# What happened to the logs explorer?

**URL:** <https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165>\
**Category:** Kibana\
**Created:** [December 18, 2024, 1:13pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165 "2024-12-18T13:13:05Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [December 18, 2024, 1:13pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/1 "2024-12-18T13:13:05Z")

</div>

So actually just recently discovered the "Logs explorer" beta feature and was super impressed by it: the way it tagged services and showed the agentname in the message was really user friendly. Now today we upgraded to 8.17 and I notice a big "Deprecated" notice on top of that page, saying that I should use the "Discover" page because all features from the explorer are ported to that page. But, if I then try the discover function, this is totally not the same as the previous versions of the logs explorer. Am I missing something or is the entire functionality of the logs explorer being discontinued?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a416a2cf8d978d315838bcfa3dd352295af14f4.jpeg)

---

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [December 18, 2024, 1:21pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/2 "2024-12-18T13:21:28Z")

</div>

For contrast, here is what it looks like in discover. Basically it boils down to "why does it show the message field instead of that summary field as it used to be?"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b785161d6fdff3c50c6f355c097c6bd38c420d1.png)

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [December 18, 2024, 1:38pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/3 "2024-12-18T13:38:34Z")

</div>

Hi @catn0b0t,

It shows only `message` in your case because it's selected in the fields sidebar. If you unselect it or start a new search, then Summary should appear.

---

<div class="post-metadata">

**Author:** ![ninoslavmiskovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninoslavmiskovic/32/113140_2.png) [@ninoslavmiskovic](https://discuss.elastic.co/u/ninoslavmiskovic)\
**Post date:** [December 18, 2024, 3:00pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/4 "2024-12-18T15:00:49Z")

</div>

Hey @catn0b0t

@jughosta is correct. Let me add a few more details about the contextual data presentation in Discover.

We introduced a contextual Discover in 8.16 that adapts the data presentation based on what you’re exploring—similar to what you saw in Log Explorer.

In 8.17, we tied this contextual experience to the navigation settings you select for new deployments. Soon we will allow on-prem users to choose their navigation and get the full contextual data experience.

We will evolve this experience further.

See the example here in Discover

 ![Skærmbillede 2024-12-18 kl. 15.59.17](https://us1.discourse-cdn.com/elastic/original/3X/1/2/1230b3ca71aed82c5e8236ff11b8c5743e0babf0.jpeg)

---

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [December 19, 2024, 10:15am UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/5 "2024-12-19T10:15:07Z")

</div>

Ok, this all sounds very promising, looking forward.  
For now I will try to use the explorer. What I most like about it are those tags. We have lots of data coming in at high rate from a large variety of sources and these tags really help a human eye to make sense out of it all.

---

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [December 19, 2024, 10:18am UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/6 "2024-12-19T10:18:25Z")

</div>

Thanks, that indeed shows the summary but unfortunately no tags as in the explorer view. The summary indeed contains the info about the service and the agent providing the data but this info is not tagged, making it less convenient for a human eye to browse through the data to spot trends or investigate specific issues.

---

<div class="post-metadata">

**Author:** ![ninoslavmiskovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninoslavmiskovic/32/113140_2.png) [@ninoslavmiskovic](https://discuss.elastic.co/u/ninoslavmiskovic)\
**Post date:** [December 19, 2024, 11:08am UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/7 "2024-12-19T11:08:13Z")

</div>

@catn0b0t

We will have the same tags in Discover. It is working the same way.

Here is a new screenshot:

Hope this helps 🙂

 ![Skærmbillede 2024-12-19 kl. 12.07.21](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb25b964c834154dab575a2722526987dc1f6b59.jpeg)

---

<div class="post-metadata">

**Author:** ![frans-wtax](https://avatars.discourse-cdn.com/v4/letter/f/ce73a5/32.png) [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Post date:** [November 17, 2025, 9:37am UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/8 "2025-11-17T09:37:16Z")

</div>

My main issue with this view is that it is still paginated.

I need something that replaces doing `tail -f` or just `tail -1000` on log files directly on the server.

Log lines should be sorted by timestamp ascending and it should be easy to just scroll through this back and forth, sort of like how the Logs view worked.

Is this on the roadmap?

Thanks!

Frans

---

<div class="post-metadata">

**Author:** ![frans-wtax](https://avatars.discourse-cdn.com/v4/letter/f/ce73a5/32.png) [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Post date:** [November 17, 2025, 9:46am UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/9 "2025-11-17T09:46:32Z")

</div>

Another issue we have is that `@timestamp` on its own is not granular enough to reconstruct the original order in which the log lines appeared in the log file. Is there an additional field we could add to “break the tie” when multiple records have the same timestamp, to make sure they appear in the original order?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 17, 2025, 12:07pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/10 "2025-11-17T12:07:38Z")

</div>

> [@frans-wtax](#):
>
> Is there an additional field we could add to “break the tie” when multiple records have the same timestamp, to make sure they appear in the original order?

If they are being collected by Filebeat and from the same file, you could use the offset field to sort.

---

<div class="post-metadata">

**Author:** ![frans-wtax](https://avatars.discourse-cdn.com/v4/letter/f/ce73a5/32.png) [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Post date:** [November 17, 2025, 12:15pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/11 "2025-11-17T12:15:41Z")

</div>

Will there be a way to customize the Summary?

I like the tag view, but I want to add my own fields as tags, which doesn’t seem possible at the moment. As soon as I add a field, the entire Summary is replaced. I’d rather have the choice to add a field as a tag OR as a column.

Thanks!

---

<div class="post-metadata">

**Author:** ![frans-wtax](https://avatars.discourse-cdn.com/v4/letter/f/ce73a5/32.png) [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Post date:** [November 17, 2025, 12:16pm UTC](https://discuss.elastic.co/t/what-happened-to-the-logs-explorer/372165/12 "2025-11-17T12:16:07Z")

</div>

Sadly, no, coming from journald. I don’t see any fields with that kind of info.
