Sherlog
v1.0 is now available

Your logs deserve
a better home.

Stop juggling AWS Console tabs and CSV exports. Query CloudWatch Logs and local files in a native macOS notebook.

Native macOS app • Universal Binary • No subscription

Built for how you actually debug

Log investigation is iterative. You query, you refine, you cross-reference. Sherlog is designed around that workflow—not fighting against it.

Think in Blocks

Each query is a block with its own context. Chain investigations together, compare results side-by-side, and never lose your train of thought.

CloudWatch Without the Console

Query multiple log groups across regions without opening 15 browser tabs. Same Insights syntax you know, minus the AWS Console frustration.

Drop Files, Get Answers

Drag a CSV export, JSON dump, or JSONL file into Sherlog and instantly query it with SQL. No import wizards, no database setup.

DuckDB Under the Hood

Your local queries run on DuckDB—the same engine powering modern data tools. Analyze millions of rows without breaking a sweat.

Actually Native

Not an Electron app. Built with SwiftUI for instant startup, low memory usage, and the responsiveness you expect from macOS software.

Results That Make Sense

Interactive data grids with sorting, filtering, and one-click export. See patterns in your logs, not just walls of text.

From question to answer in seconds

No setup wizards. No configuration files. Open Sherlog and start investigating.

01

Connect or Drop

Link your AWS credentials to query CloudWatch, or drag-and-drop local log files. Both work seamlessly.

02

Write Your Query

Use CloudWatch Insights syntax for AWS logs, or standard SQL for local files. Each block remembers its own time range and source.

03

See Results Instantly

Results appear in an interactive grid. Sort columns, filter rows, and export what you need without leaving the app.

04

Add Another Block

Found something interesting? Add a new block to dig deeper. Your investigation builds like a document you can save and revisit.

The old way vs. Sherlog

You've been doing this the hard way. Here's what changes.

Before

Switching between AWS Console tabs

With Sherlog

All log groups in one interface

Before

Copy-pasting results to spreadsheets

With Sherlog

Query and analyze in the same place

Before

Re-running queries after timeout

With Sherlog

Persistent blocks that save your work

Before

CLI tools for local file analysis

With Sherlog

Drag, drop, and query with SQL

Before

Losing context between sessions

With Sherlog

Notebook saves your investigation

Before

Waiting for Electron apps to load

With Sherlog

Native macOS speed

Real scenarios. Real solutions.

Sherlog was built by engineers who got tired of the same painful debugging workflows. Here's when it shines.

3 AM Production Incident

"Users are reporting 500 errors. You need answers fast."

Query your API Gateway logs and Lambda logs side by side. Filter by request ID, trace the error through services, and identify the failing deployment—all without context-switching.

Post-Deployment Verification

"You just shipped. Did anything break?"

Compare error rates before and after deployment. Query two time ranges in separate blocks and visually diff the results. Know within minutes, not hours.

Customer Support Escalation

"Support needs to know what happened to user X at timestamp Y."

Pull CloudWatch logs and that CSV export from your billing system. Query both with SQL and correlate by user ID. Export your findings as evidence.

Compliance Audit

"Security team needs 90 days of access logs analyzed."

Export logs to JSON, drop them into Sherlog, and run SQL aggregations. Who accessed what, when, how many times. Generate the report without spinning up infrastructure.

Professional Edition

Your next incident shouldn't take all night.

Download Sherlog and turn your chaotic debugging sessions into structured investigations. First query in under 60 seconds.

macOS 12.0+ No telemetry