Application Logs (Admin)
List Logs
GET /api/v1/logs
Returns recent application log entries from the in-memory ring buffer (2000 entries max, no database persistence). Admin-only. Used by the Logs tab in the Activity pane for initial page load before WebSocket streaming takes over; the WebSocket continuation (log_subscribe) enforces the same admin gate in the hub.
Query parameters:
| Parameter |
Type |
Required |
Default |
Description |
level |
string |
No |
-- |
Minimum log level filter: debug, info, warn, error |
service |
string |
No |
-- |
Filter by service name: engine, api, collector-manager, snmp-poller, collector |
search |
string |
No |
-- |
Case-insensitive substring search in log message |
limit |
integer |
No |
200 |
Max entries to return (1-2000) |
Response: 200 OK
{
"logs": [
{
"type": "log",
"timestamp": "2026-02-28T14:30:00.123Z",
"level": "info",
"service": "engine",
"message": "snapshot processed for area 0.0.0.0",
"fields": "{\"area_id\":\"uuid\"}"
}
],
"total": 1847
}
| Field |
Type |
Description |
logs |
array |
Log entries matching filters, newest first |
logs[].type |
string |
Always "log" |
logs[].timestamp |
string (RFC 3339) |
Log event timestamp |
logs[].level |
string |
"debug", "info", "warn", "error" |
logs[].service |
string |
Originating service name |
logs[].message |
string |
Log message text |
logs[].fields |
string (optional) |
Additional structured fields as JSON string |
total |
integer |
Total entries in ring buffer (before filtering) |
Error responses:
401 Unauthorized -- Missing or invalid access token
403 Forbidden -- Non-admin user