get_events
List cluster- or namespace-wide Kubernetes events filtered by reason, type, or involved object to diagnose evictions, scheduling failures, and warnings.
Instructions
Lists cluster- or namespace-wide events with optional server-side filtering.
Unlike `get_pod_events` (which is scoped to a single named pod), this supports
the sweep queries common in capacity/storage runbooks — e.g. all "Evicted"
events, or all "FailedScheduling" events — where the affected pods often have no
stable name to look up. Note Kubernetes expires an event record about an hour
(by default) after its last occurrence, so events that stopped repeating
earlier than that are gone.
Parameters
----------
namespace : Optional[str], default=None
Namespace to list events from. If None, lists across all namespaces.
reason : Optional[str], default=None
If set, only return events with this reason (e.g. "Evicted",
"FailedScheduling", "BackOff").
involved_kind : Optional[str], default=None
If set, only return events whose involved object is of this kind (e.g.
"Pod", "Node", "PersistentVolumeClaim").
involved_name : Optional[str], default=None
If set, only return events whose involved object has this name.
event_type : Optional[str], default=None
If set, only return events of this type ("Normal" or "Warning").
Returns
-------
list of EventSummary
Matching events. Each EventSummary has the following fields:
last_seen : Optional[datetime.timedelta]
Time since the event was last seen (if available).
first_seen : Optional[datetime.timedelta]
Time since the first occurrence combined into this record (if
available).
count : Optional[int]
How many occurrences Kubernetes combined into this record: repeats
of the same event on the same object are counted in one record
rather than listed separately. The count covers first_seen to
last_seen, not the object's lifetime - a record that stops repeating
expires (after 1h by default), and a later repeat starts a new one.
For a crash-looping container, count the "Created" or "Started"
events to get restarts. "BackOff" is emitted repeatedly while the
kubelet waits to restart, so its count is several times the number
of restarts. count divided by (first_seen - last_seen) is the
average rate over that window, not the current back-off.
A record can lag behind what it counts. By default the kubelet
writes at most one event update per object and event type
("Normal" or "Warning") every 5 minutes, once a burst of 25 is
used up; occurrences in between are counted but only written with
the next update, which then jumps by several at once. So count and
last_seen describe the most recent *written* occurrence and can
trail reality by several occurrences and tens of minutes. They lag
together, so the rate above still holds, but last_seen is not the
time of the last restart: for that, use the container status
(last_state.finished_at, state.started_at from
get_pod_container_statuses) or PodSummary.last_restart, which come
from the kubelet's status rather than from events. "Pulled",
"Created" and "Started" share one write budget, so their counts for
the same restarts can differ by a few; don't compare counts across
reasons.
type : str
Type of the event ("Normal" or "Warning").
reason : str
Reason for the event.
object : str
The involved object as "Kind/name" (or just the name when the kind is
unavailable).
message : str
Message describing the event.
Raises
------
K8sConfigError
If unable to initialize the K8S API.
K8sApiError
If the API call to list events fails.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| reason | No | ||
| namespace | No | ||
| event_type | No | ||
| involved_kind | No | ||
| involved_name | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |