Offline Log Investigation Workstation

LogSearchX
A must have tool in every SOC Analyst's Arsenal

SIEMs are built to collect and monitor. LogSearchX is built to help security analysts deep-investigate security telemetry.

Windows · No cloud · No SIEM

Build complex investigations with simple logic

Chain AND / OR / NOT conditions across your data using powerful field-level operators. No SQL. No query language to learn.

Query Builder — LogSearchX
Usercontainsadmin
AND
IPregexPrivate IP Range
AND
Processcontainspowershell
OR
Processcontainscmd
Run Investigation
Signature capability

AND / OR / NOT Query Chaining

Build complex investigations by combining multiple conditions with AND, OR, and NOT logic. Use field-level operators to precisely narrow, expand, and exclude results without writing SQL.

AND / OR / NOT logicMultiple conditionsField-level investigation

Multi-File & Multi-Source Correlation

Load multiple security datasets and investigate related activity across different sources to uncover connections between users, IPs, hosts, processes, domains, and other security telemetry.

Multi-file investigationCross-source analysisSecurity telemetry correlation

Regex Investigation

Go beyond keyword searches with regular expressions for IOC hunting, pattern matching, complex string analysis, and advanced security investigations.

Regex conditionsIOC huntingPattern matching

Built-In Investigation Filters

Start investigating with 50+ ready-to-use security filters covering IPs, URLs, domains, hashes, PowerShell, RDP, authentication activity, suspicious processes, and other security artifacts.

50+ filtersSecurity artifactsInvestigation ready

Every feature

A complete investigation workstation — no plugins, no cloud, no configuration.

General Search

Perform fast free-text keyword searches across your loaded security telemetry.

Multiple File Formats

Load CSV, TSV, LOG, TXT, JSON, XML, XLS, XLSX, and XLSM files directly into LogSearchX.

Column Filtering & Projection

Filter investigation results by individual columns and use Project Columns to focus the workspace on the fields that matter.

Timeline Investigation

Analyze investigation results chronologically to understand when activity occurred and how events progressed over time.

Statistics & Data Analysis

Analyze result distributions, counts, and patterns to identify important activity and support deeper investigation.

Save & Reuse Queries

Save, load, and manage investigation queries so frequently used searches can be reused during future investigations.

Bulk & Filtered Export

Export investigation results and filtered findings for reporting, evidence handling, and further analysis.

Fully Offline

No cloud dependency, no telemetry upload, and no SIEM required. Investigate sensitive security datasets locally on your Windows machine.

Built for every technical team

Cybersecurity

  • SOC Analysts
  • Threat Hunters
  • Incident Responders
  • Digital Forensics
  • Security Researchers

IT & Infrastructure

  • System Administrators
  • Network Engineers
  • IT Operations
  • Infrastructure Engineers
  • Cloud Engineers

Software & Engineering

  • Developers
  • QA Engineers
  • SREs
  • DevOps Engineers
  • Application Support

Data & Operations

  • Database Administrators
  • Technical Support
  • Production Support
  • Operations Teams
  • Data Analysts

No SIEM. No server. No cloud.

Runs entirely on your Windows machine
Your investigation data stays on your machine
No SIEM ingestion pipeline or database deployment required
Designed for restricted and offline environments
Investigate sensitive security telemetry locally

Start investigating in minutes

Download the free edition, load your first dataset, and start investigating security telemetry locally.