UTMStack

Search every log, from this morning or from last year, in one place

Log Explorer is where analysts search every stored event, from today's firewall logs to last year's sign-ins. Use filters or write SQL, and save the searches you run often.

UTMStack · Log Explorer
Log Explorer over the last 24 hours: the field list and log events from every source, each one expandable. Pick a data type to see its events over time, or switch to SQL to query the same data.
  • Filters or SQL

    Click to add filters, or switch to SQL, the standard database query language, with autocompletion for fields and keywords.

  • Cold data included

    Search older data in the cold tier the same way as recent data, with no snapshot restore.

  • Related events

    Open a log and pull up the events around it to see what happened just before and after.

  • Saved searches and tabs

    Save the queries you run often and keep several investigations open in tabs.

  • Table or chart

    Switch results between a table and a chart, choose the columns you need and resize them.

  • Raw and parsed side by side

    Every result keeps the original log line, and you can copy any event as JSON.

Investigate without waiting

Logs are stored in ClickHouse with hot and cold tiers, and cold data is searchable without a snapshot restore. That matters when an incident started months ago or an auditor asks for last year's records.

Search the way you think

Start with the search bar and point-and-click filters, or click any field value to filter on it. When you need counts, grouping or more complex conditions, switch to manual SQL mode with autocompletion. Saved searches keep a name and description so you can run them again later.

Follow the thread

From any log, open the related events to see what the same host or user did around that moment. Add a field as a column, copy the event as JSON, or ask the AI assistant, which can search the logs for you from a plain question.

Questions buyers ask

Can I search data that has moved to cold storage?

Yes. UTMStack keeps cold data searchable without restoring a snapshot first. You decide how long data stays in each tier, up to 5 years in total.

Do I have to learn a query language?

No. The search bar and filters cover most investigations. SQL is there for analysts who want it, with autocompletion, and the AI assistant can search the logs for you from a plain question.

Can I save searches I use often?

Yes. Saved searches keep the query with a name and description so you can run it again. Tabs let you keep several investigations open at the same time.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.