LogRaker Features Pricing Docs Release Notes Blog Download

← Documentation

Streams

A Stream is what produces lines into the right-pane tail view. Every Stream belongs to one Source (Local / SSH / GCP / Firebase). One Source can have many Streams.

Creating a Stream

+ ▸ New Stream…

Fields depend on the parent Source's kind:

  • Name - sidebar label.
  • Icon - any SF Symbol.
  • Source - pick from your configured Sources.
  • File (Local / SSH) - absolute path to the file to tail. For local Sources, the Browse… button opens a picker (and captures a security-scoped bookmark under the App Store sandbox). For SSH Sources, the path is typed - it's sent verbatim to the remote shell.
  • Source - File or Journal (SSH only) - a switch in the editor (labeled Source). Choose Journal to follow the host's systemd journal with journalctl instead of tailing a file. See Journal Streams below.
  • Source - File or Unified Log (Local, Web Edition) - the same switch on a Local System Source. Choose Unified Log to follow this Mac's unified log, the messages Console shows. See Unified Log streams below.
  • Filter - wildcard patterns (using * and ?) ORed together. Empty = show every line. See Filters below.
  • Strip matched text from output - when on, removes the matched substring from the message. Useful for stripping noisy line prefixes like [ServiceName] from the visible output while still using them to filter.
  • Auto-stream at startup - start tailing automatically when LogRaker launches. Otherwise the Stream comes online the first time you select it in the sidebar.

Rotated logs (daemontools-style logdirs)

Many service loggers - multilog (daemontools), svlogd (runit), s6-log (s6), and cyclog (nosh), as used by systems like Victron Venus OS - write their live log to a file named current and, when it fills, rename it to a dated @… archive in the same folder, keeping a small set of recent files.

When a Stream points at a file named current, LogRaker recognizes this Layout and, for the initial history only, reads back across those @… archives - so you still get the number of history lines set in Settings ▸ General, even right after a rotation when current itself holds only a few lines. This is automatic, based on the file name; other log files are read normally. Over SSH, archives that a logger's processor has gzip-compressed are decompressed automatically. (In the App Store edition's sandbox only the file you picked is readable, so there the history comes from current alone.)

Columns

A Stream is shown as a table: one row per line, with the time, severity, host, process, and message each in a column of its own.

Which columns you get depends on what the Source knows about its lines:

  • Files and SSH tails start with Time and Message. Severity, Host, and Process appear on their own as soon as lines carrying them arrive, so a log that only sometimes speaks syslog grows the columns when it does.
  • Journal Streams get Time, Process, and Message.
  • GCP and Firebase Streams get Time, Severity, Resource, and Message.
  • CloudWatch, S3, and Supabase Streams get Time and Message.

Columns fit their content on their own and widen when a longer value arrives. Drag a column's edge to set its width yourself, and that column keeps it. Drag its title to move it, and right-click the header to hide or show columns or to select 'Size Columns to Fit', which makes every column fit its content again. Every Stream keeps its own arrangement, in a Layout too, where a narrow first column carries the time-sync marker.

Click a column's title to sort by it, and click again to reverse. Sorting by Severity gathers a Stream's errors together; sorting by Message groups lines that repeat; sorting by Host or Process collects everything one machine or service said. Lines with no severity at all sort to the end.

While a Stream is sorted by anything other than Time, the view stops scrolling to keep up: the newest line can sort to anywhere, so following it would throw the view around. The tail keeps running and new lines still appear in their sorted place - a strip above the table says so, and its 'Back to Time Order' button returns to time order at the newest line. Clicking the Time title does the same. Each Stream opens in time order.

Rows are one line tall and never wrap; the Message column runs to the longest line, so scroll sideways for the rest of a long one. Select rows the usual way - click, Shift-click for a range, Cmd-click to add or remove one, ⌘A for all, arrow keys to walk. ⌘C copies the columns you can see, separated by tabs, so a paste lands in a spreadsheet as columns; the right-click menu adds 'Copy Message' for the payload alone and 'Copy Raw Line' for the line exactly as the Source sent it.

