
Company:
WatchGuard Technologies
Year:
2024
Duration:
3 months
Overview
Log Search is an enterprise search experience within WatchGuard Cloud that helps administrators investigate network activity, troubleshoot issues, and identify security events across large volumes of log data. While the underlying search engine already existed, the user experience needed to make complex queries approachable without limiting the flexibility required by experienced administrators.
As the lead product designer, I was responsible for designing the complete experience, from query creation and filtering to results exploration and saved searches. My work included user research, interaction design, prototyping, usability testing, and close collaboration with engineering throughout implementation.

Problem
Searching enterprise security logs is inherently complex. Administrators need to investigate incidents quickly while working with thousands, or even millions of log entries containing dozens of searchable fields, operators, and filters.
Traditional log-search interfaces often assume users already understand query syntax, making advanced investigations difficult for newer administrators while slowing experienced users with cumbersome workflows.
The challenge was to create an experience that supported both audiences: allowing new users to build powerful searches without memorizing query language while still enabling advanced users to construct complex queries efficiently. The interface also needed to present large datasets in a way that made patterns, anomalies, and investigation workflows easier to understand.
Solution
Rather than exposing administrators directly to query syntax, I designed a guided search experience that progressively built complex searches through visual controls. Users could construct powerful queries by selecting fields, operators, and values while the interface generated the underlying search logic automatically.
For more advanced investigations, the experience seamlessly transitioned into an advanced query mode where administrators could edit the generated query directly. This approach reduced the learning curve for new users while preserving the efficiency expected by experienced analysts.
The results experience was designed to support rapid investigation. Filters remained easily accessible, search history reduced repetitive work, and large result sets were organized for quick scanning without overwhelming the user. Throughout the design process, prototypes were iteratively tested with users and refined alongside engineering to ensure the experience remained both technically powerful and approachable.
The final design transformed Log Search from a feature intended primarily for networking experts into an investigation tool that better supported administrators with varying levels of technical experience while remaining scalable as additional log types and search capabilities were introduced.









