Logs you can read at a glance.

Log Lion opens Windows Event Logs, ETW traces, firewall and web server logs, JSON and nearly any text log, then colors them so the pattern is visible before you search for it.

Free trial. Windows 10 and 11. Log files are never modified.

The same rows before and after color. Four failures from one address, then a success, and the red strand tells you whose account it was.

Made for people who read logs for a living

IT administrators

Browse live event logs, follow growing server logs, and open IIS, CSV and compressed logs as they are.

Security and incident response

Filter a Security log to failed logons, color by account or address, and see when an attack started on the timeline.

Digital forensics

Log Lion never writes to a log. Open collected .evtx files, and legacy .evt files left unclosed by a crash.

Software developers

Capture debug output live, and open JSON Lines, logfmt, HAR and BSON with nested fields as columns.

Color does the reading

Event Viewer and text editors give you row after row of the same gray text. Log Lion colors it for you, with nothing to set up.

Syntax highlighting
Numbers, quoted strings, name=value pairs, GUIDs and hex values each get their own color inside every message, so the value you need stands out in a dense line.
Color by column
Pick a column and every distinct value gets its own color. By thread, interleaved work separates into strands. By session, one transaction stays visible without hiding what happened around it.
Highlight rules
Mark every match of a regular expression at once, several rules together, each in its own color.
Color a filter
Color what a filter matches instead of hiding everything else, so you never lose the context.

Colors carry through when you copy or export to HTML and RTF, ready to paste into a ticket or a report.

An IIS log in Log Lion colored by client address, with one attacking address forming a solid strand of color.
An IIS log colored by client address. One address becomes a solid strand of color: a credential-stuffing attack, visible before you search for it.

Built for Windows logs

Log Lion was made on Windows, for Windows, and reads its logs natively.

  • Event Logs, live and from filesApplication, System, Security and other classic logs, plus .evtx files collected from other machines.
  • Legacy event log files.evt files read directly, including ones left unclosed by a crash or power loss.
  • ETW event traces.etl captures from logman, wpr, xperf and Performance Monitor, decoded with provider, level, process and message.
  • Windows Defender FirewallFound automatically for every profile with logging turned on.
  • Debug outputOutputDebugString captured live, including from Windows services.
The live Windows Security event log in Log Lion, colored by event ID.
The live Security event log colored by event ID. Logons, privilege use and credential reads each have their own color.

More than Windows

IIS and W3C web server logs, CSV, TSV, JSON Lines, logfmt, HTTP Archive and MongoDB BSON files open with their structure intact. SQL Server, PostgreSQL, MySQL, Oracle and SQLite tables open over ODBC.

Anything else, teach Log Lion once with the import wizard: it detects the time, fields and message for you. See how

Try Log Lion for free

Start with the free trial from the Microsoft Store. New in 3.1: ETW traces, firewall logs, SQL databases and more. See what's new.