Search logs
search_logsQuery Graylog log messages with a Lucene query to debug issues. Returns compact, redacted lines with a 'ref' for follow-up. Default range: last 15 minutes.
Instructions
Search log messages with a Lucene query. Returns compact, redacted lines with a 'ref' (index/id) usable by get_message and context_around. Default range: last 15 minutes.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sort | No | 'timestamp:desc' (default), 'asc', or '<field>:asc|desc' | timestamp:desc |
| limit | No | Messages to fetch (capped by config) | |
| query | No | Lucene query, '*' for everything | * |
| range | No | Relative range ending now (or at to_time): '15m', '2h', '1d', '1h30m' | |
| fields | No | Fields to return; default timestamp/source/level/message, ['*'] for all | |
| offset | No | Skip this many messages (use next_offset) | |
| streams | No | Stream titles or ids to search in; all streams when omitted | |
| to_time | No | Absolute end, same formats as from_time; default now | |
| instance | No | Graylog instance (environment) from list_instances, e.g. 'staging' or 'prod'; the default instance when omitted | |
| from_time | No | Absolute start: ISO 8601 or 'YYYY-MM-DD HH:MM' in the instance timezone; overrides range | |
| dedup_lines | No | Group lines that only differ in numbers/ids/timestamps (default true) |