Topology Events (Read)

List Events

GET /api/v1/events
GET /api/v1/events?area_id={areaID}
GET /api/v1/events?area_id={areaID}&type={eventType}&entity_type={entityType}&router_id={routerID}&from={from}&to={to}&limit={limit}&offset={offset}

Query the topology event log. Returns time-ordered events (newest first) matching the filter criteria. With no area_id, the result is deployment-wide, as used by the Activity panel.

Query parameters:

Response: 200 OK

{
  "events": [
    {
      "id": "uuid",
      "event_time": "2026-02-16T14:23:46.456Z",
      "area_id": "uuid",
      "collector_id": "collector-nyc-dc1-01",
      "event_type": "link_cost_changed",
      "entity_type": "link",
      "entity_id": "uuid",
      "router_id": "10.0.0.2",
      "detail": {
        "router_a": "10.0.0.2",
        "router_b": "10.0.0.3",
        "old_cost": 10,
        "new_cost": 100
      },
      "incident_id": "uuid",
      "display_names": {
        "10.0.0.2": "core-rtr-01.ams",
        "10.0.0.3": "edge-rtr-02.ams"
      }
    }
  ],
  "total": 42,
  "limit": 100,
  "offset": 0
}

Optional cursor pagination (from 1.4.4):

Use pagination=cursor to traverse recorded history without offset shifts:

GET /api/v1/events?pagination=cursor&area_id={areaID}&limit=100
GET /api/v1/events?pagination=cursor&area_id={areaID}&limit=100&cursor={next_cursor}

This mode returns pagination: "cursor", events, limit, has_more, next_cursor and window_to. It does not return total or offset. The last page has has_more: false and next_cursor: null. Event objects retain all the ordinary fields and enrichment described above.

Keep the same filters, including the presence or absence of from and to, on every page; limit may change. Copy next_cursor as an opaque URL-encoded query value. Do not send offset, including offset=0, with this mode. The first request fixes window_to to to, or the current server time if omitted, at microsecond precision. Future to values and from > window_to are rejected. Rows are ordered by event time and UUID, descending.

Cursors expire after 24 hours or an installation signing-key rotation. A malformed, modified, expired or filter-mismatched cursor returns 400; start a new traversal when it expires. Every page still requires authentication. A cursor grants no access and does not extend history retention.

This is historical traversal, not a consistent database snapshot or lossless incremental feed. Newer events do not shift the next page, but a later insert with an older event time in an already traversed range can be missed. Retention can remove rows between requests. Related-link membership, display names and incident attribution reflect their state when each page is read.

Always check that the response says pagination: "cursor": release 1.4.3 ignores these unknown query parameters and returns the ordinary offset envelope. Omitting pagination=cursor keeps the existing behavior used by the application.

Notes:

Error responses: