Files
peardata/user-guide/logs.md
T
Raven Scott 5521f2952a
CI / test (push) Successful in 1m1s
Release rolling / release (push) Has been cancelled
Update Docs
2026-07-19 13:35:19 -04:00

2.4 KiB

Logs

The Logs tab is a searchable stream from the active agent: host journal (default), anomalies, and the agent audit trail.

Layout

Region Role
Header Follow (auto-refresh) · Refresh
Sources Journal · Anomalies · Audit
Time 15m / 1h / 6h / 24h window
Search Message substring; journal Max priority + Unit
Stream Time · severity · unit · message · actions

Sources

Source Who What
Journal (default) Admin Host journalctl (Linux; on by default)
Anomalies Viewer+ Threshold / z-score events
Audit Admin Mutating RPC trail (data/audit.log)

The tab prefers Journal whenever your role allows it (including after you connect as admin). Non-admin sessions fall back to Anomalies; Journal/Audit tabs stay disabled until you have admin.

Search & follow

  1. Open Logs (defaults to Journal when admin).
  2. Pick a time window.
  3. Type in search (/ focuses the field; Esc clears).
  4. Journal: optional Max priority (and higher) and Unit (e.g. peardata.service).
  5. Search or wait for debounce; Clear resets filters.
  6. Follow polls every 5s; Refresh / r runs once. f toggles Follow.
  7. Copy exports visible lines; per-row Copy for a single line.
  8. Anomaly rows: Show / Correlate → Charts (same as Alerts).
  9. Load more appears when the agent returns a cursor (anomaly/audit).

Match text is highlighted in the message column.

Host journal

Installer setup (default):

  1. peardatasystemd-journal
  2. Unit SupplementaryGroups=systemd-journal
  3. PEARDATA_JOURNAL=1 in .env / unit Environment

Disable with PEARDATA_JOURNAL=0. Non-Linux agents report journal as unsupported.

See CONFIGURATION and SECURITY.

Keyboard

Key Action
/ Focus search
Esc Clear search (when focused)
r Refresh
f Toggle Follow

API

GET /api/v3/logs?source=journal&q=error&limit=100

Default REST bind: http://127.0.0.1:18888. RPC: queryLogs. Audit/journal require admin over P2P.

vs Alerts

Alerts Logs
Focus Live anomaly feed + notifications Searchable multi-source history
Sources Anomalies only Journal + anomalies + audit