Logs

Run a log query

Changed on

Run a log query with no model involved, given either the queryId of an earlier logs.ask answer or logs.executeQuery run, or a spec written in the log query spec (its JSON Schema is this operation's spec input; sazabi logs query schema prints it). Runs over window (by default the same absolute times a queryId read, or the last hour for a spec; a relative window ends now, which asks the same question again over the latest period), with an optional limit, or narrowed to the log lines of one group of a table. Returns the same envelope as logs.ask without an answer: results, what was measured (explanation), how exact and complete the numbers are (meta), and a new queryId naming this run (its query and the times it read). A run by queryId names that id as parentId. An unknown queryId is not found; a spec the service cannot run is refused with what to change; asking the question again yields a new id.

post/logs/queries/execute

Request

  • Base URL: https://api.sazabi.com/v1
  • URL: https://api.sazabi.com/v1/logs/queries/execute
  • Auth: none declared

Request body

projectIdstring uuid

Project to run the query in. Auto-filled from CLI and SDK context when omitted.

queryIdstring uuid

queryId of an earlier logs.ask answer or logs.executeQuery run, to run that query again. Give queryId or spec, not both.

limitinteger

Maximum rows, groups, points or kinds in results (1-5,000). It only pages results: the answer, and each result's matched and total, are computed over every matching line whatever the limit. Rows are the newest (or earliest) matching lines, up to this many; tables, series and top messages are cut to this many of the groups or points the question asks for (its top 20, or the top N it names); a search's results show at most 50 kinds of log lines. truncated says when more matched than results shows.

groupstring[]

For a query whose results are a table: return the log lines of one group instead of the table, as one value per column before the measure (a group's key).

Response

OK

queryIdstring uuid

Id of this query. Pass it to logs.executeQuery to run the same query again with no model involved, a not_found answer's included (over a wider window, say). Absent only when nothing was planned (a refused question, or an error before any query), so there is nothing to run again.

parentIdstring uuid

With logs.executeQuery by queryId only: the queryId that was run. Absent when a spec was run.

status'ok' | 'not_found' | 'partial' | 'error' required

ok answered; partial answered in part: for part of the window, or without a detail the logs do not record, such as request status codes (the answer says which); not_found the query ran and nothing matched in window, for the question as read (interpretedAs); error the question could not be answered, or was refused (rejection).

answerstring

The plain-language answer. Present on every logs.ask reply.

explanationstring required

What was measured, over which window, in plain words.

interpretedAsstring

How the question was read, so it can be rephrased.

writeDeclinedunknown

Changes

    • ▲

      removed subschema #1 subschema #2 subschema #3 from the / request property anyOf list

    • ▲

      removed subschema #3 subschema #4 subschema #5 subschema #9 from the / request property anyOf list

    • ○

      added subschema #1 subschema #2 subschema #3 to the / request property anyOf list

    • ○

      added subschema #3 subschema #4 subschema #5 subschema #9 to the / request property anyOf list

    • ○

      added the new 10m enum value to the request property /

    • ○

      added the new 12h enum value to the request property /

    • ○

      added the new 15m enum value to the request property /

    • ○

      added the new 30m enum value to the request property /

    • ○

      added the new 6h enum value to the request property /