Log Template Miner
Paste one event per line to identify number, IP, UUID, hexadecimal and time-shaped variables. Lines with enough fixed words in the same positions form a template, including varying words in the middle. Inspect each group's frequency, source line numbers and original variable values. Ordinary first and last words must match, reducing accidental merges between different event types. This is a rule-based candidate finder, not a complete log parser.
Key features
- Up to 1500 text log lines and 256 KiB
- Shape-based number/unit, IP, UUID, hexadecimal and time slots
- Clusters based on shared fixed words and varying middle words
- Frequency, original line numbers, variable positions and values
- Template CSV, field CSV and full JSON downloads
How to use
- Paste log lines or choose a local .log/.txt file.
- Run pattern mining to separate repeated and one-off messages.
- Filter repeated or single templates and inspect original line numbers.
- Review original values in variable positions and check mistaken clusters.
- Download template/field CSV or full JSON.
Use cases
- Count recurring server error messages
- Locate changing request IDs and response times
- Prepare candidate shapes before writing alert rules
Frequently asked questions
Which lines share a template?
Lines need the same whitespace-token count and first token, with roughly 60% of fixed positions matching. Different ordinary first or last words remain separate. Review these heuristic groups yourself.
Does it understand every log format?
No. It recognizes selected date, number, IP, UUID and hexadecimal shapes plus common words in matching positions. It does not structurally parse nested JSON, multiline stack traces or custom delimiters.
Are numbers followed by ms or MB recognized?
Yes. Numeric values with ms, s, KB, MB, GB or % suffixes are treated as variable. Arbitrary unit formats are not interpreted.
Are original logs sent out?
No. Input and selected files remain in the browser. Field CSV and JSON contain original tokens and sample lines, so inspect sensitive data before sharing.
Why can one event split into several templates?
The grouping limits merging when token counts or ordinary first/last words differ. This conservative rule avoids some false merges; manual rule training is not provided.
What happens to blanks and what are the limits?
Blank lines are skipped and counted. Input supports up to 1500 nonblank lines, 256 KiB UTF-8, 2000 characters and 64 tokens per line.
Privacy
Logs are analyzed in browser memory and selected files are not uploaded. Variable CSV and JSON may contain original IP addresses, names or secrets. Check them before sharing.
Comments & questions