exportLogs
exportLogsSave matching Loki log lines from a selected time window to a local file, oldest first, by passing a LogQL query and optional start, end, format, and directory.
Instructions
Save matching log lines of a window to a local file, oldest first, when the user asks to save logs. Pass the same LogQL query as queryLogs, e.g. {app="backend"} |= "ERROR". Omit format to use the connection's default export format, which is raw unless the operator set a template; format="raw" keeps the lines returned by Loki, including any LogQL line_format stage; a template like "{time} {level:5} [{thread}] {logger} : {message}{stack}" rewrites them locally. Pass a user-specified directory directly; omit it for the default export directory. The answer gives the file path, the line count, and a start value to continue with when a limit stopped it.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end | No | Window end. Default "now". Same formats as start. | |
| query | Yes | LogQL log query, e.g. {app="backend"} |= "ERROR". Take label names and values from discoverLogs. | |
| start | No | Window start, default now-1h. Examples: now-15m, now-2d, 2026-09-13T10:00:00+03:00. | |
| format | No | Omit it for the connection's default export format (raw unless configured). "raw" forces the lines returned by Loki; a template with {time}, {level}, {service}, {logger}, {message}, {stack} and line fields like {thread} renders locally. | |
| directory | No | Local directory for the new file, e.g. C:\tmp\logs or incident-42. Omit it for the default export directory; a relative path is resolved under that directory. Configured exportRoots, if present, restrict destinations. | |
| connection | Yes | Connection name from listConnections |