Pagination

Many list endpoints support pagination via query parameters. The defaults below apply to the standard envelope; individual endpoints document exceptions, including unpaginated historical results:

Parameter Type Default Max Description
limit integer 100 1000 Maximum items to return
offset integer 0 — Number of items to skip

Paginated endpoints return a standard envelope:

{
  "data": [...],
  "total": 42,
  "limit": 100,
  "offset": 0
}

Endpoints using this envelope:

Already-paginated endpoints (GET /events, GET /alerts, GET /incidents, GET /ssh/sessions, GET /audit-log) retain their existing response keys (events, alerts, incidents, sessions, entries) and now also include limit and offset in the response.