SearchSQL
Run time-windowed SQL queries against OpenObserve streams to retrieve matching log rows for production analysis.
Instructions
Run SQL against an OpenObserve stream and return the matching rows. The stream name is the FROM target. start and end accept an ISO timestamp, a plain date, epoch seconds/ms/µs, a relative offset like "-24h" or "-90m", or "now". They default to the last 24 hours. Bucket by time with histogram(_timestamp, '1 hour'). _timestamp is microseconds since the epoch. Call StreamList first if you do not know what exists, and StreamSchema before querying a stream whose fields you have not seen — field names differ per stream and guessing wastes a round trip. Beware that many log shippers emit SEVERAL rows per request (one per output line), so a naive count(*) overstates traffic. Check the schema for a status or level field and count only rows that carry one.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end | No | Window end. Default now. | |
| sql | Yes | e.g. SELECT level, count(*) AS n FROM my_stream GROUP BY level ORDER BY n DESC | |
| size | No | Maximum rows to return. Default 50, maximum 1000. | |
| start | No | Window start. Default -24h. | |
| max_field_chars | No | Truncate long string fields to this length. Default 400. |