The Filter field and 'Minimum Severity' narrow the rows, and matches are highlighted in the cell they were found in. A pattern is matched against the line's content - its severity, host, process, and message - and not against the time, so filtering never turns into a search through the clock.

Dimming works from the right-click menu and the keyboard, with the pattern pills above the table; a dimmed row draws back rather than disappearing, and 'Hide Dimmed' removes it. The timeline strip sits above the table, and trimming a range and turning Focus on narrows the rows to it. On GCP Streams, 'Focus on This Execution' reduces the table to one execution and esc restores the rest, 'Inspect Entry' opens the structured entry, and execution colouring tints whole rows. Leave a Stream with a row selected and you return to that row, not to the live tail.

Finding a line

The toolbar's 'Find' button opens a find bar above the table, and puts it away when you press it again; Edit ▸ Find ▸ 'Find…' opens it too. Type and every match highlights where it stands - no rows are hidden, so you keep the lines around it. The match you are on is boxed and tinted more strongly than the rest; 'Find Next' and 'Find Previous', the ‹ › buttons, or Return and Shift-Return step between them - in the find field, or in the log itself while a search is on - and the count beside the ‹ › buttons, like the status bar under the table, shows your place. The bar stays open, with its search, as you move between Streams and Layouts; in a Layout it steps through the pane you are working in. esc or the close button ends the search. Tab and Shift-Tab stop at the find field on their way between the sidebar and the log - in a Layout, on to each pane in turn - and Return and Shift-Return step through the matches of whichever one you land in. A match that sits beyond the pane's right edge is scrolled into view as you step onto it.

Find looks at the same content a filter does - severity, host, process, and message - and never the timestamp. Click the magnifying glass inside the field and choose how the term is compared under 'Compare By': 'Contains' for a plain piece of text, 'Matches All' to require every space-separated part of the term somewhere in the line, in any order, 'Matches Any' to require at least one of them, 'Matches Word' for whole words only, 'Wildcards (* and ?)' for * as any run of characters and ? as any single one, or 'Regular Expression' for a pattern of your own; 'Regular Expression Help', below the list, opens Regular Expressions, the syntax with examples. The empty field shows the comparison in use. The same menu keeps your recent searches - press ↑ and ↓ in the field to walk through them - with 'Clear Recents' to forget them and 'Wrap Around' to decide whether stepping past the last match returns to the first.

The Insert button at the field's right end, beside the ✕, drops a token pill into the term for a shape you'd otherwise spell out as a pattern: an 'IPv4 Address', an 'IPv6 Address' such as 2001:db8::1, a 'Host Name', a 'Reverse DNS Name' such as com.apple.network, a 'URL', a 'UUID/GUID', an 'EC2 Instance ID', a 'File Path', an 'Email Address', a 'MAC Address', a 'Duration', or 'Digits'. Token pills sit in the field and combine with anything you type; click one to select it, then press Delete to remove it or type to replace it. Token pills combine with text, so HOST: followed by an IPv4 Address token pill finds HOST:192.168.0.1 and skips HOST:unknown. They work under every comparison. Under 'Contains' and 'Matches Word' your own text is taken literally, and under 'Wildcards' only * and ? are special; under 'Matches All' and 'Matches Any' each part is, so {URL} {HOST} finds the lines carrying both a URL and a host name whichever comes first under 'Matches All', and {IPV4} {IPV6} finds the lines carrying either kind of address under 'Matches Any' - two token pills side by side count as two parts there even with no space between them; and under 'Regular Expression' your text stays a pattern, so you can join token pills yourself - {URL}.*{HOST} for a URL followed later on the line by a host name.

Finding differs from the Filter field, which removes the lines that don't match. Find keeps them and walks you between the ones that do. The two fields otherwise work the same way: the same comparisons, the same token pills, and each keeps its own recent searches.

