Docs » View problem details in an individual log

View problem details in an individual log 🔗

The previous topic, Filter by fields from logs, filtered logs to find the error that appeared with the greatest frequency. Clicking the most frequent error value helps you focus on logs that contained the could not retrieve product error.

After you find log records that contain a specific area, view the contents of an individual record to get a precise view of the data related to the problem.

To view the contents of an individual log record, follow these steps:

  1. Click a log record line in the Logs table to display the Log Details panel. This panel displays the entire record in JSON format as well as a table of each field and its value.

  2. To do more with a particular field in the table, hover over the field value, then click the More menu. Log Observer displays a drop-down list with 5 options:

    • To copy the field value to the clipboard, select Copy

    • To filter to the Logs table so it only displays log records containing the selected value, select Add to filter.

    • To filter the Logs table so it doesn’t display log records containing the selected value, select Exclude from filter.

    • To create a new log processing rule based on the selected field, click Extract Field. To learn more about extracting fields to create log processors, see Transform your data with log processing rules.

    • To add the field as a new column in the Logs table, click Add field as column.

    • Select View <field_name> to go to the appropriate view in the Splunk Observability Cloud. For example, if you click a field related to Kubernetes, Observability Cloud displays related data in the Kubernetes Navigator. If you click fields related to APM, such as View trace_id or View span_id, Observability Cloud displays the trace or span in the APM Navigator.

The following screenshot shows you an example of viewing the contents of an individual log record:

Individual log details