Logs

For instructions on how to authenticate to use this endpoint, see API overview.

Endpoints

GET
POST
GET
PATCH
DELETE
POST
POST
GET
POST
POST
POST
POST
GET
POST
POST
POST
POST
POST
POST

List all logs alerts

Also available via the PostHog MCP server:

  • logs-alerts-list — List log alerts

Required API key scopes

logs:read

Query parameters

  • created_by
    string
  • limit
    integer
  • offset
    integer

Response


Example request

GET /api/projects/:project_id/logs/alerts
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/

Example response

Status 200
RESPONSE
{
"count": 123,
"next": "http://api.example.org/accounts/?offset=400&limit=100",
"previous": "http://api.example.org/accounts/?offset=200&limit=100",
"results": [
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"enabled": true,
"filters": {
"filterGroup": null,
"serviceNames": null,
"severityLevels": null
},
"threshold_count": 100,
"threshold_operator": "above",
"window_minutes": 5,
"check_interval_minutes": 0,
"state": "not_firing",
"evaluation_periods": 1,
"datapoints_to_alarm": 1,
"cooldown_minutes": 0,
"schedule_restriction": {
"blocked_windows": [
{
"start": "string",
"end": "string"
}
]
},
"snooze_until": "2019-08-24T14:15:22Z",
"next_check_at": "2019-08-24T14:15:22Z",
"last_notified_at": "2019-08-24T14:15:22Z",
"last_checked_at": "2019-08-24T14:15:22Z",
"consecutive_failures": 0,
"last_error_message": "string",
"state_timeline": [
{
"start": "2019-08-24T14:15:22Z",
"end": "2019-08-24T14:15:22Z",
"state": "not_firing",
"enabled": true
}
],
"destination_types": [
"slack"
],
"first_enabled_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"created_by": {
"id": 0,
"uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",
"distinct_id": "string",
"first_name": "string",
"last_name": "string",
"email": "user@example.com",
"is_email_verified": true,
"hedgehog_config": {},
"role_at_organization": "engineering"
},
"updated_at": "2019-08-24T14:15:22Z"
}
]
}

Create logs alerts

Also available via the PostHog MCP server:

  • logs-alerts-create — Create log alert

Required API key scopes

logs:write

Request parameters

  • name
    string
  • enabled
    boolean
    Default: true
  • filters
  • threshold_count
    integer
    Default: 100
  • threshold_operator
    Default: above
  • window_minutes
    integer
    Default: 5
  • evaluation_periods
    integer
    Default: 1
  • datapoints_to_alarm
    integer
    Default: 1
  • cooldown_minutes
    integer
    Default: 0
  • schedule_restriction
  • snooze_until
    string | null

Response


Example request

POST /api/projects/:project_id/logs/alerts
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/\
-d name="string"

Example response

Status 201
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"enabled": true,
"filters": {
"filterGroup": null,
"serviceNames": null,
"severityLevels": null
},
"threshold_count": 100,
"threshold_operator": "above",
"window_minutes": 5,
"check_interval_minutes": 0,
"state": "not_firing",
"evaluation_periods": 1,
"datapoints_to_alarm": 1,
"cooldown_minutes": 0,
"schedule_restriction": {
"blocked_windows": [
{
"start": "string",
"end": "string"
}
]
},
"snooze_until": "2019-08-24T14:15:22Z",
"next_check_at": "2019-08-24T14:15:22Z",
"last_notified_at": "2019-08-24T14:15:22Z",
"last_checked_at": "2019-08-24T14:15:22Z",
"consecutive_failures": 0,
"last_error_message": "string",
"state_timeline": [
{
"start": "2019-08-24T14:15:22Z",
"end": "2019-08-24T14:15:22Z",
"state": "not_firing",
"enabled": true
}
],
"destination_types": [
"slack"
],
"first_enabled_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"created_by": {
"id": 0,
"uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",
"distinct_id": "string",
"first_name": "string",
"last_name": "string",
"email": "user@example.com",
"is_email_verified": true,
"hedgehog_config": {},
"role_at_organization": "engineering"
},
"updated_at": "2019-08-24T14:15:22Z"
}

