Logs you can read at a glance.
Log Lion opens Windows Event Logs, ETW traces, firewall and web server logs, JSON and nearly any text log, then colors them so the pattern is visible before you search for it.
Free trial. Windows 10 and 11. Log files are never modified.
The same rows before and after color. Four failures from one address, then a success, and the red strand tells you whose account it was.
Made for people who read logs for a living
IT administrators
Browse live event logs, follow growing server logs, and open IIS, CSV and compressed logs as they are.
Security and incident response
Filter a Security log to failed logons, color by account or address, and see when an attack started on the timeline.
Digital forensics
Log Lion never writes to a log. Open collected .evtx files, and legacy .evt files left unclosed by a crash.
Software developers
Capture debug output live, and open JSON Lines, logfmt, HAR and BSON with nested fields as columns.
Color does the reading
Event Viewer and text editors give you row after row of the same gray text. Log Lion colors it for you, with nothing to set up.
- Syntax highlighting
- Numbers, quoted strings, name=value pairs, GUIDs and hex values each get their own color inside every message, so the value you need stands out in a dense line.
- Color by column
- Pick a column and every distinct value gets its own color. By thread, interleaved work separates into strands. By session, one transaction stays visible without hiding what happened around it.
- Highlight rules
- Mark every match of a regular expression at once, several rules together, each in its own color.
- Color a filter
- Color what a filter matches instead of hiding everything else, so you never lose the context.
Colors carry through when you copy or export to HTML and RTF, ready to paste into a ticket or a report.
Built for Windows logs
Log Lion was made on Windows, for Windows, and reads its logs natively.
- Event Logs, live and from filesApplication, System, Security and other classic logs, plus .evtx files collected from other machines.
- Legacy event log files.evt files read directly, including ones left unclosed by a crash or power loss.
- ETW event traces.etl captures from logman, wpr, xperf and Performance Monitor, decoded with provider, level, process and message.
- Windows Defender FirewallFound automatically for every profile with logging turned on.
- Debug outputOutputDebugString captured live, including from Windows services.
More than Windows
IIS and W3C web server logs, CSV, TSV, JSON Lines, logfmt, HTTP Archive and MongoDB BSON files open with their structure intact. SQL Server, PostgreSQL, MySQL, Oracle and SQLite tables open over ODBC.
Anything else, teach Log Lion once with the import wizard: it detects the time, fields and message for you. See how
Try Log Lion for free
Start with the free trial from the Microsoft Store. New in 3.1: ETW traces, firewall logs, SQL databases and more. See what's new.