wherethemlogs.app

MCP serverFiles & storage

Where apps write their log files on Windows, macOS and Linux, as exact copyable paths.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use wherethemlogs.app to search log locations

Install wherethemlogs.app

The server’s own address, for the clients that take one directly. Or connect ahel once and every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user wherethemlogs-app 'https://wherethemlogs.app/api/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://wherethemlogs.app/api/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=wherethemlogs-app&config=eyJ1cmwiOiJodHRwczovL3doZXJldGhlbWxvZ3MuYXBwL2FwaS9tY3AifQ==

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://wherethemlogs.app/api/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add wherethemlogs-app --url 'https://wherethemlogs.app/api/mcp'

    Run it once, then sign in with codex mcp login wherethemlogs-app if the server asks for an account.

From the project's README

As published by scotscottmca/wherethemlogs.app in README.md.

A searchable index of application log file locations across Windows, macOS and Linux - every path qualified by installer type and architecture, printed exactly as the machine writes it.

Built for the people who need the path mid-incident: IT and endpoint administrators, application packagers, and anyone else who has lost twenty minutes to a forum thread of unknown vintage.

Layout

app/                  pages, route handlers, proxy - Next.js 16
components/  lib/     UI, shared model, server-only data access
infra/                Azure resources - Bicep
scripts/              seed data and the seeder
docs/                 architecture, API reference, deployment, MCP, answer engines

One application, one image. Pages are server-rendered from Cosmos; route handlers under app/api/ serve the browser and the admin portal from the same process.

Run it

npm install
LOCAL_ADMIN_BYPASS=true \
COSMOS_ENDPOINT=https://<account>.documents.azure.com:443/ \
COSMOS_DATABASE=wtla \
npm run dev            # http://localhost:3777

Needs az login with an account that holds the Cosmos data-plane role. Full setup is in docs/DEPLOYMENT.md.

What's here

RouteWhat it does
/Title sign, search field with live type-ahead, recent additions, recent searches, platform filter
/searchFull results, filterable by platform, installer, architecture and scope
/privacyPrivacy and cookie notice
/adminAdmin portal - vendors, apps and log paths, with JSON import and export at /admin/import. Entra sign-in, admin role. API in docs/API.md.

Keyboard: / focuses the search field from anywhere, arrows walk the type-ahead, Enter commits to the full results, Shift+Enter copies the highlighted result's first path.

The catalogue

Vendor > App > LogPath. One vendor has many apps; one app has many log paths, embedded on the app document. Every vendor carries an icon and every app may override it - App.iconUrl: null means inherit the vendor's, resolved on read.

Currently seed data: 24 vendors, 33 apps, 86 log paths in scripts/seed-data.json, all real and verifiable, labelled as a demonstration set in the footer and on the privacy page.

npm run seed -- --endpoint https://<account>.documents.azure.com:443/

Paths are stored byte for byte - %LOCALAPPDATA%, ~/Library/Logs, $XDG_STATE_HOME are never expanded, because the machine being fixed is not this one.

Contributing an entry

Open an issue. One issue per application, with the platform and installer type in the title, and say how you verified the path.

Issues are public: do not paste real hostnames, usernames, tenant identifiers or customer names into one.

Before this goes live

  • Register the Entra ID app, add the admin app role, and set the AUTH_CLIENT_ID / AUTH_TENANT_ID repository variables. Until then /admin has nowhere to send you. docs/DEPLOYMENT.md § 7.
  • Choose the analytics provider - Google Analytics 4, loaded only after Accept (components/Consent.tsx).
  • Replace the seed catalogue with the real index - /admin/import takes the research JSON.
  • Build the admin UI on top of the CRUD API.
  • Make the repo public - requests and corrections are issues here, from the forms in .github/ISSUE_TEMPLATE/.

Infrastructure

Azure Container Apps runs the image; Cosmos DB (serverless) and Blob Storage sit behind it, both reached by managed identity - no keys anywhere. Deploys are a new revision, so rolling back is a traffic shift rather than a rebuild.

Around $20/month. Why each piece, and what it costs, is in docs/ARCHITECTURE.md.

Design

DESIGN.md records the visual system as built. PRODUCT.md records product truth. The direction contract for the site's surfaces lives in .impeccable/surfaces/.

Two rules worth knowing before you touch the CSS:

  • Flat print, no exceptions. No gradients, no shadows, no floating cards. Structure is stencilled rules and hazard tape. Signal cyan on near-black must not drift into neon glow.
  • Two voices. Archivo for anything human, Spline Sans Mono for anything machine-true - paths, codes, counts, filter values. Nothing else.

Tools it offers (2)

What this server listed when ahel dialed its public endpoint in Oct 2026, with no key and no account of yours. The names are the server’s own.

  • search_log_locations
  • get_app_log_locations

Signals

Last commit
Oct 2026
Advanced
Delivery
log-locations MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
app-wherethemlogs-log-locations
Source
github.com/scotscottmca/wherethemlogs.app
Hosted endpoint
https://wherethemlogs.app/api/mcp