The story is in the order
Read the top of the table downward and the outage assembles itself: the link drops, the line protocol follows, OSPF loses the neighbour, spanning tree reconverges, the access points fall off. Severity colour is what makes that readable at a glance instead of a wall of text.
It is a syslog server, not a log viewer
It listens on port 1514 by default, over UDP and TCP, and accepts what your switches, firewalls, hypervisors and Linux boxes already send. There is nothing to install on them — you point them at your computer and they start arriving.
Old logs stay searchable
Messages are rolled to compressed archives on disk rather than dropped, and Search archived logs reaches back into them. Retention is a number you set, not a plan tier that quietly deletes your evidence.
Free covers every host, with three alert rules
Everything sending to you is received and stored on the free tier, from any number of hosts, with up to three alert rules. Pro adds full-text search across the archive, up to 50 rules, email notifications and CSV/JSON export. Enterprise adds the AI detection pass that flags patterns nobody wrote a rule for.