Skip to content
User Guide

Review → Syslog

Search and inspect the syslog records your collectors have ingested inbound from your network devices and servers. Use the filters to narrow down by time, source, and content, then open a record to see its full detail. This page is visible to anyone with app.collector.execute.

What you can do

  • Search ingested syslog records across your estate with server-side filtering.
  • Narrow results by date range, location, resource, source, host, app, severity, facility, and message text.
  • Open any record to see its full metadata, raw message, and structured data.
  • View only a single resource’s logs from that resource’s Syslog tab.

Filters

FilterMeaning
From Date / To DateLimit results to a date range.
LocationRecords attributed to a location.
ResourceRecords attributed to a specific resource.
Resource TypeRecords attributed to a resource type.
TagsRecords on resources carrying these tags.
Source IPThe address the record arrived from.
HostThe syslog hostname.
AppThe syslog app-name.
Severity ≥Records at or above this severity.
FacilityThe syslog facility.
Message containsRecords whose message contains this substring.
ResetClear all filters.

Results are filtered and paginated on the server, so large result sets stay fast; records are always shown newest first.

Table columns

ColumnNotes
TimeWhen MisterShell received the record.
LocationThe attributed location.
ResourceThe attributed resource.
Source IPThe address the record arrived from.
HostThe syslog hostname.
AppThe syslog app-name.
SeverityThe syslog severity.
FacilityThe syslog facility.
MessageThe log message text.

Common tasks

Find specific records

  1. Set the From Date / To Date range to the period you care about.
  2. Add filters — for example a Source IP, Host, or a Message contains substring — to narrow the results.
  3. Set Severity ≥ to show only records at or above a level when you want to focus on warnings or errors.
  4. Click Reset to clear every filter and start over.

Inspect a record

  1. Click a row to open its detail view.
  2. Review the full metadata: receive time, device time, priority/severity/facility, source IP, host, app, and the attributed resource and location.
  3. Read the raw message and any RFC 5424 structured data the record carried.
  4. If the message contained JSON, expand the pretty-printed tree to explore it.

View one resource’s logs

  1. Open a resource’s detail page and select its Syslog tab.
  2. Browse only that resource’s records. The location, resource, type, tag, host, and source-IP pickers are hidden here because the view is already scoped to the resource.

Permissions

  • Read syslog records: app.collector.execute.