Logs

Run an earlier log query (deprecated)

Changed on

Deprecated alias for POST /logs/queries/execute with a queryId; removed on 2027-03-01. Run the query behind an earlier logs.ask answer again, by its queryId, with no model involved: over the window the answer covered or a new one, with a new limit, or narrowed to the log lines of one group of a table. Returns results without an answer, and a new queryId whose parentId is the one that was run. An unknown id is not found; asking the question again yields a new id.

post/logs/queries/{queryId}/execute

Request

  • Base URL: https://api.sazabi.com/v1
  • URL: https://api.sazabi.com/v1/logs/queries/{queryId}/execute
  • Auth: none declared

Path parameters

queryIdstring uuid required

queryId returned by an earlier logs.ask answer.

Request body

projectIdstring uuid

Project the query belongs to. Auto-filled from CLI and SDK context when omitted.

limitinteger

Maximum rows, groups, points or kinds in results (1-5,000). It only pages results: the answer, and each result's matched and total, are computed over every matching line whatever the limit. Rows are the newest (or earliest) matching lines, up to this many; tables, series and top messages are cut to this many of the groups or points the question asks for (its top 20, or the top N it names); a search's results show at most 50 kinds of log lines. truncated says when more matched than results shows.

groupstring[]

For a query whose results are a table: return the log lines of one group instead of the table, as one value per column before the measure (a group's key).

Response

OK

queryIdstring uuid

Id of this query. Pass it to logs.executeQuery to run the same query again with no model involved, a not_found answer's included (over a wider window, say). Absent only when nothing was planned (a refused question, or an error before any query), so there is nothing to run again.

parentIdstring uuid

With logs.executeQuery by queryId only: the queryId that was run. Absent when a spec was run.

status'ok' | 'not_found' | 'partial' | 'error' required

ok answered; partial answered in part: for part of the window, or without a detail the logs do not record, such as request status codes (the answer says which); not_found the query ran and nothing matched in window, for the question as read (interpretedAs); error the question could not be answered, or was refused (rejection).

answerstring

The plain-language answer. Present on every logs.ask reply.

explanationstring required

What was measured, over which window, in plain words.

interpretedAsstring

How the question was read, so it can be rephrased.

writeDeclinedunknown

Changes

    • ▲

      removed the required property from the response with the status

    • ○

      api operation id logs.executeQuery removed and replaced with logs.executeQueryById

    • ○

      endpoint deprecated

    • ○

      added the optional property // to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added subschema #2 subschema #3 subschema #4 subschema #5 subschema #6 subschema #7 to the response property anyOf list for the response status

    • ○

      removed subschema #2 subschema #3 subschema #4 subschema #5 subschema #6 subschema #7 from the response property anyOf list for the response status

    • ○

      added subschema #1 to the response property anyOf list for the response status