Big logs. Clear answers.
A fast, open-source log explorer for Windows, macOS, and Linux.
Search huge files, follow live logs, and turn noisy output into something you can actually work with.
Why LogSquirl? · Get started · Features · Plugins · Building · Help · Contributing · About
Follow the incident, highlight the clues, and keep matching lines in view. Captured on macOS with fictional demo data; the local file path is anonymized.
Your editor struggles with the file. Your terminal shows the match, but not the whole story. LogSquirl brings grep, less, and tail into one desktop app so you can find what happened without losing the context.
| Less friction | More insight |
|---|---|
| Open the big one. Work with multi-gigabyte logs without loading the entire file into memory. | Find the signal. Combine regex searches with AND, OR, and NOT, then inspect matches alongside the source. |
| Stay with the action. Follow growing files and reload automatically when they change. | See the structure. Detect supported log formats and switch between raw text and a column-based table view. |
| Skip the unpacking. Open compressed logs and tarballs directly. | Spot the pattern. Chart numeric values, message rates, and filter frequency over time. |
Download the latest release and choose the package for your platform, or add a package source and let your system keep it up to date.
| Platform | Download | Package source |
|---|---|---|
| Windows | NSIS installer | – |
| macOS (Apple Silicon, macOS 15+) | DMG | Homebrew |
| Ubuntu 24.04 (amd64) | DEB or AppImage | APT repository |
| Fedora 44, Oracle Linux 10 | RPM or AppImage | DNF repository |
| Other Linux | AppImage | – |
The DEB and RPM packages use your distribution's Qt and install only when it is at least the Qt version LogSquirl was built with; on other distributions, use the AppImage, which brings its own Qt. There is no build for Intel Macs. The release notes have the package details and platform requirements.
Windows: deploy the installer silently (Intune and similar tools)
The installer installs silently for all users with /S; /D=<dir> as the last argument sets the
directory. The user guide says
what it installs and how to detect it.
macOS: install with Homebrew
brew install --cask 64x-lunicorn/tap/logsquirlLater releases arrive with brew upgrade.
Ubuntu 24.04: add the APT repository
sudo install -d -m 0755 /etc/apt/keyrings
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl-packages.asc -o /etc/apt/keyrings/logsquirl.asc
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl.sources -o /etc/apt/sources.list.d/logsquirl.sources
sudo apt update
sudo apt install logsquirlLater releases arrive with apt upgrade. The repository holds the last three stable releases and no
betas, signed with the key 51ABA6432D0407ED62E8EC403169E5DF85C9A3A3.
Fedora 44 and Oracle Linux 10: add the DNF repository
sudo curl -fsSL https://packages.lunicorn-lab.de/logsquirl-fedora.repo -o /etc/yum.repos.d/logsquirl.repo
sudo dnf install logsquirlOn Oracle Linux 10 (and EL10 clones), fetch logsquirl-el10.repo instead of logsquirl-fedora.repo.
Later releases arrive with sudo dnf upgrade.
The Fedora package is built against Fedora 44 and supported there only; a newer Fedora that changes its
Qt may need a newer LogSquirl build, so use the AppImage until then. The repositories hold the last three
stable releases and no betas. The repository metadata is signed with the key
51ABA6432D0407ED62E8EC403169E5DF85C9A3A3 (repo_gpgcheck=1); the RPMs themselves are unsigned,
exactly the release assets, and dnf verifies them through the signed metadata.
Any platform: verify that a download is genuine
Every release has a logsquirl-<version>-sha256.txt checksum file signed with Sigstore, and every
asset carries a GitHub build provenance attestation. The CycloneDX SBOM
logsquirl-<version>-sbom.cdx.json lists the third-party components a release contains.
The Verifying downloads section of the release notes has the cosign verify-blob,
sha256sum -c and gh attestation verify commands.
- Open a log file you want to investigate.
- Search for a keyword or regex such as
ERROR|WARN|timeoutwith regex mode enabled. - Select a match to inspect the surrounding lines in the original log.
- Enable follow mode to keep watching as new lines arrive.
Need a log to try? Open the fictional incident demo and follow a service from healthy traffic through timeouts to recovery. The user guide covers filters, charts, and keyboard shortcuts.
- Fast where it matters. Multi-threaded, SIMD-optimized search. Persistent index caching for
reopening files. Automatic encoding detection. Direct support for
.gz,.bz2,.xz,.zst,.lz4, and tarballs. Master is measured every night against its own history and budgets; the performance trend shows each scenario over time. - Make the important parts stand out. Save and group filters, pin them across sessions, and switch between color highlighter sets. Browse supported formats as structured tables, or chart values and jump from a data point straight to its log line. Reuse chart templates and share presets as JSON.