Retrieve logs alerts

Also available via the PostHog MCP server:

  • logs-alerts-retrieve — Get log alert

Required API key scopes

logs:read

Path parameters

  • id
    string

Response


Example request

GET /api/projects/:project_id/logs/alerts/:id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/

Example response

Status 200
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"enabled": true,
"filters": {
"filterGroup": null,
"serviceNames": null,
"severityLevels": null
},
"threshold_count": 100,
"threshold_operator": "above",
"window_minutes": 5,
"check_interval_minutes": 0,
"state": "not_firing",
"evaluation_periods": 1,
"datapoints_to_alarm": 1,
"cooldown_minutes": 0,
"schedule_restriction": {
"blocked_windows": [
{
"start": "string",
"end": "string"
}
]
},
"snooze_until": "2019-08-24T14:15:22Z",
"next_check_at": "2019-08-24T14:15:22Z",
"last_notified_at": "2019-08-24T14:15:22Z",
"last_checked_at": "2019-08-24T14:15:22Z",
"consecutive_failures": 0,
"last_error_message": "string",
"state_timeline": [
{
"start": "2019-08-24T14:15:22Z",
"end": "2019-08-24T14:15:22Z",
"state": "not_firing",
"enabled": true
}
],
"destination_types": [
"slack"
],
"first_enabled_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"created_by": {
"id": 0,
"uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",
"distinct_id": "string",
"first_name": "string",
"last_name": "string",
"email": "user@example.com",
"is_email_verified": true,
"hedgehog_config": {},
"role_at_organization": "engineering"
},
"updated_at": "2019-08-24T14:15:22Z",
"destinations": [
{
"hog_function_ids": [
"497f6eca-6276-4993-bfeb-53cbbbba6f08"
],
"type": "slack",
"enabled": true,
"slack_workspace_id": 0,
"slack_channel_id": "string",
"webhook_url": "string"
}
]
}

Update logs alerts

Also available via the PostHog MCP server:

  • logs-alerts-partial-update — Update log alert

Required API key scopes

logs:write

Path parameters

  • id
    string

Request parameters

  • name
    string
  • enabled
    boolean
    Default: true
  • filters
  • threshold_count
    integer
    Default: 100
  • threshold_operator
    Default: above
  • window_minutes
    integer
    Default: 5
  • evaluation_periods
    integer
    Default: 1
  • datapoints_to_alarm
    integer
    Default: 1
  • cooldown_minutes
    integer
    Default: 0
  • schedule_restriction
  • snooze_until
    string | null

Response


Example request

PATCH /api/projects/:project_id/logs/alerts/:id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X PATCH \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/\
-d name="string"

Example response

Status 200
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"enabled": true,
"filters": {
"filterGroup": null,
"serviceNames": null,
"severityLevels": null
},
"threshold_count": 100,
"threshold_operator": "above",
"window_minutes": 5,
"check_interval_minutes": 0,
"state": "not_firing",
"evaluation_periods": 1,
"datapoints_to_alarm": 1,
"cooldown_minutes": 0,
"schedule_restriction": {
"blocked_windows": [
{
"start": "string",
"end": "string"
}
]
},
"snooze_until": "2019-08-24T14:15:22Z",
"next_check_at": "2019-08-24T14:15:22Z",
"last_notified_at": "2019-08-24T14:15:22Z",
"last_checked_at": "2019-08-24T14:15:22Z",
"consecutive_failures": 0,
"last_error_message": "string",
"state_timeline": [
{
"start": "2019-08-24T14:15:22Z",
"end": "2019-08-24T14:15:22Z",
"state": "not_firing",
"enabled": true
}
],
"destination_types": [
"slack"
],
"first_enabled_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"created_by": {
"id": 0,
"uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",
"distinct_id": "string",
"first_name": "string",
"last_name": "string",
"email": "user@example.com",
"is_email_verified": true,
"hedgehog_config": {},
"role_at_organization": "engineering"
},
"updated_at": "2019-08-24T14:15:22Z"
}

