Skip to content
64x-lunicornPublic

About

Fast open-source log explorer for Windows, macOS and Linux. Search multi-gigabyte files, follow live logs, and chart what you find. Qt6/C++, based on klogg and glogg.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

9 stars

Watchers

2 watching

Forks

Latest commit

 

History

2,649 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

LogSquirl mascot investigating a log with a magnifying glass

LogSquirl

Big logs. Clear answers.

A fast, open-source log explorer for Windows, macOS, and Linux.

Search huge files, follow live logs, and turn noisy output into something you can actually work with.

Download LogSquirl Read the docs

Latest release Downloads CI Build CodeQL OpenSSF Scorecard License: GPL-3.0-or-later

Why LogSquirl? · Get started · Features · Plugins · Building · Help · Contributing · About

LogSquirl in dark mode showing the fictional Acorn Store incident, highlighted errors, and matching log lines

Follow the incident, highlight the clues, and keep matching lines in view. Captured on macOS with fictional demo data; the local file path is anonymized.


Why LogSquirl?

Your editor struggles with the file. Your terminal shows the match, but not the whole story. LogSquirl brings grep, less, and tail into one desktop app so you can find what happened without losing the context.

Less friction More insight
Open the big one. Work with multi-gigabyte logs without loading the entire file into memory. Find the signal. Combine regex searches with AND, OR, and NOT, then inspect matches alongside the source.
Stay with the action. Follow growing files and reload automatically when they change. See the structure. Detect supported log formats and switch between raw text and a column-based table view.
Skip the unpacking. Open compressed logs and tarballs directly. Spot the pattern. Chart numeric values, message rates, and filter frequency over time.

Get started

1. Install LogSquirl

Download the latest release and choose the package for your platform, or add a package source and let your system keep it up to date.

Platform Download Package source
Windows NSIS installer –
macOS (Apple Silicon, macOS 15+) DMG Homebrew
Ubuntu 24.04 (amd64) DEB or AppImage APT repository
Fedora 44, Oracle Linux 10 RPM or AppImage DNF repository
Other Linux AppImage –

The DEB and RPM packages use your distribution's Qt and install only when it is at least the Qt version LogSquirl was built with; on other distributions, use the AppImage, which brings its own Qt. There is no build for Intel Macs. The release notes have the package details and platform requirements.

Windows: deploy the installer silently (Intune and similar tools)

The installer installs silently for all users with /S; /D=<dir> as the last argument sets the directory. The user guide says what it installs and how to detect it.

macOS: install with Homebrew
brew install --cask 64x-lunicorn/tap/logsquirl

Later releases arrive with brew upgrade.

Ubuntu 24.04: add the APT repository
sudo install -d -m 0755 /etc/apt/keyrings
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl-packages.asc -o /etc/apt/keyrings/logsquirl.asc
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl.sources -o /etc/apt/sources.list.d/logsquirl.sources
sudo apt update
sudo apt install logsquirl

Later releases arrive with apt upgrade. The repository holds the last three stable releases and no betas, signed with the key 51ABA6432D0407ED62E8EC403169E5DF85C9A3A3.

Fedora 44 and Oracle Linux 10: add the DNF repository
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl-fedora.repo -o /etc/yum.repos.d/logsquirl.repo
sudo dnf install logsquirl

On Oracle Linux 10 (and EL10 clones), fetch logsquirl-el10.repo instead of logsquirl-fedora.repo. Later releases arrive with sudo dnf upgrade.

The Fedora package is built against Fedora 44 and supported there only; a newer Fedora that changes its Qt may need a newer LogSquirl build, so use the AppImage until then. The repositories hold the last three stable releases and no betas. The repository metadata is signed with the key 51ABA6432D0407ED62E8EC403169E5DF85C9A3A3 (repo_gpgcheck=1); the RPMs themselves are unsigned, exactly the release assets, and dnf verifies them through the signed metadata.

Any platform: verify that a download is genuine

Every release has a logsquirl-<version>-sha256.txt checksum file signed with Sigstore, and every asset carries a GitHub build provenance attestation. The CycloneDX SBOM logsquirl-<version>-sbom.cdx.json lists the third-party components a release contains. The Verifying downloads section of the release notes has the cosign verify-blob, sha256sum -c and gh attestation verify commands.

2. Find your first clue

  1. Open a log file you want to investigate.
  2. Search for a keyword or regex such as ERROR|WARN|timeout with regex mode enabled.
  3. Select a match to inspect the surrounding lines in the original log.
  4. Enable follow mode to keep watching as new lines arrive.

Need a log to try? Open the fictional incident demo and follow a service from healthy traffic through timeouts to recovery. The user guide covers filters, charts, and keyboard shortcuts.

