Analyze log files in seconds — paste your logs and get level counts, deduplicated error groups and an hourly timeline. Runs locally, so server logs never leave your machine.
2026-08-30T08:02:45.000Z ERROR Rejected order 4815: stock unavailable
2026-08-30T08:03:11.900Z ERROR Rejected order 1022: stock unavailableRejected order *: stock unavailable (2x)You have a 5,000 line tail and ten minutes. Paste it, find the one error that repeats 400 times, and chase it instead of the noise.
Compare error groups before and after a rollout to confirm the change introduced (or fixed) specific failures.
Because analysis is local, you can inspect logs that contain customer data instead of redacting them for an online tool.
Everything lands in one bucketWhy: Level-less log formats (like pure access-log lines with only an IP and status) have no recognizable level label.
Fix: Paste into Levels and accept the UNKNOWN bucket, or switch to the Timeline view which works off timestamps alone.
Two errors that look different grouped togetherWhy: Normalized grouping strips IDs/numbers on purpose so repeats collapse.
Fix: Check the raw log line for the true distinguishing field — grouping only needs to flag 'likely the same problem'.
Empty timelineWhy: No timestamps were detected in RFC-3339 or nginx access-log form.
Fix: Use the Epoch/millisecond columns of your log, or convert timestamps with the Timestamp tool first.
Line-based text: JSON logs, Java/Node style lines with a level label (DEBUG, INFO, WARN, ERROR, FATAL, TRACE), console-prefixed output, nginx access logs and generic timestamped lines. Each line is scored for level, timestamp and message separately.
ERROR/FATAL lines are grouped by a normalized message — parameter values, numbers and IDs are stripped, so 'Rejected order 4815: stock unavailable' and 'Rejected order 9999: stock unavailable' collapse into one group with a count.
When timestamps are detected, lines are bucketed into UTC hours with separate counts for all lines, errors and warnings. It's a quick way to spot error spikes around a deploy or a batch run.
Analysis covers up to 50,000 lines so the page stays fast. For bigger files, slice the relevant window or filter in your log tool first.
No. Logs are analyzed entirely in your browser. This is the safe way to inspect a log that contains live user data or internal endpoint names.
Yes — Copy Report produces a plain-text summary (totals, level counts, error groups) and Download saves it. Raw log lines are never sent anywhere.
Last reviewed September 2026 · DataFormatter team — this tool processes data locally in your browser.