Delete logs alerts

Also available via the PostHog MCP server:

  • logs-alerts-destroy — Delete log alert

Required API key scopes

logs:write

Path parameters

  • id
    string

Example request

DELETE /api/projects/:project_id/logs/alerts/:id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/

Example response

Status 204 No response body

Create logs alerts destinations

Also available via the PostHog MCP server:

  • logs-alerts-destinations-create — Attach alert destination

Create a notification destination for this alert. One HogFunction is created per alert event kind (firing, resolved, ...) atomically.

Required API key scopes

logs:write

Path parameters

  • id
    string

Request parameters

  • type
  • slack_workspace_id
    integer
  • slack_channel_id
    string
  • slack_channel_name
    string
  • webhook_url
    string

Response


Example request

POST /api/projects/:project_id/logs/alerts/:id/destinations
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/destinations/\
-d type=undefined

Example response

Status 201
RESPONSE
{
"hog_function_ids": [
"497f6eca-6276-4993-bfeb-53cbbbba6f08"
]
}

Create logs alerts destinations delete

Also available via the PostHog MCP server:

  • logs-alerts-destinations-delete-create — Detach alert destination

Delete a notification destination by deleting its HogFunction group atomically.

Required API key scopes

logs:write

Path parameters

  • id
    string

Request parameters

  • hog_function_ids
    array

Example request

POST /api/projects/:project_id/logs/alerts/:id/destinations/delete
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/destinations/delete/\
-d hog_function_ids="array"

Example response

Status 204 No response body

List all logs alerts events

Also available via the PostHog MCP server:

  • logs-alerts-events-list — List alert events

Paginated event history for this alert, newest first. Returns state transitions, errored checks, and user-initiated control-plane rows (reset, enable/disable, snooze/unsnooze, threshold change) — quiet no-op check rows (where state didn't change and there was no error) are filtered out since only the last 10 are kept and they carry no forensic value. Optional ?kind=... narrows to a single kind.

Required API key scopes

logs:read

Path parameters

  • id
    string

Query parameters

  • limit
    integer
  • offset
    integer

Response


Example request

GET /api/projects/:project_id/logs/alerts/:id/events
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/events/

Example response

Status 200
RESPONSE
{
"count": 123,
"next": "http://api.example.org/accounts/?offset=400&limit=100",
"previous": "http://api.example.org/accounts/?offset=200&limit=100",
"results": [
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"kind": "check",
"state_before": "string",
"state_after": "string",
"threshold_breached": true,
"result_count": 0,
"error_message": "string",
"query_duration_ms": 0
}
]
}

Create logs alerts reset

Reset a broken alert. Clears the consecutive-failure counter and schedules an immediate recheck.

Required API key scopes

logs:write

Path parameters

  • id
    string

Response


Example request

POST /api/projects/:project_id/logs/alerts/:id/reset
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/:id/reset/

Example response

Status 200
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"enabled": true,
"filters": {
"filterGroup": null,
"serviceNames": null,
"severityLevels": null
},
"threshold_count": 100,
"threshold_operator": "above",
"window_minutes": 5,
"check_interval_minutes": 0,
"state": "not_firing",
"evaluation_periods": 1,
"datapoints_to_alarm": 1,
"cooldown_minutes": 0,
"schedule_restriction": {
"blocked_windows": [
{
"start": "string",
"end": "string"
}
]
},
"snooze_until": "2019-08-24T14:15:22Z",
"next_check_at": "2019-08-24T14:15:22Z",
"last_notified_at": "2019-08-24T14:15:22Z",
"last_checked_at": "2019-08-24T14:15:22Z",
"consecutive_failures": 0,
"last_error_message": "string",
"state_timeline": [
{
"start": "2019-08-24T14:15:22Z",
"end": "2019-08-24T14:15:22Z",
"state": "not_firing",
"enabled": true
}
],
"destination_types": [
"slack"
],
"first_enabled_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"created_by": {
"id": 0,
"uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",
"distinct_id": "string",
"first_name": "string",
"last_name": "string",
"email": "user@example.com",
"is_email_verified": true,
"hedgehog_config": {},
"role_at_organization": "engineering"
},
"updated_at": "2019-08-24T14:15:22Z"
}

