Open a trace
From the trace explorer. Click a span on the Spans tab of Traces. The trace opens with that span selected. From a log. Open any log in the detail drawer. If the log carries a trace ID, a Trace tab appears alongside the other tabs, showing the waterfall inline. Click Open trace page for the full page. From service health. A row on a service’s Errors tab opens its trace in a new tab, with that span selected. See Service health. By trace ID. Paste a trace ID (32 hexadecimal characters, any case) into the log search box or the explorer’s Search spans box, and press Enter. If the span store has no spans for that ID, it runs as a text search where you pasted it. Wrap the ID in quotes to search for it as text from the start. By URL. A trace has a permanent address at/traces/<traceId>. A trace with no spans in the span store opens empty: its spans may not have arrived yet, or may be past retention.
The header
The header shows the root operation, the total duration, the root span’s service and start time, the trace ID (click to copy), and each service’s span count. When spans failed, click the error count to select the first failing span.The waterfall
Spans are colored by service, and spans that ended in an error are marked.- Click the arrow beside a span to collapse or expand its children.
- Drag across the timeline strip above the waterfall to zoom into a window. Drag the frame to pan, or its edges to resize it. Double-click the strip to see the whole trace again.
- Select a span to open its detail panel. The URL gains
span=<spanId>, so a link can point at one span.
Search spans
The search box above the waterfall finds spans within the trace. It matches service names, span names, span IDs, and attributes written askey=value, ignoring case. For example, status_code=503 finds spans whose HTTP status is 503.
Spans that don’t match are dimmed. Press Enter and Shift+Enter to step through the matches.
Span details
The detail panel has four tabs. Database and Events are disabled when the span has none.Database calls
A span is a database call when it carriesdb.system, db.system.name, db.statement, or db.query.text. The tab counts those calls in the selected span and all of its descendants, with their summed duration. Concurrent calls overlap, so the sum can exceed the span’s own duration.
Calls are grouped by database (the system plus server.address or net.peer.name), then by statement (db.statement or db.query.text, falling back to the span name). Each statement shows its call count, total time, and failures. Expand it to see each call, and click a call to select its span.
Statements group on their exact text, and instrumentation usually sends them parameterized. A query run once per row in a loop therefore collapses into one statement with a high call count, the usual sign of an N+1 query.
Correlate logs with traces
Correlation in both directions depends on one per-index setting, Trace ID field: the dot-notation path to the trace ID inside a log document. It defaults totrace_id, which matches the OpenTelemetry log schema, so the bundled otel-logs-v0_9 index needs no configuration.
For a custom schema, set it to wherever your trace ID lives, for example attributes.traceId, on the index’s Configuration tab under Settings → Indexes. See Manage indexes. Until it points at a real field, logs and traces stay unlinked: no Trace tab in the log drawer, and no log counts on spans.
Per-span links and counts read a top-level span_id field. That path is not configurable, so on a custom schema without it, only the trace-wide link works.
Jump back to logs
The header’s index picker sets which index holds the trace’s logs. It defaults to the index you came from, or the last log index you used.- Logs for this trace opens Logs filtered on the trace ID over the trace’s time window.
- Spans with logs carry a count in the waterfall. Logs for this span, in the detail panel, also filters on the span ID.

