LogRaker Features Pricing Docs Release Notes Blog Download

← Documentation

Monitors

A Monitor is a pattern-matched watcher that highlights lines you care about across one or many Streams. Think of it as a long-running search: every line that arrives on a subscribed Stream is matched against a list of patterns; if any pattern matches, the line is recorded under the Monitor.

Use Monitors to catch:

  • panic, fatal, OutOfMemory across every service you're watching.
  • Domain-specific signals like payment.declined, customer.churn.detected.
  • Latency or status-code thresholds you've baked into log lines.

Creating a Monitor

+ ▸ New Monitor…

Fields:

  • Name - sidebar label.
  • Icon - any SF Symbol.
  • Color - the color the Monitor's match count uses, both in the desktop widget and on the Monitor's sidebar badge. Two modes: Fixed shows a picker - red (a warning), orange (caution), or green (good news); red is the default. By activity derives the color from the recent match rate instead: you set two thresholds and a shared window - amber over N matches, red over M matches, within the last X hours (1-24) - and anything below the amber threshold shows green. The color updates live as the rate climbs and falls, on the card, the badge, and the widget alike, so a wall of Monitors reads as a status board: green means calm, red means look here. In either mode the count is only tinted once there's at least one match; a zero count stays grey.
  • Patterns - one or more wildcard patterns (same syntax as Stream filters: *, ?, comma-separated). At least one is required - a Monitor with no patterns could never match, so the Save button stays disabled until a pattern is entered.
  • Actions - what the Monitor does on a match (pick any combination):
    • Show macOS notification - LogRaker posts a macOS notification banner each time a line matches this Monitor. Requires notification permission - see Notifications & the dock badge.
    • Highlight pattern matches - underlines the matched words within each row of the match list.
    • Play sound - plays a sound each time a line matches, independent of notifications so it needs no permission. The popup offers several synthesized alarms - Klaxon, Siren, Air Raid, Warble, Pulse, Sweep - built for the job, since none of the macOS system sounds are real alarms (they're intentionally omitted). ▶︎ previews the selection. The Repeat popup sets how many times it plays per match - Once, 5 times, or Until stopped (loops until you silence it). Prefer your own siren? Drop a custom .aiff/.wav into ~/Library/Sounds and it appears in the popup too. See Silencing alarms.
    • Flash the screen - throws a full-screen red alert: a pulsing red panel over a dimmed backdrop, floating above every app on your main display, for matches you can't afford to miss. Independent of the sound, and persistent until dismissed. See Silencing alarms.
  • Sources - which Streams (or whole Server Groups, Servers, or Stream Groups) this Monitor subscribes to. A Monitor scoped to a Server Group automatically picks up every Stream under any Server in that group, including ones added later; one scoped to a Stream Group covers every Stream in that folder, nested subfolders included. If you delete one of a Monitor's Sources, it's removed from the Monitor automatically. When a Monitor is left with no Source to watch - every Source deleted, or none added yet - a warning badge (an amber triangle) appears on its sidebar row, since the Monitor can't match anything until you give it a Source. The same badge appears on a Monitor that has ended up with no patterns (for example, restored from an older configuration) - and the Monitor's own pane shows the same triangle large, with the reason, in place of the usual waiting-for-matches message.

There is no Group field in this sheet - Monitors are grouped from the sidebar. Right-click a Monitor and use Move to Group (the submenu appears once you have at least one Monitor Group), or create the Monitor from a Monitor Group's own New Monitor… and it lands in that group.

Adding Sources by dragging

Besides the editor's Sources field, you can drag a Stream, Server, Server Group, or Stream Group from the sidebar straight onto the Monitor. Drop it anywhere in the Monitor's pane - on the match list, on the timeline, on empty space - and it is added as a Source pill in the strip at the top, which lights up as you drag to show where it will land - and what you dropped flies up into its new pill. Dropping something the Monitor already watches changes nothing.

