Ask a Question
Back to All

Is there a way to quickly set the start/end time filters to a small window relative to a specific event?

If not, this would be a killer feature (to know what else was going on in the system around the same time as an event of interest). At the moment my workflow often involves locating an interesting event, noting its timestamp then manually setting the start/end filters to -30/+30sec respectively of that event. It would be really handy to be able to do this automatically.

Asymmetry between Type->Find and Type->Exclude

Each event provides a drop down under "Type" that includes "Find" and "Exclude". When selecting "Find", the current behavior is to replace the existing query with something like "@EventType = 0xED5F661B". When selecting "Exclude", the current behavior is to add to the existing new signal (or a new new signal if there wasn't one before) a filter containing something like "Not(@EventType = 0xED5F661B)". This is not what I expected to happen. I expected either that both would add their respective query text to the same location: either the current query or the current (or new) new signal, but not one of each. Why is the current behavior the way it is? I would prefer that both modified the current query instead of the current/new new signal. I have two reasons for this. First, there is an easy way to make the current query into a filter in the current/new new signal but not the other way around. Second, the current query is reflected in the URL, which means that duplicating the browser tab also duplicates the query. In contrast to this, filters in a new signal are not copied to a duplicated browser tab. On a related note. I would prefer if selecting "Find" would add to the existing query instead of replacing it.

Typical setup for installation

In terms of your Enterprise licence, what is the typical setup for SEQ installation with particular regard to High Availability/Disaster Recovery. Especially if we are only limited to 3 installs on Dev/Staging/Production? Any advice here would be great.

Could not log in error

Hi, We have about 30 users using Seq. They all use Integrated Windows Authentication to log in. We have one user however, that receives the following error when trying to log in: "Could not log in An unhandled error occurred while serving the request (token: xxxxxxxxxxxxxxxxxx)." This use has been configured in Seq exactly the same as all the others that are working. Any ideas? Any place where I can check a log for more information? Thanks! Sean

Couldn't restore a backup

Hello, I'm trying to restore a configuration on another server, but it's failing with the error below: Could not restore backup: Error converting value "Pie" to type 'Seq.Server.Data. Documents.Monitoring.MeasurementDisplayType'. Path 'Charts[1].Queries[0].Display Style.Type', line 1, position 633. The version is 4.0.60. Is there any known issue with this version or it's caused by something else? Should I try upgrading Seq to the latest release? Thank you in advance.

Seq + Azure

Hello, Are there any options besides hosting Seq in a VM, such as running it in a container? Maybe it would be interesting to have a Seq offering in the Azure Marketplace. Thx

Seq is starting to slow down

Hi! Recently Seq has started slowing down due to an increasing volume of events. Diagnostics: Events arrived 3 783 /minute Events accepted 3 469 /minute Ingested data 14.34 MB/minute Range in RAM 1,25 days Count in RAM 3 516 167 events System memory utilization 85 % After scanning the ~3.5m events in RAM (which is just one day worth of events), it takes a very long time searching through older events that are stored on disk. So my question is what hardware you guys genereally recommend for 5+ million events/day? Thanks!

How to use the "API Filter"

Dear Team, How to use the "API Filter"? "Apply a custom filter on arrival to events written with the API key"? Please help for using Filter in the version : Seq 4.2.1113 Thanks

Azure support

Hi! I am a huge seq/serilog fan. I am working on a new project that is purely cloud based. I was hoping to use seq for central logging and was surprised to see there isn't any Azure web-app support other than as a virtual machine. (I prefer not to use azure vm due to maintenance / price concerns.) I feel like seq would be a great candidate for a cloud service. I was hoping to be able to either get seq setup under my own azure subscription or add it as an Enterprise Application. I would love to hear your thoughts on this. How much would would be involved in getting seq 'cloud-ready'? Is seq not a good saas candidate? Would you recommend I use a different serilog sink form here that writes to azure? Is there azure sink you recommend thats as easy to use as seq? Again, I'm a huge fan of Seq/Serilog. They are really great products! Thank you! -Eytan

Feature Request: Add time between logs filter

Hi. Would it be possible to add a field that displays the time between logs. It'd be nice to have access to the time elapsed between a request and the preceding one, without doing it manually. And why not add a filter to know which request was the most/less time-consuming. Many thanks

single-user license warning

I often open up multiple seq windows that can be on different chrome windows, in a vm, and sometimes in different browsers at the same time. I just noticed that there is a server status with the following message displayed: The single-user license only permits one user to access Seq. To maintain compliance with Seq's terms of use, purchase an appropriate license or limit access to a single person. If this message is displayed in error, please contact the Seq support team for assistance. Is this something I can ignore. I am pretty sure I am the only person using it.

Restore from backup file

We have accidentally deleted all logs before a specific date. We are trying to restore our SEQ instance from backup file but we could not do it. It just restored daily events. We want to restore all historic data before our unfortunate operation. How can we do it?

using aggregate function(Max, Min) along with distinct

Hi, I am trying to extract max response time of my each unique scenarios , and it is giving me the highest response time of all. ex. Scenerio 1 has 10 req, scenario 2 has 10 req , scenario 3 has 5 req etc and I want to extract highest reponse time of scenario 1 , 2 and 3, instead it is giving me the highest response time from all the scenario suppose scenario 1 consists the max response time then it is showing me 10 rows with highest response time of scenario. I need max of all 10 req from scenario 1 and 2 etc

Scaling seq for lots of events

I'm currently looking for a way to scale seq. The main issue is the number of events and looking back when data is not in memory. Currently with 16Gb of RAM, I can see about 6 hours of logs. I can add more ram, but even 64 gigs would allow me to see 1 day at most, I'd like to look for data for a week or more, and with Seq I'm not seeing the way. So, is there any way to speed up SEQ other than having lots of memory? 1. is it possible to index some types of events so they're always fast to find, or at least don't require scanning the entire database on disk? 2. Is it possible to scale to more than one server somehow?

Serilog only writing to Seq when console is open

When the console is running (with a Console.Readline()), the application writes to Seq. But if the application closes without the Console.Readline() then the Seq browser does not have time to receive all the logs, and only reports the first few. Any tips here would be great. Thanks, James

Logging object properties with nlog

Hi Trying to log properties so they are searchable using NLog. I know I can use @ to serialize objects in messages - but how to do the same for properties? Pseudo c# code that works (I can e.g. search for x.status=0 ): class MyClass { public int status { get; set; } }; var x = new MyClass(); log.Debug().Message("Write {@x}", x).Write(); Pseudo c# code no working (only x class name is serialized): class MyClass { public int status { get; set; } var x= new MyClass(); log.Debug().Message("Write Hi").Property("x", x).Write(); How do I make MyClass serailized so I can search i when logging it as a user Property Regards

Your Company details

Please can you let us have your Company details :

EventType on Dashboards

Hi, Is there a way to use EventType in Dashboard charts? I want to be able to display data on specific events, and I'd like to try to avoid adding in a specific parameter to differentiate. EventType does this brilliantly in the event view, but so far I've been unsuccessful in using it on the Dashboard. Thanks.

Query Execution Timeout

I did see this question: I'm currently using seq 4.2.839 and I'm running a query "select count(*) from stream group by Application". If I set the From-To time to the current day it returns without issue (and pretty fast 4-5 seconds). If I extend that time by a day I get "The query execution timeout of 00:01:00 was reached. In Admin -> Preferences -> Query timeout is currently set to 600. I'm not sure why it's still defaulting to 60. Thanks

insufficient space

Hi - We have received this error on our UAT site. Could you please help Server Status The disk holding Seq event storage has insufficient space; arriving events will be dropped.