rsc_get_events
Retrieve recent backup jobs, failures, and anomalies for workloads within a time window. Filter by workload to diagnose failures and get recommended remedies.
Instructions
Get recent events and activity for workloads.
Returns backup jobs, failures, anomalies, and other activity. Always scoped to a time window (default: last 24 hours) to keep queries fast.
For failure details, each event includes the error message, reason, and recommended remedy where available.
Args: last_hours: How far back to look, in hours. Default 24. Always provide this — omitting a time range makes the query very slow. workload_id: Filter to a specific workload FID (from rsc_get_workloads). Use this to answer "why did the backup fail for workload X". object_name: Filter by object name substring. status: Filter by event status. One of: SUCCESS, FAILURE, WARNING, RUNNING, CANCELED, CANCELING, QUEUED, PARTIAL_SUCCESS, TASK_FAILURE, TASK_SUCCESS, INFO. severity: Filter by severity. One of: SEVERITY_CRITICAL, SEVERITY_WARNING, SEVERITY_INFO. activity_type: Filter by activity type. Common values: BACKUP, RECOVERY, REPLICATION, ARCHIVE, ANOMALY, INDEX, LOG_BACKUP. cluster_id: Filter by Rubrik cluster UUID. limit: Maximum number of events to return. Default 100.
Returns:
A dict with count (true total matching the filter), returned (how
many events are in this response), truncated (True when more events
exist than were returned, because of limit or the record cap), and
events (the list of event records). Report count for "how many"
questions, not len(events).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| status | No | ||
| severity | No | ||
| cluster_id | No | ||
| last_hours | No | ||
| object_name | No | ||
| workload_id | No | ||
| activity_type | No |