VectleSkillsTenant log search syntax: query filters that find the exact failure

Tenant log search syntax: query filters that find the exact failure

Export

Symptom: drowning in tenant logs. Cause: not using the search query syntax. Confirmation is the point: the right query isolates the failing user, client, and event type in seconds.

TL;DR: Symptom: drowning in tenant logs. Cause: not using the search query syntax. Log retention Retention depends on the subscription tier (days to months). Verify Run the query for a known recent login and confirm it returns the event.

The error

drowning in tenant logs. Cause: not using the search query syntax. Log retention Retention depends on the subscription tier (days to months). Verify Run the query for a known recent login and confirm it returns the event.

The fix

TL;DR: Symptom: drowning in tenant logs. Cause: not using the search query syntax. Log retention Retention depends on the subscription tier (days to months). Verify Run the query for a known recent login and confirm it returns the event.

The error

failed logins;

The fix

Tenant log search

The syntax

Monitoring > Logs search box accepts Lucene-style queries. The ones that matter:

  • type:f failed logins; type:s successes. Full type codes are in the docs.
  • user_id:"auth0|abc123" exact user. user_name:"[the user email]".
  • client_id:"YOUR_CLIENT_ID" scope to one app.
  • connection:"google-oauth2" or connection:"Username-Password-Authentication".
  • description:*denied* wildcard on the description.
  • Date ranges: the dashboard picker, or date:[2026-09-26 TO 2026-09-27] in API queries.
  • Combine: type:f AND client_id:"xxx" AND user_name:"y@" finds one user's failures on one app.

Management API search

GET /api/v2/logs?q=type:f AND user_id:"auth0|123"&per_page=50&sort=date:-1. Script this; the dashboard is for humans, the API is for incidents.

Log retention

Retention depends on the subscription tier (days to months). If the incident is older than retention, the logs are gone; this is the argument for log streaming to your SIEM before you need it.

PII

Logs can contain PII. The docs describe PII handling and obfuscation options for streams. Do not paste raw log lines into public issues.

Verify

Run the query for a known recent login and confirm it returns the event. Save the team's top five queries in the runbook so incidents start from a template, not a blank box.

When to use this

  • You are seeing this exact error message; match the block above, not just part of it.
  • The failing call matches the scenario in the title: Tenant log search syntax.
  • You want the fastest verified fix before digging through logs.

When not to use this

  • Your error text differs from the block above; close cousins often have different causes.
  • The stack trace points at a different component than the one in the title.
  • You already applied this fix and the error persists; look for a second cause instead of reapplying.

Compatibility

  • Not pinned to a specific version; follows current Tenant behavior.

Also seen as

  • description:*denied*

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Tenant+log+search+syntax%3A+query+filters+that+find+the+exact+failure&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.