Review → Syslog
Search and inspect the syslog records your collectors have ingested inbound from your network devices and servers. Use the filters to narrow down by time, source, and content, then open a record to see its full detail. This page is visible to anyone with app.collector.execute.
What you can do
- Search ingested syslog records across your estate with server-side filtering.
- Narrow results by date range, location, resource, source, host, app, severity, facility, and message text.
- Open any record to see its full metadata, raw message, and structured data.
- View only a single resource’s logs from that resource’s Syslog tab.
Filters
| Filter | Meaning |
|---|---|
| From Date / To Date | Limit results to a date range. |
| Location | Records attributed to a location. |
| Resource | Records attributed to a specific resource. |
| Resource Type | Records attributed to a resource type. |
| Tags | Records on resources carrying these tags. |
| Source IP | The address the record arrived from. |
| Host | The syslog hostname. |
| App | The syslog app-name. |
| Severity ≥ | Records at or above this severity. |
| Facility | The syslog facility. |
| Message contains | Records whose message contains this substring. |
| Reset | Clear all filters. |
Results are filtered and paginated on the server, so large result sets stay fast; records are always shown newest first.
Table columns
| Column | Notes |
|---|---|
| Time | When MisterShell received the record. |
| Location | The attributed location. |
| Resource | The attributed resource. |
| Source IP | The address the record arrived from. |
| Host | The syslog hostname. |
| App | The syslog app-name. |
| Severity | The syslog severity. |
| Facility | The syslog facility. |
| Message | The log message text. |
Common tasks
Find specific records
- Set the From Date / To Date range to the period you care about.
- Add filters — for example a Source IP, Host, or a Message contains substring — to narrow the results.
- Set Severity ≥ to show only records at or above a level when you want to focus on warnings or errors.
- Click Reset to clear every filter and start over.
Inspect a record
- Click a row to open its detail view.
- Review the full metadata: receive time, device time, priority/severity/facility, source IP, host, app, and the attributed resource and location.
- Read the raw message and any RFC 5424 structured data the record carried.
- If the message contained JSON, expand the pretty-printed tree to explore it.
View one resource’s logs
- Open a resource’s detail page and select its Syslog tab.
- Browse only that resource’s records. The location, resource, type, tag, host, and source-IP pickers are hidden here because the view is already scoped to the resource.
Permissions
- Read syslog records:
app.collector.execute.