---
title: "Search production logs"
description: "Find production evidence across traces, spans, and sessions, then preserve the relevant case."
sidebar:
  label: "Search logs"
seo:
  title: "Search Production Logs | Judgment How-to"
  description: "Search Judgment Logs, filter traces and spans, inspect sessions and evaluation coverage, and export selected trace fields."
---

Use **Logs** to find and inspect traces, spans, and sessions in your project.

## Prerequisites

- Access to the target project and recorded production traces
- A time window and a useful clue, such as a customer ID, session ID, tool
  name, error message, or behavior
- Session IDs recorded by your instrumentation when investigating sessions

If no traces have arrived yet, start with [Instrument your
agent](/documentation/tracing/instrumentation).

## Choose a tab

| Tab | One row represents | Use it to |
| --- | --- | --- |
| **Traces** | An agent execution | Find a reported input/output, exception, behavior, or tagged case. |
| **Spans** | An individual operation within a trace | Compare model or tool calls across executions. |
| **Sessions** | Traces grouped by a session ID | Follow a conversation or workflow across multiple executions. |

Each tab has its own filters and saved views. Check the time selector when
switching investigations: an empty result can mean the evidence falls outside
the selected window.

## Find a trace

1. Open **Logs > Traces** and choose the relevant time range.
2. In **Filter traces...**, choose **Full Text Search** and enter a distinctive
   recorded phrase, such as `payment declined`.
3. Add **Customer ID =** with the affected customer's recorded ID, or
   **Session ID =** when you know the session. Use your actual values.
4. Inspect the matching rows' input/output previews, exceptions, duration,
   LLM cost, and judge results, then open a representative trace.

Build these filters with the field, operator, and value pickers; the example
is not a query-language string to paste into the search box. Add filters one
at a time so you can see which condition narrows the result.

Other useful filters include:

| Filter | Example investigation |
| --- | --- |
| **Error** | Use **exists** to find executions with recorded errors, or **contains** with a known message. |
| **Duration** / **LLM Cost** | Find slow or expensive executions using an explicit threshold and unit. |
| **Span Name** / **Span Attribute** | Narrow to an operation or recorded attribute such as a deployment value. |
| **Tags** | Return to a named collection of cases. |
| **Dataset** | Find traces associated with a selected dataset. |
| **Behaviors** | Find traces assigned a particular judge behavior. |
| **Automations** | Find traces for which an automation was invoked. |

- **Columns:** Open the table's column menu to choose visible fields and
  adjust their layout.
- **Sorting:** Select a supported column header. Some sorts may be unavailable
  for the current query.

### Add an attribute column

You need Developer access or higher to change attribute keys.

1. Open the column menu's **Attributes** section.
2. Select **Add attribute key** and choose or enter a recorded key.
3. Open a trace and compare its attributes with the new column. An empty cell
   does not mean every span lacks the attribute.

Where the selection is saved depends on the active view:

- **All traces:** Attribute keys are shared with the project.
- **Saved view:** Save changes to the view to retain its attribute columns.
  Applying a view leaves the project's default keys unchanged.

### Tag and open related evidence

1. Open a trace and use **Tags** in the header or overflow menu to manage tags.
2. Return to the table and filter by **Tags** to find related traces.

From an open trace, you can also:

- Use **Copy URL** to share its link with a teammate who has project access.
- Select **View Session** to open the surrounding session, when the trace has
  a session ID.

For help reading the evidence, follow [Investigate a failed trace](/documentation/monitoring/trace-investigation).

### Export selected traces

1. Select the trace rows you need using the table checkboxes.
2. In the selection bar, choose **Export > Download as JSONL**.
3. Choose the fields in the export column selector, then select **Export**.
4. Open the downloaded file and verify the expected trace records and fields.

This exports selected traces and the columns chosen in the export dialog.
Filtering the table alone does not select every matching trace, and visible
table columns are not a substitute for checking the export selection.

To preserve evidence for evaluation, use [Add production
traces](/documentation/datasets/production-traces) instead.

## Find an operation across traces

Open **Logs > Spans** when the question concerns a particular model call,
tool, or nested operation.

1. Set the time window and choose **Span Type = Tool** or **Span Type = LLM**
   in **Filter spans...**, as appropriate for your instrumentation.
2. Add **Span Name =** with the recorded operation name. You can also filter
   by duration, LLM cost, error, customer ID, session ID, or span attribute.
3. Use the column menu to expose **Span ID**, **Trace ID**, input/output,
   **Duration**, **LLM Cost**, and **Exceptions** as needed.
4. Open a row. Judgment opens its parent trace with that span selected.

Span duration and cost describe the selected operation, not the whole trace.
Inspect the parent and neighboring spans before attributing an execution's
total latency or cost to that one call. The Spans filter picker does not offer
the Traces tab's **Full Text Search** option.

## Follow a session

In **Logs > Sessions**, set the time window and filter by **Session ID**,
**Trace Count**, **Duration**, **Total Cost**, or **Behaviors**. Open a match:

- **Conversation:** Read the combined interaction across traces.
- **Tree:** Inspect individual traces and their spans.

Check trace boundaries when switching views. Both views rely on recorded
data; messages your agent never recorded will be missing.

### Check what a session evaluation covered

In the behavior panel, read the evaluation reason. Select its coverage control
(such as **Evaluated first 3 traces**), when available, to highlight the
evaluated traces in the tree.

A session can gain more traces after an evaluation. The result applies only
to the traces it covered. Missing results and evaluation errors do not mean
the session passed.

### Preserve the session evidence

- For investigation notes, copy the session ID from the header and record the
  project and relevant traces.
- For evaluation, follow [Add production sessions](/documentation/datasets/production-traces#add-production-sessions).
  Session capture uses a different dataset picker from trace field mapping.

## Verify and troubleshoot

- Open a matching row and confirm its recorded evidence supports the filter
  you applied. A table preview is a starting point, not the full execution.
- If results are empty, check the project and time window, then remove filters
  one at a time. Use the refresh control to request current results.
- If a session or **View Session** is missing, confirm the traces carry the
  intended session ID in your instrumentation.
- If values or results are incomplete, check whether the execution is still
  running and whether the relevant judge has produced an evaluation.
- If another person cannot open a link, confirm their project access. Copying
  a URL does not grant access.

## Next step

[Save a log view](/documentation/monitoring/saved-log-views) to reuse the
filters and layout for the next investigation.
