Manage Logs Query usage
Not yet enforced
The allowance and degraded-state consequences described on this page are not enforced yet. This page describes how enforcement will work once the grace period ends at the start of 2027.
What you are charged for#
Logs Query usage isn't billed directly. Instead, your organization gets a log query allowance that scales with how much log data you ingest. The allowance covers the volume of log data scanned when you read logs through the Studio UI, the Management API, the CLI, or any other interface.
How your allowance is calculated#
Every organization gets a query allowance scaled to its log ingest usage, at a fixed ratio:
Query allowance = 100 × log ingest usageThe Free Plan includes 1 GB of ingest, so it also includes 100 GB of query allowance. Paid plans include 20 GB of ingest, so they start with 2,000 GB of query allowance. If you ingest more than your plan's included amount and pay for the overage, your allowance grows at the same 100x rate.
| Monthly ingest | Ingest overage (billed) | Query allowance |
|---|---|---|
| 20 GB | 0 GB | 2,000 GB |
| 21 GB | 1 GB | 2,100 GB |
| 25 GB | 5 GB | 2,500 GB |
| 40 GB | 20 GB | 4,000 GB |
| 100 GB | 80 GB | 10,000 GB |
There's no separate per-GB price for Logs Query. Your allowance is always 100 times your ingest usage for the same month.
Usage on your invoice#
Logs Query doesn't appear as a line item on your invoice, because it isn't billed directly.
View usage#
You can view Logs Query usage on the organization's usage page of the Dashboard. The page shows the usage of all projects by default. To view the usage for a specific project, select it from the dropdown. You can also select a different time period.
Optimize usage#
Two people asking similar-sounding questions can generate very different amounts of usage, depending on how they ask. These tips help you avoid scanning more data than a question requires — they're habits, not restrictions, and none of them ask you to give up visibility you need.
- Narrow your time range to what the question needs. Query cost scales with how much data a query scans, and time range is usually the biggest factor: a 1-day window scans about 7 times less data than a 7-day window. Start with the smallest window that could contain the answer, and widen only if you don't find it. Keep a wide window when you're doing genuine historical or trend analysis on purpose — that's a real use case, only a more expensive one by nature.
- Filter as part of the query, not after you've pulled the data. Add filters for source, service, status code, or project before you run a search. A broad, unfiltered query scans everything in its time range, even if you only look at a fraction of the results afterwards. Filtering after the fact doesn't reduce what was already scanned.
- Use the Logs Explorer for ad-hoc digging, not scripted polling. Every query scans data again — there's no caching benefit from asking the same question repeatedly. A script that polls the query endpoint on a schedule re-scans on every run, so it can use far more allowance than a person checking manually, even if it usually finds nothing new.
- Use Log Drains for anything continuous. If you need an ongoing feed of your logs — for your own monitoring stack, alerting, or archiving — repeatedly querying for what's new since you last checked is one of the most expensive ways to get it, because each check re-scans. Drains stream logs to a destination as they arrive instead.
After you change how you query, check your usage trend over the following few days rather than a single day. Usage varies with how much debugging or investigation you happen to do, so a single day's change isn't a reliable signal on its own.
When you exceed your allowance#
If you scan more log data than your allowance covers in a given month, the following month enters a degraded state:
- Queries are rate limited to 10 per minute.
- Log retention shrinks to 24 hours (Pro, Team, and Enterprise) or 1 hour (Free).
If you exceed your allowance again the next month, while still in that degraded state, logs access in the API and Studio UI will be cut off entirely for the month after. Access returns to normal at your next billing cycle.
A concrete walkthrough#
- January: You use 20 GB of ingest and 2,450 GB of query, more volume than your allowance covers.
- February: Degraded — 10 queries/min, retention shrunk to 24 hours on paid tiers, 1 hour on the Free Plan.
- March: If February also went over, that's two consecutive months, so this month is a full cutoff.
- April: Billing cycle resets, access returns to normal. This allows you to make continued efforts to optimize your log query usage.