apmlog.get

Description

integer/array apmlog.get(object parameters)

The method allows you to retrieve log records according to the given parameters.

This method is available to users of any type. Permissions to call the method can be revoked in user role settings. See User roles for more information.

Parameters

(object) Parameters defining the desired output.

The method supports the following parameters.

Parameter Type Description
time_from timestamp Return only log records of events that occurred at or after the given time.

Parameter behavior:
- required
time_till timestamp Return only log records of events that occurred before the given time.

Parameter behavior:
- required
traceids string/array Return only log records produced during the given traces.
spanids string/array Return only log records produced during the given spans.
with_flags_on integer Return only log records that have all of the given trace flags set.
To specify several flags, use the sum of their values.
with_flags_off integer Return only log records that have none of the given trace flags set.
To specify several flags, use the sum of their values.
resource_attributes object/array Return only log records with the given resource attributes.
Format: [{"key": "<key>", "value": "<value>", "operator": "<operator>"}, ...].
An empty array returns all log records.

Possible operator values:
0 - (default) Contains;
1 - Equals;
2 - Does not contain;
3 - Does not equal;
4 - Exists;
5 - Does not exist.
resource_attributes_evaltype integer Evaluation method for the conditions in resource_attributes.

Possible values:
0 - (default) And/Or;
2 - Or.
scope_attributes object/array Return only log records with the given scope attributes.
Format: [{"key": "<key>", "value": "<value>", "operator": "<operator>"}, ...].
An empty array returns all log records.

Possible operator values:
0 - (default) Contains;
1 - Equals;
2 - Does not contain;
3 - Does not equal;
4 - Exists;
5 - Does not exist.
scope_attributes_evaltype integer Evaluation method for the conditions in scope_attributes.

Possible values:
0 - (default) And/Or;
2 - Or.
log_attributes object/array Return only log records with the given log attributes.
Format: [{"key": "<key>", "value": "<value>", "operator": "<operator>"}, ...].
An empty array returns all log records.

Possible operator values:
0 - (default) Contains;
1 - Equals;
2 - Does not contain;
3 - Does not equal;
4 - Exists;
5 - Does not exist.
log_attributes_evaltype integer Evaluation method for the conditions in log_attributes.

Possible values:
0 - (default) And/Or;
2 - Or.
filter object Return only those results that exactly match the given filter.

Accepts an object, where the keys are property names, and the values are either a single value or an array of values to match against.

Supported properties: traceid, spanid, trace_flags, severity_text, severity_number, service_name, resource_schema_url, scope_schema_url, scope_name, scope_version, event_name.
search object Return results that match the given pattern (case-insensitive).

Accepts an object, where the keys are property names, and the values are strings to search for. If no additional options are given, this will perform a LIKE "%…%" search.

Supported properties: severity_text, service_name, body, resource_schema_url, scope_schema_url, scope_name, scope_version, event_name.
sortfield string/array Sort the result by the given properties.

Possible values: timestamp, traceid, spanid, trace_flags, severity_text, severity_number, service_name, resource_schema_url, scope_schema_url, scope_name, scope_version, event_name.
offset integer Number of records to skip before returning the result.
countOutput boolean These parameters are described in the reference commentary.
excludeSearch boolean
limit integer
output query
searchByAny boolean
searchWildcardsEnabled boolean
sortorder string/array
startSearch boolean

Return values

(integer/array) Returns either:

  • an array of objects;
  • the count of retrieved objects, if the countOutput parameter has been used.

Examples

Retrieving error logs of a trace

Retrieve log records with the ERROR severity (severity numbers 17-20) that are associated with the trace "8a4f1c7e2b9d4e6fa0c3b5d7e9f1a2c4".

Request:

{
    "jsonrpc": "2.0",
    "method": "apmlog.get",
    "params": {
        "output": "extend",
        "time_from": 1790848800,
        "time_till": 1790852400,
        "traceids": "8a4f1c7e2b9d4e6fa0c3b5d7e9f1a2c4",
        "filter": {
            "severity_number": [17, 18, 19, 20]
        },
        "sortfield": "timestamp",
        "sortorder": "ASC"
    },
    "id": 1
}

Response:

{
    "jsonrpc": "2.0",
    "result": [
        {
            "timestamp": "1790849305091452376",
            "traceid": "8a4f1c7e2b9d4e6fa0c3b5d7e9f1a2c4",
            "spanid": "5d2e8f1a9c3b7046",
            "trace_flags": "1",
            "severity_text": "ERROR",
            "severity_number": "17",
            "service_name": "zabbix-frontend",
            "body": "mysqli_query(): (HY000/1205): Lock wait timeout exceeded; try restarting transaction",
            "resource_schema_url": "https://opentelemetry.io/schemas/1.26.0",
            "resource_attributes": {
                "service.name": "zabbix-frontend",
                "host.name": "6583ceeb5f94",
                "host.arch": "x86_64",
                "os.type": "linux"
            },
            "scope_schema_url": "",
            "scope_name": "zabbix-frontend",
            "scope_version": "",
            "scope_attributes": {},
            "log_attributes": {
                "log.file.path": "/var/log/zabbix/zabbix_frontend.log",
                "code.filepath": "/usr/share/zabbix/include/db.inc.php"
            },
            "event_name": ""
        }
    ],
    "id": 1
}

Searching log messages

Retrieve the time, service, and message of the 10 latest log records whose message contains "timeout".

Request:

{
    "jsonrpc": "2.0",
    "method": "apmlog.get",
    "params": {
        "output": ["timestamp", "service_name", "severity_text", "body"],
        "time_from": 1790848800,
        "time_till": 1790852400,
        "search": {
            "body": "timeout"
        },
        "sortfield": "timestamp",
        "sortorder": "DESC",
        "limit": 10
    },
    "id": 1
}

Response:

{
    "jsonrpc": "2.0",
    "result": [
        {
            "timestamp": "1790849305091452376",
            "service_name": "zabbix-frontend",
            "severity_text": "ERROR",
            "body": "mysqli_query(): (HY000/1205): Lock wait timeout exceeded; try restarting transaction"
        },
        {
            "timestamp": "1790848961730284115",
            "service_name": "zabbix-frontend",
            "severity_text": "ERROR",
            "body": "mysqli_query(): (HY000/1205): Lock wait timeout exceeded; try restarting transaction"
        }
    ],
    "id": 1
}

See also

Source

CApmLog::get() in ui/include/classes/api/services/CApmLog.php.