Features

  • Fast where it matters. Multi-threaded, SIMD-optimized search. Persistent index caching for reopening files. Automatic encoding detection. Direct support for .gz, .bz2, .xz, .zst, .lz4, and tarballs. Master is measured every night against its own history and budgets; the performance trend shows each scenario over time.
  • Make the important parts stand out. Save and group filters, pin them across sessions, and switch between color highlighter sets. Browse supported formats as structured tables, or chart values and jump from a data point straight to its log line. Reuse chart templates and share presets as JSON.
  • Keep your investigation in one place. Dark mode, configurable shortcuts, and a Command Palette (Ctrl+Shift+P) for quick access. A Scratchpad for notes, data transformations, and JWT decoding.

Go deeper: Log formats · Chart Panel · Full user guide

Plugins

Your logs do not have to start in a file. Extend LogSquirl with data sources, format converters, and custom UI actions.

Plugin What it brings
Android Logcat Stream logcat output from ADB devices.
Serial Monitor Stream data from serial ports.

Plugins → Plugin Management… finds, installs, updates and enables them (Plugins in the documentation).

Want to build your own? The C ABI supports DataSource, Converter, and UI Extension plugins.

Explore the registry · Read the Plugin SDK guide · Publish a plugin

Building

LogSquirl is built with C++23 and Qt6, using CMake and CPM for dependency management. You will need a C++23 compiler (GCC 13+, Clang 17+, or MSVC 19.36+), Qt 6.5+, and CMake 3.16+, along with the platform-specific dependencies.

Follow the build guide for setup, build options, and testing instructions.

How to get help

Looking for… Start here
Usage, settings, and shortcuts User guide
New features and fixes Changelog
A known issue or workaround Search existing issues
A bug report or feature request Open an issue

Contributing

Help make the next log investigation a little easier. Bug reports, feature ideas, documentation improvements, plugins, and code contributions are all welcome.

Read the contributing guide to get started. If LogSquirl helps you, give it a star or share it with someone who spends too much time scrolling through logs.

Code signing policy

Status: signing of the Windows releases through the SignPath Foundation is being set up (#445). Until it is in place, the Windows releases are not signed.

What is signed, and who approves a release

What is signed: logsquirl.exe, logsquirl_portable.exe, logsquirl_grep.exe and the Windows installer, built by this repository's GitHub Actions workflows and never on a developer's computer. The components LogSquirl ships but does not develop (Qt, OpenSSL, oneTBB, Hyperscan, the Microsoft Visual C++ runtime, the Sentry crash handler) are not signed with the LogSquirl certificate.

Team roles:

  • Committers and reviewers: 64x-lunicorn, the maintainer. Changes by other contributors are reviewed by the maintainer before they are merged.
  • Approvers: 64x-lunicorn. A release is signed only after an approver has approved its signing request.

Privacy: LogSquirl checks for updates on its own when it starts, at most once a week (at every start with beta updates on), with a request that carries nothing about you; the Windows installer and the Options turn it off. Crash reports are sent only if you agree, for each crash. Nothing else is sent unless you ask for it. See the privacy policy.

About the project

LogSquirl is a fork of klogg, which itself started as a fork of glogg - the fast, smart log explorer. Since the original klogg project is no longer actively maintained, LogSquirl continues development under a new name, building on the excellent foundation laid by both glogg and klogg. LogSquirl is standing on the shoulders of giants.

Differences from klogg

klogg's last stable release is 22.06, from June 2022. LogSquirl picks up from there and should still feel like klogg: open, search, filter, follow. New capabilities are meant to come as optional plugins, so you choose what you add.

In stable releases:

  • Log format detection and a column-based Table View
  • The Chart Panel, with format-aware templates
  • The Filters Panel and Filter Groups
  • Plugins for data sources, format converters, and UI extensions

Coming in the next release (on master, in the next beta):

  • Time navigation: go to a timestamp, or limit a search to a time range
  • A Table View for JSON and logfmt logs
  • Reading a log from standard input: journalctl -f | logsquirl -
  • A Team Folder that shares Filter Groups and Highlighter Sets via a repository
  • APT and DNF repositories for Ubuntu, Fedora, and Oracle Linux

What it gives up:

  • Qt 6.5+ and C++23 only; there is no Qt 5 build.
  • The macOS build is Apple Silicon only and needs macOS 15 or later.
  • There is no Chocolatey package; its unpublished package source was removed.

The changelog has the details.

Acknowledgements and license

LogSquirl is built by 64x-Lunicorn on the work of:

See NOTICE for third-party components and their licenses.

LogSquirl is free and open source under the GNU General Public License v3.0 or later. See COPYING for the full license.


Less scrolling. More investigating.

Download LogSquirl · Read the docs · Back to top

About

Fast open-source log explorer for Windows, macOS and Linux. Search multi-gigabyte files, follow live logs, and chart what you find. Qt6/C++, based on klogg and glogg.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

9 stars

Watchers

2 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages