Warm Tier
Warm tier keeps older logs searchable at a lower cost than your primary retention. This page covers how warm-tier data behaves when you use it; for what the tier is and how to set it up, see Warm Tier.
The practical thing to know is that warm-tier searches are deliberate rather than automatic.
Searching warm data in Explore
When your selected timeframe reaches into warm-tier data, Explore stops re-running the query as you change things. Instead you'll see:
Current results are outdated — Click Run Query to apply new search
This is intentional. Warm-tier queries are heavier than hot-tier ones, so Explore doesn't fire one off every time you adjust a filter or a column. You compose the search you want, then run it.
If results look stale after you've changed something, that banner is why. Select Run Query.
Warm data elsewhere
- CSV export — exports include warm-tier data when your timeframe covers it, so you don't need a separate route to get older logs out.
- Accounts — warm tier is configured per account; see the account management docs for enabling and sizing it.
Dashboards don't support warm-tier data. Panels query your primary retention only, so a dashboard won't show warm data even when its time range covers it — use Explore for that.
Practical notes
- Narrow the timeframe before you narrow anything else. On warm data, a smaller window is the difference between a query you wait on and one you don't.
- Expect warm queries to take longer than hot ones.