Search and filters
Use filters to reduce a stream to the events relevant to one investigation.
Available filters
Section titled “Available filters”- one or more stream IDs;
- time range;
- case-insensitive message terms;
- exact host, service name, or service namespace;
- severity;
- repeatable
key:valuelabels; - Kubernetes namespace, deployment, pod, container, node, or cluster.
Start broad, then narrow
Section titled “Start broad, then narrow”- Select the stream and time window.
- Search a stable message fragment or error name.
- Add service and severity filters.
- Add labels or Kubernetes fields only when needed.
An empty result means no retained row matches all active filters. It does not prove the receiver has no traffic.
API equivalent
Section titled “API equivalent”The customer Stream API exposes the same main filters on GET /api/v1/logs, histograms, and facets. Use the public logId parameter for an exact event.