> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Search Logs

> Explore collected tables and run queries in Log Search.

Open [Log Search](https://app.cotool.ai/platform/logs) from the main navigation, or use the **Log Search** button on the [Log Ingest overview](https://app.cotool.ai/platform/log-ingest).

## Explore and query

1. Find a table in the tables sidebar.
2. Expand it to inspect its columns and types.
3. Insert a starter query from the table, then adjust the fields and filters.
4. Select **Run** and inspect the results or query error.

Cotool Logs uses ClickHouse SQL. Use the actual table and column names shown in your workspace. Include a time filter when investigating a specific period, and use SQL `LIMIT` to keep exploratory results manageable.

An empty result is not proof that the activity did not happen. Verify that the relevant stream is enabled, that ingestion has reached the event time, and that your filters match the source's schema. See [Monitor Log Ingestion](/log-ingest/monitoring).

## Reuse a query

**History** lets you return to queries run in your browser. This history is stored locally in the browser; it is not a shared query library.

Use the share-link control to copy a link containing the query text. Review the SQL before sharing it, especially if you included sensitive values. The link shares the query, not a frozen copy of the results.

## Move from investigation to detection

Once you understand the relevant events and fields, use the [Detections Platform](/detections-platform/overview) to build repeatable logic. Include the data source, time window, suspicious condition, and known benign exceptions when describing the detection you want.

[Back to Cotool Log Ingest](/log-ingest/overview)
