Search Logs (Aggregated)
search_logsQuery logs to return aggregated totals, top hosts, paths, status codes, user agents, a bucketed timeline, and a small sample for exploratory analysis instead of raw events.
Instructions
Runs a query and returns an aggregated summary (total, top hosts/paths/status codes/user agents, a bucketed timeline, and a small representative sample) instead of raw events. Prefer this over get_events/iterate_events_* for exploratory analysis.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| from | No | -1h | |
| query | No | * | |
| top_n | No | ||
| until | No | now | |
| account | No | ||
| host_field | No | ||
| path_field | No | ||
| sample_size | No | ||
| bucket_count | No | ||
| status_field | No | ||
| user_agent_field | No |