Skip to main content

Warm Tier

Warm tier keeps older logs searchable at a lower cost than your primary retention. This page covers how warm-tier data behaves when you use it; for what the tier is and how to set it up, see Warm Tier.

The practical thing to know is that warm-tier searches are deliberate rather than automatic.

Searching warm data in Explore

When your selected timeframe reaches into warm-tier data, Explore stops re-running the query as you change things. Instead you'll see:

Current results are outdated — Click Run Query to apply new search

This is intentional. Warm-tier queries are heavier than hot-tier ones, so Explore doesn't fire one off every time you adjust a filter or a column. You compose the search you want, then run it.

If results look stale after you've changed something, that banner is why. Select Run Query.

Warm data elsewhere

  • CSV export — exports include warm-tier data when your timeframe covers it, so you don't need a separate route to get older logs out.
  • Accounts — warm tier is configured per account; see the account management docs for enabling and sizing it.
note

Dashboards don't support warm-tier data. Panels query your primary retention only, so a dashboard won't show warm data even when its time range covers it — use Explore for that.

Practical notes

  • Narrow the timeframe before you narrow anything else. On warm data, a smaller window is the difference between a query you wait on and one you don't.
  • Expect warm queries to take longer than hot ones.