Reading the log panels
What each panel on the log dashboard shows, how to read it, and which question it answers — the summary numbers, volume by level, lines by level, errors over time, and top error patterns.
The log dashboard is four panels, and each one exists to answer a different question. A project group adds a fifth, By project, which ranks the group's apps against each other — see Logs on a group. This page is the reference for all of them — what the panel shows, how to read it, and what a healthy reading looks like. Every panel also carries this same explanation behind the ⓘ beside its title, so you never have to leave the page you are on.
Summary — is this healthy?
Four numbers: Lines, Errors, Warnings, and Error rate. The first three are counts. The fourth is the one to watch.
A raw error count cannot tell you whether an app is in trouble. Twelve errors in a hundred lines is an incident; twelve in two hundred thousand is a normal Tuesday. Error rate is the share of all lines that the application itself marked ERROR or FATAL, so it stays meaningful as the app grows and traffic changes.
| Error rate | Reading |
|---|---|
| Under 1% (green) | Normal. Errors happen; this is the background rate. |
| 1%–5% (amber) | Worth a look. Something is failing repeatedly. |
| Above 5% (red) | A meaningful share of everything this app says is a failure. |
Log volume by level — how much, and what kind?
How much the app printed over time, split by severity. Each colour is one level stacked on the others, so the height of a whole column is the total for that moment.
- A tall column is a busy minute, not necessarily a bad one — traffic and noise look the same here.
- Red appearing where there was none is the shape that matters. Reach for the time range and line it up against a deploy.
- A column that drops to zero and stays there usually means the container stopped, not that the app went quiet.
"GET / HTTP/1.1" 200 — which record a visit rather than a problem, and treating them as informational is what every log viewer does.Lines by level — what is the mix?
The same data as the chart above, but as a table you can read exact numbers off: each level, how many lines, a bar for its share, and the percentage. The footer totals every level shown.
- Read the share, not the count. The bar and the percentage are the point of this panel; the raw count is there so you can quote it.
- Sorted by volume, so the loudest level is always on top.
- The total is of what is shown — change the level filter and the total changes with it.
Errors over time — when did it start?
Errors and fatals on a scale of their own. This panel exists because of a specific problem: on the stacked volume chart, five errors underneath nine hundred info lines are a line one pixel tall. Here they are the only thing on the chart.
- A flat line at zero is the reading you want.
- A step up that never comes back down is usually a deploy that broke something.
- A single spike that recovers on its own is usually a dependency having a bad minute.
When a panel says "No data"
It means the query found nothing matching your filters in the range you picked — which is usually the honest answer rather than a fault.
| Check | Why |
|---|---|
| The time range | The most common cause by far. "Last 1 hour" on an app that was busy yesterday finds nothing. |
| The level filter | Set to ERROR on an app that is behaving will correctly show nothing. |
| The search box | A search term is applied to every panel, not just the log list. |
| Whether the container is running | Logs are collected from running containers. A stopped project stops adding lines, though its history stays for 30 days. |
Going deeper
These four panels are deliberately fixed — they answer the questions people ask most, without anyone writing a query. When your question is more specific than they allow, open Open full dashboard and pick Drilldown from Grafana's own nav: it runs Logs Drilldown on your own logs, with a live tail, a patterns view, and a breakdown by every label a line carries.