What's new in 3.1
Log Lion 3.1 adds ETW traces, firewall logs, SQL databases and more ways to extend it. It's a free update for everyone who owns Log Lion 3.
- NewWindows Event Trace Logs (.etl). ETW captures from logman, xperf, wpr and Performance Monitor are decoded into time, provider, event ID, level, task, process, thread, processor, keywords and message columns. Events from providers not registered on your machine still show their header fields. The first open caches an index beside the file so it reopens fast.
- NewWindows Defender Firewall logs. Log Lion checks the Domain, Private and Public profiles and lists a source for each one with logging enabled, so there's no path to hunt down.
- NewSQL database logs. Read logs stored in a table in SQL Server, PostgreSQL, MySQL, Oracle, SQLite or any database with an ODBC driver, using a .lldb connection profile.
- NewMongoDB BSON files, as written by mongodump and change stream captures. Nested documents become dotted columns, real types drive the time column and severity icons, and a damaged file resumes at the next good document. BSON export too.
- Newlogfmt logs (.logfmt), and logfmt as a field parser in the Import Text Log wizard.
- NewLua scripts that process every entry in a log.
- NewExtensions (.llx). Third parties can add log formats and live data sources through a documented C interface. Log Lion asks before loading a new extension and remembers the answer against its SHA-256. Tools > Extensions shows what's installed; hold Shift at startup to skip them all.
- NewA Getting Started dialog, and a round of UI modernization.
- AddedThe Extension SDK: a documented C header, two sample extensions, and llxprobe, which checks an extension against the interface before it's installed.
- AddedContent-based detection for plain text, CSV, TSV, JSON, JSON Lines and regular expression logs, so more files open as the right type automatically.
- AddedTools > Open Data Folder, which opens the folder holding plugins, text log profiles, filters and the license file.
- AddedDebug Output options for time zone offset and namespace. Use the Global namespace to capture from Windows services.
- AddedA context menu on the Source Info pane with Select All, Copy and Refresh.
- ChangedFaster timeline loading and better timeline highlighting.
- ChangedA new color scheme for severity levels.
- ChangedA clearer About box.
- FixedTimestamps with a UTC offset, such as
2026-01-15T10:30:00-08:00, weren't recognized. They are now, and are adjusted to UTC. - FixedOpening a general text file with a .log extension could take a very long time while auto detection tried every profile.
- FixedUnmatched Pairs and Profiler paired an end event with the oldest open begin, which gave wrong durations for nested scopes. They now pair with the newest, and unmatched end events are no longer dropped.
- FixedHTTP Archive (.har) files weren't auto-detected without asking.
- FixedShort TSV rows could borrow fields from the next row.
- FixedRight and center aligned columns had no padding.
- FixedCrashes when opening a file with a very short name, and when formatting some IPv6 addresses.