Search Security Data
Find events, filter by field values, and drill into individual events. Core investigation skill for triaging alerts, correlating events across sources, and building evidence timelines.
Inspect Individual Events
Expand individual events to examine every field and value. Essential for forensic analysis and incident investigation when you need the full context of a security event.
Field Interactions and Refinement
Use contextual menus to filter and aggregate on field values, expand time windows, and interactively refine searches. Accelerates triage workflows by letting you pivot on any field value directly from results.
Save and Share Searches
Save threat hunting queries for reuse, share investigations with team members, and preserve query results for compliance documentation and incident reporting.
Export Data for Reporting
Export query results as CSV, JSON, or plain text for evidence collection, executive reporting, and sharing investigation findings with stakeholders outside LogScale.
Enrich Data with Lookup Files
Upload lookup files to enrich security events with additional context: map IP addresses to known threat actors, user IDs to names, or asset IDs to business owners. Critical for contextual investigations.