A Monitor with no Sources yet frames its whole pane in a dashed border instead - drop the first Source anywhere inside it, and the strip appears at the top with its first pill.

Each pill carries a checkbox and an ×: clear the checkbox to stop watching that Source without removing it, or click the × to take it off the Monitor. Both are undoable with Cmd+Z.

Viewing matches

Click the Monitor in the sidebar. The right pane shows the same kind of table a Stream does:

  • Source pill - color-coded per Stream so a quick scan reveals which service the match came from.
  • Time - the line's timestamp in your chosen format, exactly as the Stream's own Time column shows it. Blank for a line that carries no timestamp.
  • Severity, Host and Process - each appearing only once a match actually carries it, so a Monitor over plain files is not given three empty columns. Severity is colored by level, as in a Stream.
  • Match - what is left of the line: the payload, without the timestamp and header the columns beside it already show.

Click a column title to sort by it, and again to reverse. While the list is sorted by anything other than Time, a strip above it says so: matches keep arriving and are placed in sorted order, but the list stops scrolling to keep up, since the newest match can sort to anywhere. 'Back to Time Order' returns to the newest-last order and starts following again. The seen/unseen divider only appears in that order too - it marks a boundary in a list running oldest to newest, which a sort does away with; acknowledged matches still read as dimmed wherever they land.

The Filter field's 'Minimum Severity' keeps only the matches at that level or worse. It is offered on a Monitor whose matches carry a severity, and a match that carries none is left out once you set one. Select 'All' to show everything again.

Columns fit their content on their own; drag a column's edge to set its width yourself. Columns reorder and hide from the header's right-click menu, where 'Size Columns to Fit' makes every column fit its content again, and each Monitor remembers its own arrangement.

The toolbar's 'Reload' button rebuilds the list: the Monitor's matches are discarded and every Stream it watches is read again from the beginning of what it currently holds. A match older than that, or one from a Stream that is not running, does not come back - so use it when you want the list re-read, not to tidy it up. ⌘Z puts the old list back.

'Clear' empties the list, reads nothing back, and starts the count fresh. It is the other half of a pair with 'Reset Count', which marks every match as seen and leaves the rows where they are; ⌘Z restores a cleared list.

Double-click any row to teleport to the Source. A plain double-click opens that line's Stream in the main window, scrolled to and selecting the matched line; ⌘-double-click opens it in a separate window instead. If the line has already scrolled off the Stream's live buffer, you land on the closest line by time.

To read a match in full, select it and press Space, ⌥-click it, or right-click it and choose 'Inspect Line' - see Inspecting a line.

Finding a match

The toolbar's 'Find' button opens a find bar above the match list, and puts it away when you press it again; Edit ▸ Find ▸ 'Find…' opens it too. Every match highlights where it stands, the one you are on is boxed and tinted more strongly, and 'Find Next' and 'Find Previous', the ‹ › buttons, or Return and Shift-Return step between them, and the count beside the ‹ › buttons, like the status bar under the list, shows your place. A hit that sits beyond the pane's right edge is scrolled into view as you step onto it, so a long line hides nothing. esc ends the search.

Find looks at the matched line as the table shows it, and never its timestamp. The comparison and the recent searches under the magnifying glass, and the token pills behind 'Insert', all work as they do in a Stream - see Finding a line.

A Monitor that has not matched anything yet opens the bar just the same, so you can arm a search and have the first hit arrive already highlighted.

Status & matches in the sidebar

Each Monitor's sidebar row summarizes what it is watching at a glance, without opening it:

  • a status LED for the worst status across the Streams the Monitor watches - green when all is well, yellow/orange while connecting or reconnecting, red the moment any Stream errors; and
  • a match badge (with the vibrating alarm bell) carrying the Monitor's unseen match count, in the Monitor's own color.