- Keep your investigation in one place. Dark mode, configurable shortcuts, and a Command
Palette (
Ctrl+Shift+P) for quick access. A Scratchpad for notes, data transformations, and JWT decoding.
Go deeper: Log formats · Chart Panel · Full user guide
Your logs do not have to start in a file. Extend LogSquirl with data sources, format converters, and custom UI actions.
| Plugin | What it brings |
|---|---|
| Android Logcat | Stream logcat output from ADB devices. |
| Serial Monitor | Stream data from serial ports. |
Plugins → Plugin Management… finds, installs, updates and enables them (Plugins in the documentation).
Want to build your own? The C ABI supports DataSource, Converter, and UI Extension plugins.
Explore the registry · Read the Plugin SDK guide · Publish a plugin
LogSquirl is built with C++23 and Qt6, using CMake and CPM for dependency management. You will need a C++23 compiler (GCC 13+, Clang 17+, or MSVC 19.36+), Qt 6.5+, and CMake 3.16+, along with the platform-specific dependencies.
Follow the build guide for setup, build options, and testing instructions.
| Looking for… | Start here |
|---|---|
| Usage, settings, and shortcuts | User guide |
| New features and fixes | Changelog |
| A known issue or workaround | Search existing issues |
| A bug report or feature request | Open an issue |
Help make the next log investigation a little easier. Bug reports, feature ideas, documentation improvements, plugins, and code contributions are all welcome.
Read the contributing guide to get started. If LogSquirl helps you, give it a star or share it with someone who spends too much time scrolling through logs.
Status: signing of the Windows releases through the SignPath Foundation is being set up (#445). Until it is in place, the Windows releases are not signed.
What is signed, and who approves a release
What is signed: logsquirl.exe, logsquirl_portable.exe, logsquirl_grep.exe and the
Windows installer, built by this repository's GitHub Actions workflows and never on a
developer's computer. The components LogSquirl ships but does not develop (Qt, OpenSSL,
oneTBB, Hyperscan, the Microsoft Visual C++ runtime, the Sentry crash handler) are not signed
with the LogSquirl certificate.
Team roles:
- Committers and reviewers: 64x-lunicorn, the maintainer. Changes by other contributors are reviewed by the maintainer before they are merged.
- Approvers: 64x-lunicorn. A release is signed only after an approver has approved its signing request.
Privacy: LogSquirl checks for updates on its own when it starts, at most once a week (at every start with beta updates on), with a request that carries nothing about you; the Windows installer and the Options turn it off. Crash reports are sent only if you agree, for each crash. Nothing else is sent unless you ask for it. See the privacy policy.
LogSquirl is a fork of klogg, which itself started as a fork of glogg - the fast, smart log explorer. Since the original klogg project is no longer actively maintained, LogSquirl continues development under a new name, building on the excellent foundation laid by both glogg and klogg. LogSquirl is standing on the shoulders of giants.
Differences from klogg
klogg's last stable release is 22.06, from June 2022. LogSquirl picks up from there and should still feel like klogg: open, search, filter, follow. New capabilities are meant to come as optional plugins, so you choose what you add.
In stable releases:
- Log format detection and a column-based Table View
- The Chart Panel, with format-aware templates
- The Filters Panel and Filter Groups
- Plugins for data sources, format converters, and UI extensions
Coming in the next release (on master, in the next beta):
- Time navigation: go to a timestamp, or limit a search to a time range
- A Table View for JSON and logfmt logs
- Reading a log from standard input:
journalctl -f | logsquirl - - A Team Folder that shares Filter Groups and Highlighter Sets via a repository
- APT and DNF repositories for Ubuntu, Fedora, and Oracle Linux
What it gives up:
- Qt 6.5+ and C++23 only; there is no Qt 5 build.
- The macOS build is Apple Silicon only and needs macOS 15 or later.
- There is no Chocolatey package; its unpublished package source was removed.
The changelog has the details.
Acknowledgements and license
LogSquirl is built by 64x-Lunicorn on the work of:
- klogg by Anton Filimonov and contributors (GPL-3.0).
- glogg by Nicolas Bonnefon (GPL-3.0).
See NOTICE for third-party components and their licenses.
LogSquirl is free and open source under the GNU General Public License v3.0 or later. See COPYING for the full license.
Less scrolling. More investigating.