Create logs alerts simulate

Also available via the PostHog MCP server:

  • logs-alerts-simulate-create — Simulate log alert

Simulate a logs alert on historical data using the full state machine. Read-only — no alert check records are created.

Required API key scopes

logs:read

Request parameters

  • filters
  • threshold_count
    integer
  • threshold_operator
  • window_minutes
    integer
  • check_interval_minutes
    integer
    Default: 5
  • evaluation_periods
    integer
    Default: 1
  • datapoints_to_alarm
    integer
    Default: 1
  • cooldown_minutes
    integer
    Default: 0
  • date_from
    string

Response


Example request

POST /api/projects/:project_id/logs/alerts/simulate
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/alerts/simulate/\
-d filters=undefined,\
-d threshold_count="integer",\
-d threshold_operator=undefined,\
-d window_minutes="integer",\
-d date_from="string"

Example response

Status 200
RESPONSE
{
"buckets": [
{
"timestamp": "2019-08-24T14:15:22Z",
"count": 0,
"threshold_breached": true,
"state": "string",
"notification": "string",
"reason": "string"
}
],
"fire_count": 0,
"resolve_count": 0,
"total_buckets": 0,
"threshold_count": 0,
"threshold_operator": "string"
}

Create logs anomalies scan

Runs anomaly detection on demand over one service's log volume for the given window. Learns per severity baselines from up to 6 weeks of history and returns per bucket expected bands plus any spike, drop, or silence issues. Synchronous and read only.

Required API key scopes

logs:read

Request parameters

  • serviceName
    string
  • dateRange

Response


Example request

POST /api/projects/:project_id/logs/anomalies/scan
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/anomalies/scan/\
-d serviceName="string",\
-d dateRange=undefined

Example response

Status 200 Scan results: per severity evidence series and any issues that opened.
RESPONSE
{
"service_name": "string",
"eval_start": "2019-08-24T14:15:22Z",
"eval_end": "2019-08-24T14:15:22Z",
"lookback_days": 0.1,
"eval_clipped": true,
"degraded": true,
"binding_constraints": [
"team_retention"
],
"series": [
{
"severity": "string",
"stage": "insufficient",
"tier": "a",
"history_start": "2019-08-24T14:15:22Z",
"limited_by": "series_history",
"buckets": [
{
"time": "2019-08-24T14:15:22Z",
"observed": 0.1,
"expected": 0,
"lower": 0,
"upper": 0,
"stage": "insufficient",
"verdict": "spike"
}
]
}
],
"issues": [
{
"direction": "up",
"severity": "string",
"kind": "spike",
"state": "pending",
"opened_at": "2019-08-24T14:15:22Z",
"last_anomalous_at": "2019-08-24T14:15:22Z",
"resolved_at": "2019-08-24T14:15:22Z",
"anomalous_bucket_times": [
"2019-08-24T14:15:22Z"
]
}
]
}
Status 422 The scan exceeded its read budget at every degradation step.
RESPONSE
{
"error": "string"
}

Create logs anomalies series bands

Returns log volume over the requested window for every (namespace, environment, severity) series of one service, with a time-of-week expected band derived from the prior weeks of the volume rollup. The window defaults to the last 7 days and may span at most 7 days. Synchronous and read only.

