Log Analysis Online is a browser-based log inspection tool for access logs and JSON Lines files. It runs entirely in the browser, so log files can be opened, parsed, searched, filtered, summarized, and visualized without sending data to a server.
- Opens local log files directly in the browser.
- Parses JSON Lines and common access log formats.
- Searches raw log lines with literal text matching.
- Filters parsed fields by text, selected values, or time ranges.
- Shows parsed rows with configurable columns.
- Displays row details for closer inspection.
- Summarizes selected fields in statistics mode.
- Visualizes log volume over time when a timestamp field is available.
- Stores field mapping presets in local browser storage.
- JSON Lines
- Nginx access logs
- Apache access logs
- Lighttpd access logs
- Tomcat access logs
- Morgan combined logs
- Gunicorn access logs
- Traefik access logs
- Envoy access logs
- uWSGI access logs
- HAProxy HTTP logs
Plain text files such as .log, .txt, .json, and .ndjson can be selected from the browser.
Open the website in a modern browser, then add a log file in one of two ways:
- Drag the file onto the upload area.
- Click the upload area and choose a file from the file picker.
After a file is selected, the file name and size are shown below the upload area. The app processes the file locally and displays progress while parsing.
Use Choose parser to select the format that matches the log file.
Recommended choices:
- Use JSON Lines for newline-delimited JSON logs.
- Use Nginx access for common Nginx access log lines.
- Use Apache access for common Apache access log lines.
- Use the matching named parser when logs come from Lighttpd, Tomcat, Morgan, Gunicorn, Traefik, Envoy, uWSGI, or HAProxy.
If the wrong parser is selected, lines may appear as unparsed. You can choose another parser and parse the same file again.
When the selected parser exposes timestamp-like fields, the Time field control appears.
- If only one supported time field is detected, it is selected automatically.
- If multiple fields are available, choose the field that represents the event time.
- If the app shows Unsupported time format, the selected field cannot be used for time range filtering or visualization.
After the parser and time field are ready, click Parse log.
After parsing, the Field mapping panel lets you decide how each parsed field should behave in filters.
Available field types:
- string: shows a text input. Use it when you want to filter by text contained in the field.
- list: shows a multi-select dropdown. Use it for fields with repeated values, such as status, method, host, or source address.
- time: reserved for the detected timestamp field. Only one field can be used as time.
The preset controls help reuse field mappings:
- Preset selects a saved mapping.
- Save as saves the current mapping under a new name.
- Update replaces the selected preset with the current mapping.
- Delete removes the selected preset from local browser storage.
Presets are stored in the browser on the current device.
The toolbar filters the parsed result set.
Use the raw line search box to search the original log text. Search is literal text matching, so the text is matched as written.
When search results are available:
- The result counter shows how many lines match.
- Previous and next controls move through matching rows.
- Matching text is highlighted in the raw line column.
Field filters depend on the field mapping:
- string fields show a text input with
contains.... - list fields show a dropdown with checkboxes.
- time fields show a date range picker with From ~ To.
For checkbox dropdowns:
- Use Select all to select every value.
- Use Invert to flip the current selection.
- Use All to clear the restriction and include all values.
- Use OK to apply the selection.
- Use Cancel to close without applying changes.
Use Reset to clear search text, field filters, and time range filters.
Default is the main log inspection view.
It shows:
- A virtualized table of matching log lines.
- Parsed columns such as line number, time, remote address, method, path, status, bytes, referrer, user agent, and raw line, depending on the parser and visible column settings.
- A result count showing either total parsed lines or filtered matching lines.
- A detail panel for the selected row.
Click a row to inspect it. The detail panel shows:
- The original line number.
- Whether the line was parsed successfully.
- Parsed field values.
- The full original log line.
Use the column dropdown to choose which columns are visible:
- Check or uncheck individual columns.
- Use Select all to show all columns.
- Use Invert to reverse the current column selection.
- Click OK to apply the column selection.
If the table is wider than the screen, scroll horizontally or drag the table area with the mouse.
Stats summarizes filtered log lines by one or more fields.
Use Group By to choose the fields to summarize. Each selected field creates a statistics panel.
Each statistics panel shows:
- The selected field name.
- The number of unique values.
- The number of filtered lines used for the summary.
- A table of value counts.
- A Download button for exporting that field summary as a CSV file.
Stats always use the current filtered result set. If search or field filters are active, the statistics update to match the filtered lines.
Common uses:
- Group by status to find frequent HTTP status codes.
- Group by path to find common endpoints.
- Group by remote address to find active clients.
- Group by user agent to inspect client patterns.

Visualize shows log volume over time when a supported timestamp field is available.
It displays:
- A line chart of log lines per minute.
- The number of minute buckets.
- The total number of filtered lines included in the chart.
- A tooltip for inspecting the count at a specific time.
- A zoom slider for narrowing the visible time range.
Visualization also follows the current filters. For example, you can filter to a specific status code or path, then switch to Visualize to see when those matching requests happened.
If no parsed timestamps are available, the view shows an empty state. Try selecting a parser with a supported time field, choosing the correct Time field, or clearing filters.
All processing happens locally in the browser. The selected log file is not uploaded by the application.
This website is a static application. To deploy it, serve the directory that contains index.html and the assets/ folder.
Example static site root:
index.html
assets/
For a quick local preview, run this command inside the static site directory:
python -m http.server 8000Then open:
http://localhost:8000/
Use an Nginx server block that points root to the static site directory:
server {
listen 80;
server_name example.com;
root /var/www/log-analysis-online;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
}The same files can be hosted by any static file server, including GitHub Pages, Caddy, Apache HTTP Server, Netlify, Vercel static output, or an object storage bucket configured for static website hosting.
Log Analysis Online is designed for local browser-side inspection. It does not require a backend service to parse, filter, summarize, or visualize selected log files.