The status bar

A strip under every table says what it holds. On the left, how many lines the Stream has buffered, and how many of them a filter leaves - per table, so each pane of a Layout counts its own. On the right, Live while the tail is running, or Paused, with the waveform beside it beating while lines arrive - also while paused, since pausing holds the view and not the tail. In the middle sits the clock: while a reference is pinned it reads Reference with the instant and the Source it came from, and once a Source is aligned it reads Aligned with the offset - see Aligning Source clocks. A Monitor's strip counts its matches.

Filters

LogRaker filters are a list of wildcard patterns. A line is shown if it matches any pattern.

Examples:

Pattern Matches
panic lines containing panic
error code ??? error code 500, error code abc, …
WARN* lines containing WARN followed by anything
panic, OutOfMemory* either panic OR anything starting OutOfMemory

Filters are substring-style: the pattern is matched anywhere in the line's content - its severity, host, process, and message - not anchored to the start, and never against the timestamp. Spaces beside a * are ignored, so failed * timeout means the same as failed*timeout; every other space is an ordinary character.

In the Stream editor each pattern appears as a pill: press Return (or type a comma) to commit the pattern you're typing, click a pill and press Delete to remove it (the arrow keys move the selection from pill to pill), and double-click a pill to edit it in place - Return commits the change, Esc restores the original.

Selecting lines

Selection in the log is line-oriented, like a list. Shift-click extends the selection through whole lines, in either direction; Cmd-click adds or removes a single line, so a selection can skip around. The highlight draws as one band per selected block, and copying gives you whole lines.

While a Stream is following its tail, the selection sits on the newest line, so the live end is always marked and the arrow keys start from there. Click any other line, or move to one with the arrow keys, and the view holds still on it while the tail keeps running: new lines gather below, a pill in the bottom-right corner counts them, and the line stays selected until you select the newest line again or click the pill, which returns you to the live tail.

Home and End jump the selection to the very first / last line, in merged views and Monitor panes too; End rejoins the live tail. Right-clicking a line outside the selection selects that line first, so the menu acts on what you see ringed; right-clicking inside the selection leaves it alone.

Inspecting a line

To read a long line in full, select it and press Space, ⌥-click it, or right-click it and choose 'Inspect Line'. A panel under the line shows its fields and its whole message, wrapped; the copy button above the message puts the whole message on the clipboard, and the magnifier buttons beside it make the message text smaller or larger; the size you pick stays for the next line you inspect. Drag the grip in the panel's bottom-right corner to make the panel larger; it keeps that size for the lines you inspect next, and a double-click on the grip returns it to its usual size. While it is open, the arrow keys and Home / End move the selection and the panel follows; Space or Esc closes it. Merged views and Monitor panes work the same way. A GCP or Firebase line in a Stream opens its structured entry instead - see Inspecting an entry.

Dimming the noise (triage)

When you are hunting a needle in a haystack, most of the log is chatter. Three commands clear it, and they differ in what they look at.

'Dim Similar Lines' acts on what you picked. Right-click a noisy line and LogRaker turns it into a template on the spot: the timestamp is stripped and the varying numbers (durations, counters, sizes) become * wildcards, so one click catches every near-identical line. Select a block of mixed chatter first and every different kind of line in it gets its own pattern in one go. From the keyboard it acts on the selected rows. 'Focus on Similar Lines' is the inverse of the same pick: everything not matching dims.

'Dim Repetitive Lines' ignores the selection and sweeps the whole buffer. LogRaker goes through the entire scrollback, groups the lines that are alike apart from their numbers, and dims every line that repeats - ten lines or more qualifies - busiest first, up to eight patterns per pass; run it again after removing pills to reach the ones further down. The needle is by definition rare, so one click leaves only the unusual lines bright. What you have selected makes no difference to it.

Patterns are case-insensitive, * matches anything, everything else is literal - except that a JSON object in the pattern ({"key":value, …}) matches its fields in any order, since structured logs often shuffle them between entries. Hold Option in the menu to edit the pattern by hand before applying.

Dimming single lines

Some noise has no family. Select any lines and press ⌫ - or right-click and choose 'Dim Lines' - and exactly those lines go quiet: no template, no wildcards, nothing else dims with them. ⇧⌫ brings the selected ones back, and forward delete works the same way. They gather in the bar as one 'Dimmed Lines' pill with a count; click it to restore them all.

