Explore and the query API
Explore is the app’s home page. Pick Logs or Metrics, a time range (15 minutes to 7 days, or custom) and filters; Pulse draws the graph or the log table and refreshes every 30 seconds. The query is kept in the page URL, so bookmark or share it.
Data is queryable as soon as it arrives, including rows not yet written to storage, for the last 7 days (UTC days, today included). Older days have gone to your bucket; see Archive.
POST /api/v1/query
Send an API key with the read scope. Times are milliseconds since the epoch.
Logs:
{ "signal": "logs", "from": 1760140800000, "to": 1760144400000,
"service": "checkout", "minSev": 17, "contains": "timeout", "attrs": { "http.route": "/pay" }, "limit": 200 }
{ "signal": "logs", "rows": [ { "time": 1760144391123, "sev": 17, "sevText": "ERROR", "body": "upstream timeout", "service": "checkout", "attrs": {}, "resource": {} } ],
"histogram": [[1760140800000, 3], [1760141100000, 0]], "scanned": { "files": 2, "bytes": 1830211, "bufferedRows": 412 }, "truncated": false }
Metrics:
{ "signal": "metrics", "from": 1760140800000, "to": 1760144400000,
"name": "http.server.duration", "agg": "p95", "step": 60, "groupBy": ["http.route"] }
{ "signal": "metrics", "series": [ { "labels": { "http.route": "/pay" }, "points": [[1760140800000, 182.5]] } ],
"scanned": { "files": 2, "bytes": 1830211, "bufferedRows": 412 }, "truncated": false }
| Field | Logs | Metrics |
|---|---|---|
from, to |
Required | Required |
service, minSev, contains |
Optional, see Logs | — |
attrs |
Optional exact matches | Optional exact matches |
limit |
1-1,000, default 200, newest first | — |
step |
Histogram bucket width in seconds (optional) | Required, at least 10 |
name, agg, groupBy |
— | name and agg required, see Metrics |
Big queries
A query reads at most 2,000 files or about 1.5 GB of column data, and runs for at most 20 seconds. Past that you get what was read so far with "truncated": true: narrow the time range, or filter on service or name.
Points are [time, value] pairs at the start of each step.
Next: Live tail · This page as Markdown