Which log formats are recognised
The page uses built-in log parsers (combined, common, syslog, JSON). Every line is tried against each parser, and the format that matches the most lines wins. Supported formats:
- Apache/Nginx access log in Common Log Format and Combined Log Format, with or without a leading virtual host. Timestamps such as
[14/Sep/2026:08:21:05 +0000]become ISO 8601. - Nginx error log —
2026/09/14 08:21:05 [error] 1234#0: *88 ...— split into time, level, process and connection. - Syslog, both RFC 5424 (
<34>1 2026-09-14T...) and the older RFC 3164 / BSD format (Sep 14 08:21:05 host app[pid]: ...). When a<PRI>prefix is present, facility and severity are decoded from it. - JSON lines from structured loggers such as pino, bunyan, Serilog or Logstash. Common keys for time (
time,@timestamp,ts), level (level,severity) and message (msg,message) are found automatically; the remaining keys are shown askey=valuefields. Numeric pino levels like 30 or 50 are translated to INFO and ERROR. - Timestamp + level lines, the plain-text pattern most application frameworks print:
2026-09-14T08:21:05Z INFO [main] com.example.App - Started.
Reading the output
The Code view prints one entry per line with columns padded to a common width, so status codes, methods and paths line up and scanning by eye becomes possible. Indented lines that follow an entry, such as a Java stack trace under an ERROR line, are treated as continuations and kept with that entry rather than reported as unparsable.
The Table view turns the same records into a grid you can sort and filter, and export to CSV or Excel. Above the output a summary shows the detected format, the number of entries, counts by status class and code (for access logs) or by level, and the time range the lines cover.
There are no options for this format. Ctrl/Cmd+Enter re-parses after you edit, Ctrl/Cmd+Shift+C copies the aligned text, and Ctrl/Cmd+K opens the command palette — for example to jump to the stack trace formatter when the interesting part is an exception. Minify (Ctrl/Cmd+Shift+M) does not apply to logs.
When lines do not parse
Lines that do not fit the winning format are never dropped. They are printed exactly as written and a warning names the line number, which makes it easy to spot a truncated entry or a custom log_format field the parser does not expect. If no line matches any known format, the input is shown unchanged with a single warning.
Custom Nginx log_format definitions that only append fields to the combined format usually still parse, with the extra text kept in its own column. Formats that reorder the standard fields will not match; converting such logs to JSON at the source (Nginx supports escape=json) is the more robust fix. For JSON lines that you want to inspect in full, the JSON Lines formatter pretty-prints every object.
Examples
JSON lines from a Node.js service
Time, level and message become columns; every other key is listed as key=value.
{"time":"2026-09-14T08:21:05.120Z","level":"info","msg":"server started","port":8080}
{"time":"2026-09-14T08:21:09.004Z","level":"warn","msg":"slow query","durationMs":1840,"table":"orders"}
{"time":"2026-09-14T08:21:11.770Z","level":"error","msg":"payment failed","orderId":"ord_8f2k1","code":"card_declined"}2026-09-14T08:21:05.120Z INFO server started port=8080
2026-09-14T08:21:09.004Z WARN slow query durationMs=1840 table=orders
2026-09-14T08:21:11.770Z ERROR payment failed orderId=ord_8f2k1 code=card_declined
Nginx error log
Levels are upper-cased and the connection number (*88) gets its own column.
2026/09/14 08:21:05 [error] 1234#0: *88 open() "/var/www/html/favicon.ico" failed (2: No such file or directory), client: 203.0.113.7, server: example.com, request: "GET /favicon.ico HTTP/1.1"
2026/09/14 08:22:40 [warn] 1234#0: *91 an upstream response is buffered to a temporary file2026-09-14T08:21:05 ERROR 1234#0 *88 open() "/var/www/html/favicon.ico" failed (2: No such file or directory), client: 203.0.113.7, server: example.com, request: "GET /favicon.ico HTTP/1.1"
2026-09-14T08:22:40 WARN 1234#0 *91 an upstream response is buffered to a temporary file
BSD syslog from /var/log/auth.log
Host, program and PID are split out; the kernel line has no PID, so that cell stays empty.
Sep 14 08:21:05 web-01 sshd[2211]: Accepted publickey for deploy from 198.51.100.23 port 52144 ssh2
Sep 14 08:21:07 web-01 CRON[2290]: (root) CMD (/usr/local/bin/backup.sh)
Sep 14 08:21:09 web-01 kernel: eth0: link upSep 14 08:21:05 web-01 sshd 2211 Accepted publickey for deploy from 198.51.100.23 port 52144 ssh2
Sep 14 08:21:07 web-01 CRON 2290 (root) CMD (/usr/local/bin/backup.sh)
Sep 14 08:21:09 web-01 kernel eth0: link up
Application log with a stack trace
The indented exception line stays attached to the ERROR entry instead of being flagged.
2026-09-14T08:21:05Z INFO [main] com.example.App - Started in 3.2s
2026-09-14T08:21:06Z WARN [pool-1] com.example.Cache - Cache miss ratio 0.42
2026-09-14T08:21:07Z ERROR [http-3] com.example.Api - Request failed
java.net.SocketTimeoutException: Read timed out2026-09-14T08:21:05Z INFO main com.example.App Started in 3.2s
2026-09-14T08:21:06Z WARN pool-1 com.example.Cache Cache miss ratio 0.42
2026-09-14T08:21:07Z ERROR http-3 com.example.Api Request failed
java.net.SocketTimeoutException: Read timed out
Common errors and how to fix them
| Error | Cause | Fix |
|---|---|---|
No line matched a known log format (access log, Nginx error log, syslog, JSON lines, or "timestamp LEVEL message") | None of the lines fit a supported layout, often because the log uses a custom format or a prefix added by a log shipper. | Strip the shipper prefix (for example a Kubernetes or Docker timestamp) or switch the application to JSON logging. |
Line 2 does not match the Apache/Nginx access log (common/combined) format; kept as written | Most lines are access-log entries but this one is not: a truncated line, a startup message or a different log mixed in. | Usually nothing to fix. Remove unrelated lines if you want a clean table. |
Times look different from the original | Access-log timestamps are converted from 14/Sep/2026:08:21:05 +0000 to ISO 8601 so they sort correctly. | The offset is preserved, so the instant is unchanged; the raw line is still in your input. |
Frequently asked questions
How large a log file can I paste?
Tens of thousands of lines work comfortably because parsing is line-by-line in the browser. For gigabyte files a command-line tool such as GoAccess or lnav is a better fit.
Does it support Docker or Kubernetes logs?
If the container writes JSON lines or one of the supported text formats, yes. Remove any timestamp prefix that kubectl or Docker adds in front of each line first.
Can I export the parsed log?
Yes. The Table view can be sorted and filtered, then exported as CSV or an Excel file.
Which time zone are the times shown in?
The one in the log. Access-log times keep their original offset when converted to ISO 8601, and JSON or syslog times are shown as written; nothing is shifted to your local zone.