A Monitor scoped to a whole Server or Server Group covers every Stream under it, so the LED follows Streams added there later. A Monitor with no Source at all shows its amber warning triangle in place of the LED.

Collapse a Monitor Group - or the Ungrouped row - and it rolls the same summary up across every Monitor inside.

Notifications & the dock badge

Two separate signals let you notice matches without watching the window:

  • Notification banners - per Monitor, via the Show macOS notification toggle. When on, each match posts a standard macOS notification.
  • Dock-icon badge - a red count on LogRaker's Dock icon summing the new matches across all Monitors (everything since each Monitor's last Reset Count). It's always computed (independent of the per-Monitor toggle).

Both rely on macOS's notification permission for LogRaker, which it asks for once on first launch. If you declined that prompt - or never saw it - neither the banners nor the Dock badge appear, even though LogRaker is sending them: macOS silently drops them.

To enable them, open System Settings ▸ Notifications ▸ LogRaker and turn on Allow Notifications, plus Badge app icon for the Dock count specifically. When the Monitor editor detects they're off, it shows an Open Notification Settings… shortcut right under the notification toggle.

Deleting a Monitor that a widget shows asks for confirmation first, warning that the widget will be left showing 'Monitor not found'. A widget on another Mac shows that state on its own.

Resetting the count

Seen the errors and dealt with them? Reset Count acknowledges them: the Monitor's badge drops to zero and only matches arriving afterwards count as new. Nothing is deleted - the earlier matches stay in the list, dimmed below a Reset divider line that marks the point you acknowledged, so history stays readable while new hits stand out above it.

Ways to reset:

  • The Reset toolbar button, shown whenever a Monitor is selected (in the main window or a Monitor's own window). It acknowledges everything up to the selected line - the list normally follows the newest match with it selected, so that's a full reset unless you've deliberately selected an older line first. Greyed out while there's nothing new.
  • Right-click the Monitor in the sidebar ▸ Reset Count - or right-click a Monitor pane inside a Layout.
  • Right-click a Monitor Group ▸ Reset All Counts to reset every Monitor in the group at once.
  • Right-click a match line ▸ Reset from Here when a full reset is too much: that line and everything older dim as seen, while newer matches keep counting. The mark lives as long as the line does - see Monitor matches in Settings ▸ Streams for how many a Monitor keeps. With several lines selected, the newest one sets the boundary - and picking an already-dimmed line moves the divider back up, un-seeing the rows below it.

Everywhere the count appears - the sidebar badge, the Dock icon, the window title, and the desktop widget - shows the new-match count. A reset also silences that Monitor's looping alarm or screen flash, is undoable (⌘Z), and survives quitting the app.

Silencing alarms & timing

A looping sound (Repeat ▸ Until stopped) and the screen flash both keep going until you stop them. Any of these silences the active alarm:

  • Click the Monitor - its sidebar row, or its pane inside a Layout; that acknowledges it.
  • The blue Silence button that appears in the toolbar, just right of the +, whenever an alarm is active.
  • View ▸ Silence Alarms, ⌘⌥., or Esc.
  • Click the red overlay itself.

While an alarm is active, the Monitor's sidebar row shows a vibrating red bell next to its match count, so you can tell at a glance which Monitor is going off.

Two timing windows keep alarms from becoming obnoxious:

  • Cooldown - 5 seconds. After a Monitor sounds, it won't sound again for 5 seconds, so a burst of matching lines doesn't machine-gun the speaker. (A loop already running just keeps going.)
  • Warm-up - 10 seconds. When a Stream first connects it pulls its recent history; for the first 10 seconds of a Stream's output, alarms are suppressed so those old lines don't re-alarm every time you launch the app. The match list and dock badge still update - only the alarm is held off. (Reconnects pull no history, so they're unaffected.)

Live vs. historical

Matches accumulate from the moment the Monitor is created - historical lines from before that point are not retroactively matched. The match list is capped (a few thousand entries) and FIFOs older entries out as new matches arrive.

