Review status, traffic, and security events
Start broad, select the affected route, then move to detailed events.
Dashboard
Use the Dashboard for current service health, traffic totals, resource use, and items that need attention. A warning here identifies the next surface to inspect; it is not a replacement for Logs.
Analytics
Select the affected route and time range. Review traffic over time, request outcomes, latency, block sources, and targeted routes. Analytics shows the pattern; it does not contain every event detail. Bot-challenge pages use the Challenge block source. WAF-triggered challenges appear in Detections as Challenged; rate-limit challenges do not create WAF evaluations.
Enter a local start and end date-time to query any interval for which data still exists. The Dashboard keeps its fixed 24-hour operational view.
Analytics retention
Configure retention in System → Settings → Analytics or with the Core labels in the configuration catalog.
Changes take effect on the next analytics retention job. Saving does not prune immediately. Decreasing retention permanently deletes data outside the new window when the job runs; increasing retention cannot restore already-pruned data.
Longer retention can substantially increase disk use, especially for path and blocked-IP rollups whose distinct values can grow with incoming traffic.
Services
Use Services to confirm that the Clearplane components are online, inspect resource use, review pending restart settings, and apply staged configuration when required. Under ContainerProxy, check whether discovery is reconciling normally and open a container's status icon to inspect its accepted state, failures, every unrecognized label, and warnings.
Logs
Filter by route first, then narrow by service, type, level, host, source address, status, or elapsed time. Use live mode only after the historical filter identifies the event shape you need.
When indexing is catching up, the page shows that status; recent events may appear after the next refresh. Use Previous and Next to move through results. Refresh returns to the newest matching entries.
Choose Count matching logs when you need an exact total for the current filters. Counting is separate from browsing and can take longer for broad filters or millions of entries. Narrow the route and time range to reduce the work.
Clear logs
Choose Clear logs, select the cutoff, and submit to queue a background operation. The dialog shows its progress, deleted counts, and completion result. You can close it and reopen Clear logs to check the operation later; pending work resumes after a Core restart.
Clearing permanently deletes entries covered by the selected cutoff across every route, service, and log type, regardless of the page filters. Detection records covered by the same cutoff are deleted with them. Today's and yesterday's raw files are kept because services may still be writing to them; their eligible indexed entries are still cleared.
Disk space is reclaimed in the background. A large clear can take time to finish even though the request is accepted immediately.
Scheduled retention
Use System settings → Logs to review the effective retention settings and what controls them. Indexed retention covers detection records as well as log entries.
Review the Log retention job's schedule and run history under Observability → Background jobs.
Background jobs
Open Observability → Background jobs to review run status, results, and logs. When a running Core process cancels a job, the run is marked Done with a Failure result and a cancellation message in its log. Check the message before retrying. A forced process termination can prevent that final update.
Verify
Confirm the same route and time window across Dashboard or Analytics and Logs. The high-level count and detailed events should describe the same behavior.