Legal & Compliance
Turn log files into an incident timeline
Upload a TXT, LOG, JSONL or CSV log export. Timestamps are aligned, repeated errors grouped and leads listed. It shows where to look, not the root cause.
or drop them here
- TXT / LOG / JSONL / CSV
- Up to 50 log events
- 64,000 extracted characters maximum
2027-08-19T10:02:11Z gateway auth_failed user=[redacted] 2027-08-19T10:02:14Z gateway auth_failed user=[redacted]
- First event: 2027-08-19T10:02:11Z
- Repeated signature: gateway auth_failed
Incident workbook, signature-cluster CSV, redacted evidence HTML and investigation leads
One clear job, from source to download
- 1
Add the source
Supported formats and limits are visible before the upload.
- 2
Confirm the settings
Review the exact source, options, units and access before processing.
- 3
Inspect and download
Check the preview and warnings, then unlock the complete package.
Turn a log export into a timeline to investigate
What you upload
You upload a log export as TXT, LOG, JSONL or CSV. One run takes up to 50 log events and 64,000 extracted characters, so filter the export to the period that matters first. Recognized secrets are redacted before anything is analysed. The job costs 3 AI credits and needs an account. The cost is shown before it starts, and reserved credits are released if it fails.
What comes back
You get an incident workbook, a CSV of repeated error signatures, an evidence HTML file with the redacted log lines and a list of investigation leads. Your timestamps and log excerpts are kept as supplied, and the source log is not changed. Review the redacted text before you paste it into a postmortem, because logs can hold secrets or personal data that were not recognized.
Time settings and the root cause
Fallback timezone applies to lines without an offset. Give the time zone of the host that wrote the log, not your own. Incident time window limits the timeline to the period you are investigating. Widen it if the first symptom sits at the edge. The signature labels are for review only. The tool never names a root cause. That call stays with the responders who know the system.
Questions before you run it
Does it name a root cause for the incident?
No. It groups repeated signatures, orders events into a timeline and lists investigation leads to check. Calling a cause stays with the responders who know the system.
What happens to logs that contain secrets or personal data?
Recognized secrets are redacted before anything is analysed, and the evidence HTML carries the redacted text. Logs are treated as untrusted input, so review the redacted output before pasting it into a postmortem.
How are timestamps in mixed formats handled?
They are normalized into a single ordering. Lines with no offset use the Fallback timezone you set, so give the timezone of the host that produced the log rather than your own.
What does the Incident time window control do?
It bounds the timeline to the period you are investigating, so events outside the window stay out of the workbook. Widen it if the first symptom sits at the very edge of the range.
How much log can go into one run?
Up to 50 log events and 64,000 extracted characters, from TXT, LOG, JSONL or CSV. Filter the export down to the window that matters before uploading.