Open it from an alert
1
Start from an alert or investigation
Open an alert and click Explore logs, metrics and traces. The same button sits on an
investigation page. Both open the Explorer scoped to the alert’s service and to a time window
that starts shortly before the alert fired and runs to its resolve time, or to now while it is
still firing.
2
Check the scope
A bar at the top of the page shows where you came from, with a link back to the alert or
investigation. The scope bar below it holds the service, environment, deployment and time
window.
3
Pick a signal
Choose the Logs, Metrics or Traces tab.
Scope it to a service
- Pick a service lists your ECS services, Lambda functions and Kubernetes workloads, then the services known from deployments, SLIs and alerts.
- All environments narrows to one environment when you pick one.
- Deployment sets the window around a deploy (thirty minutes before it started to thirty minutes after it finished) and draws markers on the charts at the start and end, so a regression right after a release stands out.
- Last 5m through Last 24h, or From and To followed by Apply window, set a free window.
Logs, metrics and traces
Logs. The tab derives a starter query for the service and window. Narrow the results with the level filter (All levels, ERROR, WARN, INFO, DEBUG) or the Filter text box, and use Load more for further rows. A log window cannot be wider than 7 days, and a monthly scan ceiling set by an admin under Settings, Preferences pauses the tab when your organization reaches it. When that happens the tab offers a link to the CloudWatch console instead. Metrics. Charts for the service’s metrics, with deployment markers. Add a metric picks from the catalogue found for the service. A metric with no alarm shows Alarm on this when you may create one, and a metric that already has one shows Alarmed: followed by the alarm name. Traces. A list of trace summaries with Sort by duration and Errors only. Click a trace to open its detail in a drawer. If you connected both an AWS source and a native one for a signal, a source picker on the tab switches between them. A tab marked Auto was set from the service’s bindings and your configured sources, and your own pick sticks for that service.Builder and Code modes
Every tab has a Builder and Code switch.- Builder gives you structured controls for the source: a metric, label filters and operations for Prometheus, parsers and filters for Loki, row builders for CloudWatch, and quick-field chips elsewhere. The query it produces is shown read only underneath.
- Code is a full editor with syntax highlighting, error underlines and suggestions drawn from your source: metric names, labels, fields, log groups and services. Press Ctrl+Space (or the Suggest button) to open suggestions, Enter or Tab to accept one, and Ctrl+Enter or Cmd+Enter to run.
- Switching modes never runs a query. A tab opens in Builder when its query is what the builder produces, and in Code otherwise.
- If you edit in Code something the builder cannot represent, Builder says This query was edited in code. Reset builder rebuilds the query from the builder (after a confirmation), and Reset to starter replaces it with the starter query.
Save and share queries
Under the editor, type a name in Save this query as and click Save. Saved queries appear as chips for that service and tab, and everyone in the organization sees them. Members can save queries and remove their own. Admins can remove any. The address bar always holds the last query you ran, so copying the URL shares the same query, window and mode. A very large query still runs but is too big for a link, and the page tells you so.What you can do next
When you find the cause, go back to the alert and use Create ticket, Publish to status page or Fix with Claude. See Run and read an investigation for how evidence links into the Explorer.Related
- Connect your data: connect the sources the Explorer reads.
- Triage alerts: open the Explorer from an alert.
- Plan matrix: the plans that include the Explorer.

