WoluTools

Legal & Compliance

Turn log files into an incident timeline

Upload a TXT, LOG, JSONL or CSV log export. Timestamps are aligned, repeated errors grouped and leads listed. It shows where to look, not the root cause.

or drop them here

TXT, LOG, JSONL, CSV · Up to 50 log events · 64,000 extracted characters maximum
AI tool: needs an account and credits, cost shown before you start

No file at hand? See the prepared example

AI job1 credit = 1 small AI job3 AI creditsper job · Pro includes 40 credits a month · packs from €6.99
  • TXT / LOG / JSONL / CSV
  • Up to 50 log events
  • 64,000 extracted characters maximum
Prepared result preview · fictional sample dataFictional sanitized log
Source
2027-08-19T10:02:11Z gateway auth_failed user=[redacted]
2027-08-19T10:02:14Z gateway auth_failed user=[redacted]
Measured interpretation
  • First event: 2027-08-19T10:02:11Z
  • Repeated signature: gateway auth_failed

Incident workbook, signature-cluster CSV, redacted evidence HTML and investigation leads

BringTXT, LOG, JSONL, CSV
GetIncident workbook, signature-cluster CSV, redacted evidence HTML and investigation leads
PrivacyEncrypted source · 24-hour result

One clear job, from source to download

  1. 1

    Add the source

    Supported formats and limits are visible before the upload.

  2. 2

    Confirm the settings

    Review the exact source, options, units and access before processing.

  3. 3

    Inspect and download

    Check the preview and warnings, then unlock the complete package.

Turn a log export into a timeline to investigate

What you upload

You upload a log export as TXT, LOG, JSONL or CSV. One run takes up to 50 log events and 64,000 extracted characters, so filter the export to the period that matters first. Recognized secrets are redacted before anything is analysed. The job costs 3 AI credits and needs an account. The cost is shown before it starts, and reserved credits are released if it fails.

What comes back

You get an incident workbook, a CSV of repeated error signatures, an evidence HTML file with the redacted log lines and a list of investigation leads. Your timestamps and log excerpts are kept as supplied, and the source log is not changed. Review the redacted text before you paste it into a postmortem, because logs can hold secrets or personal data that were not recognized.

Time settings and the root cause

Fallback timezone applies to lines without an offset. Give the time zone of the host that wrote the log, not your own. Incident time window limits the timeline to the period you are investigating. Widen it if the first symptom sits at the edge. The signature labels are for review only. The tool never names a root cause. That call stays with the responders who know the system.

Questions before you run it

Does it name a root cause for the incident?

No. It groups repeated signatures, orders events into a timeline and lists investigation leads to check. Calling a cause stays with the responders who know the system.

What happens to logs that contain secrets or personal data?

Recognized secrets are redacted before anything is analysed, and the evidence HTML carries the redacted text. Logs are treated as untrusted input, so review the redacted output before pasting it into a postmortem.

How are timestamps in mixed formats handled?

They are normalized into a single ordering. Lines with no offset use the Fallback timezone you set, so give the timezone of the host that produced the log rather than your own.

What does the Incident time window control do?

It bounds the timeline to the period you are investigating, so events outside the window stay out of the workbook. Widen it if the first symptom sits at the very edge of the range.

How much log can go into one run?

Up to 50 log events and 64,000 extracted characters, from TXT, LOG, JSONL or CSV. Filter the export down to the window that matters before uploading.