Search Container Logs
get_logsSearch aggregated logs from Cycle containers. First stop for crash loops, application errors, and confirming "out of memory" / "no space left" style failures. Use after diagnose points at a specific container or instance, or directly when the user names one.
Scope with environment for environment-wide logs, add container to narrow, add instance to narrow further — the most specific reference wins. Search is optional; without it the newest lines in the range are returned. Use search_type "regexp" with RE2 syntax for patterns like "(?i)error|panic". context_window returns surrounding lines after each match (lines sharing a context_window ID belong to the same match).
Defaults to the last hour. If nothing comes back, widen the range or loosen the search — a container that just started may also not have shipped logs yet. Read-only.
To wait for a line to APPEAR (readiness/migration-done markers like "database system is ready"), pass search plus wait_seconds: the call polls until the first match or the budget elapses, instead of you sleeping between calls. A no-match result after the wait is not failure — repeat the same call to keep waiting.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum log lines to return, 1-500. | |
| search | No | Text or pattern to match log messages against. Omit to return the newest lines in the range. | |
| compact | No | Reduce structured JSON lines (ECS, logrus, zap...) to level, message, and error fields, dropping envelope fields. Non-JSON lines pass through unchanged. Use for chatty JSON loggers such as Elasticsearch. | |
| context | No | Why are you calling this tool? Briefly describe the user's goal. | |
| instance | No | Instance id or hostname. Narrowest scope; requires container. | |
| container | No | Container to pull logs from. Narrows the scope to one container. | |
| range_end | No | RFC3339 end of the log window. Defaults to now. | |
| environment | No | Environment to pull logs from. Broadest scope. | |
| range_start | No | RFC3339 start of the log window. Defaults to one hour before range_end. | |
| search_type | No | raw = exact substring match (default). regexp = RE2 pattern, e.g. (?i)error|panic. | |
| wait_seconds | No | Max seconds to block waiting for the first matching line, polling every few seconds (0 = return immediately). Requires search; not combinable with range_end. Values above 60 are clamped — longer blocking calls are unreliable through connectors; repeat the call to keep waiting. | |
| context_window | No | Lines of surrounding context to include after each match, 0-10. | |
| conversation_id | No | Conversation tracking id. Omit on your first tool call; every result then includes a conversation_id line — pass that exact value on all later calls in this conversation. |