Monitor Groups

Like Source Groups and Layout Groups, Monitor Groups are just sidebar buckets. Drag Monitors into a group to keep them organized; the group has no effect on what gets matched.

Four ways to make one:

  • The + menu in the toolbar ▸ 'New Monitor Group…'
  • File ▸ 'New Monitor Group…'
  • Right-click an empty area in the sidebar ▸ 'New Monitor Group…'
  • Right-click the Monitors header ▸ 'New Group…'

All four open the same sheet, which asks for an Icon and a Name, and all four stay disabled until at least one Monitor exists.

Drag a Monitor onto a group's header to put it there, or right-click the Monitor and use 'Move to Group'; drop it on the Monitors header to take it back out. Right-click the group header for 'Edit Group…', to change the name or icon, or 'Delete Group'. Selecting the group's row and pressing Return renames it in place.

When you collapse a Monitor Group, its row summarizes the Monitors hidden inside it - rolling their status LEDs up into one, and ringing the alarm bell if any of them is alarming - so you can keep groups closed without losing sight of what needs attention. Expand it again and each Monitor shows its own.

The group's match badge shows the most urgent color present, and the total for that color alone. A red Monitor on 12 sitting beside a green one on 23 gives the group a red 12: the number you would act on. Counts in different colors are never added together, since the sum would describe a group of matches that does not exist.

Select a Monitor Group to see an overview of what's in it: every Monitor with its Source count, pattern count, and a Matches badge carrying that Monitor's unseen count in its own color. The badges update live as matches arrive, and clear when you reset a Monitor's count.

To watch several Monitors at once without opening each one, make a Dashboard - a Layout kind that shows Monitors as widget-style cards and can be opened in its own window. See Dashboards.

Desktop widget

LogRaker ships a widget for your Mac desktop and Notification Center, so you can keep an eye on your Monitors without the app's window in front of you.

To add it, right-click the desktop (or open Notification Center) and choose Edit Widgets, then find Log Monitors in the gallery. Launch LogRaker at least once first so it appears.

The widget comes in three sizes:

  • Small - one Monitor: its match count and the time of its last match. Choose which Monitor it shows from the widget's Edit sheet (right-click the widget ▸ Edit Widget ▸ Small size); leave it unset to show the first Monitor in sidebar order.
  • Medium & Large - a grid of cards, one per Monitor, each showing its name and match count; the Large size (and any card with room) also shows the time of the most recent match. Choose which Monitors appear at each size in the Edit sheet (Medium size / Large size); leave them unset to show your Monitors in sidebar order.

Each Monitor's match count is shown in the Color you pick for it in the Monitor editor - red, orange, or green - so a "good news" Monitor can read green instead of alarm-red. The same color is used for that Monitor's badge in the sidebar.

A Monitor that's currently sounding a looping alarm or flashing shows a red bell in the widget, the same as in the sidebar. Click any Monitor to open LogRaker and jump straight to it.

While LogRaker is running, the widget updates live as matches arrive. Only the app actually watches your logs - the widget just shows what the app last shared with it - so if LogRaker hasn't run for a while (about half an hour), the widget dims and shows a small sleep badge in the corner to signal the numbers may be out of date. Open LogRaker to bring them current. (The counts are the live ones LogRaker keeps while it runs - see Live vs. historical.)

© 2026 Thomas Gumz · Native macOS log monitoring Features Pricing Download Docs Blog Changelog About Privacy

Also by Thomas Gumz: PanoPaper, your security cameras as live video wallpaper.

Amazon Web Services, AWS, Amazon CloudWatch, and Amazon S3 are trademarks of Amazon.com, Inc. or its affiliates. Google Cloud and Firebase are trademarks of Google LLC. Supabase is a trademark of Supabase, Inc. LogRaker is an independent product and is not affiliated with, endorsed by, or sponsored by Amazon, Google, or Supabase.