While anything is dimmed, a bar of pattern pills floats at the top of the tail: one pill per pattern with its live match count, plus a 'Dimmed Lines' pill for the lines you picked by hand - click a pill to remove it, and it blows apart as it goes. The patterns one action added together (a block selection, a 'Dim Repetitive Lines' pass) sit in a labeled box of their own ('Similar Group 1', 'Repetitive Group 2'), and clicking the label removes the whole group at once - plus a 'Hide Dimmed' switch that collapses the dimmed lines entirely (your last choice is remembered - it re-applies by itself the next time you dim), and 'Clear All'. Every step is undoable with Cmd+Z.

The whole flow also runs from the keyboard: ⌘D dims every line like the ones you selected, ⌥⌘D focuses instead, ⌘⇧D runs the repetitive sweep, and ⌫ dims just the lines you selected (all under View ▸ 'Dim'). What you dimmed stays selected, so you can see what went quiet; with 'Hide Dimmed' on those lines leave the view instead.

Dimming is triage, not configuration: it is per-stream, and it composes with the Stream's Filter (which permanently strips lines before they ever land).

How a Filter compares

A Filter field - the toolbar's, or a pane's own filter inside a Layout - compares its text the way Find does, from the same list. Click the magnifying glass inside the field and choose under 'Compare By':

  • 'Wildcards (* and ?)' - the default: * matches any run of characters and ? any single one, the way the filter saved in the Stream editor and a Monitor's patterns read. Spaces beside a * are ignored, so failed * timeout means the same as failed*timeout; every other space is an ordinary character, so out of memory finds that phrase.
  • 'Contains' - the text as it is typed, so * and ? match those characters. Use this for lines that contain real asterisks, for example *** starting vrmlogger ***.
  • 'Matches All' and 'Matches Any' - every space-separated part, or at least one of them, anywhere in the line and in any order. Two token pills side by side count as two parts, so a UUID/GUID token pill next to a Reverse DNS Name token pill finds lines with either one under 'Matches Any'.
  • 'Matches Word' - whole words only.
  • 'Regular Expression' - a pattern of your own; 'Regular Expression Help', below the list, opens Regular Expressions.

The choice is one app-wide setting: changing it in any Filter field applies to them all, and it's remembered between launches. The empty field shows the comparison in use; while the toolbar shows text, the toolbar's Filter names it in its label instead, as in 'Filter (Wildcards)'. Find keeps a choice of its own. The filter saved in the Stream editor always uses wildcards.

The same menu keeps your recent filters at the top. A filter is added when you press Return, when you leave the field, or when you clear it with the ✕ button; press ↑ and ↓ in the field to walk through them, and choose 'Clear Recents' to forget them.

Filtering by IP address, URL, path and more

While the field has focus or holds a filter, an Insert button sits at its right end. It lists the shapes a log is full of - IPv4 and IPv6 addresses, host names, reverse DNS names, URLs, UUIDs and GUIDs, EC2 instance IDs, file paths, email and MAC addresses, durations and plain digits - the same button and list as the Find bar's. Pick one and it drops into the field as a token pill where the cursor is, and the filter keeps every line carrying that shape, whatever the actual value: IPv4 Address alone shows every line with an address in it.

A token pill combines with anything else in the field, following the comparison you chose. Under 'Wildcards' and 'Contains', what sits against a token pill has to sit against the value: failed IPv4 Address wants the address right after the word. Under 'Wildcards', a * between them allows anything in between. A filter you type by hand understands the shapes written out, as {IPV4}.

Syslog severity decoding

Lines that arrive with a syslog priority prefix - <134>-style, as written by the syslog wire formats (RFC 3164 and RFC 5424) - are decoded automatically. The numeric prefix is replaced by a color-coded severity column: emergencies through errors show red, warnings yellow, notices teal, info green, debug gray. RFC 5424 headers are reshaped to the familiar host app[pid]: form. In a Stream with no priority prefixes at all, lines are shown unchanged.

