards, and Notebooks instead of starting from scratch.
  • Catch ingest and parsing issues before they affect analysis.

If you’re unsure where to start in an environment with a lot of logs:

  • Prefer Datasets with higher recent search activity.
  • De-prioritize low- or no-usage Datasets unless you have a specific use case.
  • Look up a Dataset’s top users to find people that can share proven query patterns.

Visibility depends on your permissions, so you’ll only see Datasets you’re allowed to access.

To verify that events are arriving, parsing, and routing as expected in real time, see Live Data.

See Dataset Details and Statistics ​

Explore your Log Datasets and federated Datasets:

  1. Go to Logs: On the Cribl.Cloud top bar, select Products > Search.
  2. Under Available Datasets, select a Dataset.

What you see in the details panel depends on the Dataset type.

Log DatasetsFederated Datasets
Search History ​

Review recent log searches for proven starting points. Reuse what works, then refine.

For more information and ideas, see View Log Search History and Reuse Search Results.

Saved Searches ​

Open saved searches to apply team standards or keep results more consistent across users.

Dashboards ​

View Dashboards that reference this Dataset before you write a custom query.

Notebooks ​

Open related Notebooks to see or continue earlier investigations.

Explore Fields in Log Datasets ​

Cribl-hosted Log Datasets offer deep insight into their structure, so you can pick fields that work well in filters, group-by clauses, or aggregations.

  1. Go to Logs: On the Cribl.Cloud top bar, select Products > Search.
  2. Under Available Datasets, select a Log Dataset you want to inspect.

    Log Datasets are marked with the lakehouse icon Lakehouse .

  3. In the resulting details panel, look at the Fields section.

    If the Fields section is empty, select Retry to load the metadata.

    If there’s no Fields section at all, you’re looking at a federated Dataset. Select a Log Dataset instead.

Each field has the following statistics, filtered for the selected time window:

Field StatisticDescription
FieldField name you use in queries.
TypeData type, such as string, numeric, boolean, object, or array.
UniquesHow many distinct values the field has in the selected time window.
PresenceWhat percentage of all events contain this field in the selected time window.
Null or emptyHow often values are null or empty in the selected time window.

Use those statistics to find:

  • High-presence fields for filters and joins.
  • Low-cardinality fields for group-by clauses.
  • Weak fields with many null or empty values.

Select a field to drill down into details. For example, you can add the field to a query, or aggregate on it.