Designing intuitive interfaces for complex data
NXLog is a cybersecurity and observability company specializing in enterprise-grade log management solutions. Their platform enables organizations to collect, process, and route logs from diverse systems for monitoring, compliance, and threat detection.

Problem
Log search is one of the platform’s core workflows, it is the tool security analysts rely on to investigate events, trace threats, and catch discrepancies across massive volumes of log data. As NXLog’s visual identity and feature set matured, log search hadn’t kept pace. New capabilities had been added incrementally over time, and the feature had outgrown its original structure
Our team redesigned the flow end to end. We restructured how features were grouped and where they were positioned and brought the entire flow in line with NXLog’s current visual identity.
UX Audit
We started with a UX audit of the existing log search experience, which surfaced two core issues:
A fragmented search process. The steps of a single search lived in disconnected areas of the screen, forcing analysts to piece the workflow together themselves instead of following a clear path.
A disruptive detail view. Opening a single log entry launched a slide-in panel that pulled analysts out of their results entirely, breaking their scan pattern and forcing them to relocate their place in the list every time they returned

Competitor Analysis
To ground the redesign in the category, we also analyzed how established tools handle log search. Reviewing Kibana, Datadog, and Splunk let us adopt interface patterns analysts already knew.
We immediately established that controls and content consistently competed for the same space across all three tools. We noted emergent design pattern among these solutions like the infinite scroll and a persistent timeline were universal, as well as what we found best practices (e.g.: color-coding by data type let analysts scan for a specific log type without reading every row)
Notably, none of the competitors we reviewed used an inline detail view, they all relied on slide-ins or panel overlays that pulled analysts out of their results. Since product managers had flagged screen space for search results as a priority. We built a mockup with an inline viewer to test whether it could resolve both the workflow interruption we'd identified and the space constraint.
Testing
With formal usability testing not possible, we took the next best approach: walking cybersecurity experts through our mockups and asking about their real-world workflows, to validate our design decisions against how they actually work. This surfaced several key insights.
Analysts commonly use Ctrl+F to search within the detailed log view, confirming that our inline detail viewer would support, rather than disrupt, an existing habit.
Query behavior splits by experience level, power users default to full-text search, while less experienced analysts rely on a SQL builder. This told us the redesign needed to support both entry points, not force a single query method.
Timeline placement showed a similar split with some users finding the side-positioned timeline unusual, while others valued having the timeline and search bar integrated. Rather than picking one camp over the other, this pointed us toward a flexible layout that could accommodate both preferences.
Solution
Where the log search flow had grown fragmented and hard to navigate, we rebuilt it around clarity and control, unifying scattered elements, adapting the layout for small screens, and bringing the experience in line with NXLog's evolved visual identity.





Trade-Offs
We initially explored keeping the query builder inline. However, this created a trade-off with grouping items, as not all analysts build complex, nested queries regularly, having the full grouping interface inline meant the search bar would bloat in height and prominence for every user.
Upon checking with the PM, we moved grouping into a pop-up: the default search bar stays thin and out of the way, while the full query builder is available on demand for the users who need it. Our group recommended A/B testing, however it was not possible.


Implementation
We built out the new UI as documented, annotated design system components, (e.g.:the fields in the filter panel, table fields, updated filter chips) so the reasoning behind each pattern would hold up for future contributors, not just the engineers building it in this round.
As well as writing detailed specs for each redesigned feature, covering interaction states, edge cases, and responsive behaviour, to reduce ambiguity during handoff and keep implementation aligned with the intended experience.

Thank you for taking a look, make sure to check out other works too
Next gen. payment experiences- design strategy
- research
- product design
Supporting lead decision makers with long-term product strategy
seam- product design
- impact-driven
- service design
A Kintsugi-inspired therapy support tool for processing trauma
Mercedes Memory Lane- product design
- speculative
- UX research
Transforming everyday journeys into memories that can be revisited and shared.
If any of the stories behind my projects resonate with you or something you're building, then let's connect!
hello@kitana.design