Mixed Streams stay aligned: a decoded line with no readable clock time - kernel messages stamped with seconds since boot, for example - leaves its Time cell empty, and a timestamped line without a priority leaves its Severity cell empty, so the columns line up either way. Host and process names sit in the Host and Process columns, which appear the moment a line carries them; an unusually long name is cut off at its column's edge until you widen it or select 'Size Columns to Fit'. Copied rows paste into a spreadsheet as columns.

Most log files don't contain the prefix - the usual rsyslog file format drops it, keeping only the timestamp, host, and message. To capture severity in a file LogRaker can decode, add a template on the server that keeps the priority, for example in /etc/rsyslog.d/:

template(name="WithPRI" type="string"
         string="<%PRI%>%TIMESTAMP% %HOSTNAME% %syslogtag%%msg%\n")
*.* /var/log/withpri.log;WithPRI

Then point a Stream at that file.

Filtering by severity

Click the magnifying-glass icon inside any Filter field - the toolbar's, or a pane's own inside a Layout - and pick a 'Minimum Severity'. Only lines at that level or worse stay visible; lines without a decoded severity are hidden too. Select 'All' to show everything again.

The toolbar's choice applies to every view it filters, including a merged view; a pane's own choice applies to that pane, and when both are set the stricter one wins. The choice lasts for the session.

Streams that carry no severity - a plain log file, Amazon CloudWatch, Amazon S3 - don't offer the option, and a severity set elsewhere doesn't apply to them, so switching to one shows all of its lines. A file that turns out to carry syslog lines gains the option as soon as the first one arrives.

While a severity is in effect, that field's magnifier is filled and tinted in that severity's own color - the same red an error line wears - so a strict floor reads hotter than a mild one.

SSH journal Streams (systemd / journald)

On an SSH Source, a Stream can follow the host's systemd journal instead of a file - set Source to Journal in the Stream editor. There's no File field; you pick the units to follow, an optional severity floor, and an optional current-boot limit, with a live Preview of the journalctl command. See Journal Streams for details, including the host permissions needed to read the system journal.

Unified Log streams (this Mac)

On a Local System Source in the Web Edition, a Stream can follow this Mac's unified log instead of a file - set Source to Unified Log in the Stream editor. There's no Path field; you pick the subsystems and processes to follow and a minimum level, with a live Preview of the filter. See Unified Log streams for details.

GCP & Firebase Streams

GCP and Firebase Streams don't have a File field - there's no file. Instead the editor builds a Cloud Logging filter for you from structured controls (Resource, its per-resource fields, and Severity), with a live Preview of the compiled query and a Test Cloud Logging Filter button.

The available resource list depends on the Source kind:

  • Firebase Stream Filter - the curated, Firebase-relevant resource list (Functions, Cloud Run, Auth, Hosting, Realtime DB, Pub/Sub).
  • GCP Stream Filter - the full Google Cloud resource catalog.

Pause / Resume

Pausing a Stream is display-only. The tail keeps running in the background, the sidebar status LED keeps pulsing, the line counter keeps incrementing - but the right pane stops scrolling and stops appending new lines until you resume. When you resume, you catch up to the most recent output.

Pause is per-stream, per-window. Hide-while-paused doesn't affect Monitor matching or any other consumer of the Stream.

Scrollback

The displayed scrollback is capped at ~4 million characters to keep rendering fast on very chatty Streams. Older lines are dropped from the displayed buffer (but the Source file is unaffected - re-open the Stream to start fresh).

© 2026 Thomas Gumz · Native macOS log monitoring Features Pricing Download Docs Blog Changelog About Privacy

Also by Thomas Gumz: PanoPaper, your security cameras as live video wallpaper.

Amazon Web Services, AWS, Amazon CloudWatch, and Amazon S3 are trademarks of Amazon.com, Inc. or its affiliates. Google Cloud and Firebase are trademarks of Google LLC. Supabase is a trademark of Supabase, Inc. LogRaker is an independent product and is not affiliated with, endorsed by, or sponsored by Amazon, Google, or Supabase.