Required API key scopes

logs:read

Request parameters

  • serviceName
    string
  • dateRange
  • intervalMinutes

Response


Example request

POST /api/projects/:project_id/logs/anomalies/series_bands
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/anomalies/series_bands/\
-d serviceName="string"

Example response

Status 200 Observed volume and expected band per series of the service.
RESPONSE
{
"service_name": "string",
"window_start": "2019-08-24T14:15:22Z",
"window_end": "2019-08-24T14:15:22Z",
"interval_minutes": 0,
"series_truncated": true,
"series": [
{
"namespace": "string",
"environment": "string",
"severity": "string",
"total_count": 0,
"baseline_weeks": 0,
"history_start": "2019-08-24T14:15:22Z",
"band_ready_at": "2019-08-24T14:15:22Z",
"interval_minutes": 0,
"coarsened_reason": "sparse",
"buckets": [
{
"time": "2019-08-24T14:15:22Z",
"observed": 0,
"lower": 0,
"upper": 0,
"verdict": "above"
}
]
}
]
}
Status 400 The requested window is empty, too wide, or starts before the volume rollup reaches.
RESPONSE
{
"error": "string"
}
Status 422 The service has too many series to chart in one response.
RESPONSE
{
"error": "string"
}

Retrieve logs attributes

Required API key scopes

logs:read

Query parameters

  • attribute_type
    string
    One of: "log""resource"
  • dateRange
  • date_from
    string
  • date_to
    string
  • filterGroup
    Click to open
    array
    Default:
  • keys
    string
  • limit
    integer
  • offset
    integer
  • search
    string
  • search_values
    boolean
    Default: false
  • serviceNames
    array
    Default:

Response


Example request

GET /api/projects/:project_id/logs/attributes
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/attributes/

Example response

Status 200
RESPONSE
{
"results": [
{
"name": "string",
"propertyFilterType": "string",
"matchedOn": "key",
"matchedValue": "string"
}
],
"count": 0
}

Create logs count

Required API key scopes

logs:read

Request parameters

  • query

Response


Example request

POST /api/projects/:project_id/logs/count
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/count/\
-d query=undefined

Example response

Status 200
RESPONSE
{
"count": 0
}

Create logs count ranges

Required API key scopes

logs:read

Request parameters

  • query

Response


Example request

POST /api/projects/:project_id/logs/count-ranges
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/count-ranges/\
-d query=undefined

Example response

Status 200
RESPONSE
{
"ranges": [
{
"date_from": "string",
"date_to": "string",
"count": 0
}
],
"interval": "string"
}

Create logs explainlogwithai

Explain a log entry using AI.

POST /api/environments/:id/logs/explainLogWithAI/

Required API key scopes

logs:write

Request parameters

  • uuid
    string
  • timestamp
    string
  • force_refresh
    boolean
    Default: false

Response


Example request

POST /api/projects/:project_id/logs/explainLogWithAI
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/explainLogWithAI/\
-d uuid="string",\
-d timestamp="string"

Example response

Status 201
RESPONSE
{
"uuid": "string",
"timestamp": "2019-08-24T14:15:22Z",
"force_refresh": false
}

Create logs export

Required API key scopes

logs:read

Example request

POST /api/projects/:project_id/logs/export
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/export/

Example response

Status 201

Create logs facet values

Required API key scopes

logs:read

Request parameters

  • query

Response


Example request

POST /api/projects/:project_id/logs/facet_values
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/facet_values/\
-d query=undefined

Example response

Status 200
RESPONSE
{
"results": [
{
"value": "string",
"count": 0
}
]
}

Create logs group by

Required API key scopes

logs:read

Request parameters

  • query

Response


Example request

POST /api/projects/:project_id/logs/group-by
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/projects/:project_id/logs/group-by/\
-d query=undefined

Example response

Status 200
RESPONSE
{
"groups": [
{
"value": "string",
"values": [
"string"
],
"log_count": 0,
"error_count": 0,
"last_seen": "string"
}
],
"total_groups": 0,
"total_logs": 0,
"truncated": true
}