Skip to content

Logs API

Both endpoints need telemetry.view, are rate limited to 120/minute, and return 503 when Loki is not configured. Results are newest first; continue with cursor = meta.cursor until it is empty.

Query Default Rule
since 3600 Seconds back, up to 30 days
limit 100 1–1000
level trace, debug, info, warn, error, fatal
kind both app (log files, programs, cron, containers) or access (edge requests)
cursor From the previous page
Terminal window
curl "https://falak.example.com/api/v1/sites/shop/logs?since=600&level=error&kind=app" \
-H "Authorization: Bearer $FALAK_TOKEN" -H "Accept: application/json"
{"data": [{"at": "2026-09-26T10:00:02.000000+00:00", "level": "ERROR", "source": "laravel", "server": "web-1",
"message": "boom", "attributes": {"service_name": "laravel"}}],
"meta": {"cursor": "1790000000000000001"}}

The site’s edge access log (Network Logs): one entry per request served for the site, by its servers or by its load balancer.

Query Meaning
since, limit, cursor As above
server Server id
deployment Requests served while that deployment’s release was live
method HTTP method
status A code (404) or a class (5xx)
path Substring of the request URI
client_ip Client address
{"data": [{"ts": "1790000000000000002", "at": "2026-09-28T10:00:02.000000+00:00", "method": "GET", "path": "/cart",
"query": "x=1", "status": 502, "duration_ms": 12.3, "bytes": 512, "request_bytes": 0,
"client_ip": "203.0.113.9", "user_agent": "curl/8.5", "host": "shop.example.com",
"server_id": "01k…", "deployment_id": "01k…", "release_id": "01k…"}],
"meta": {"cursor": "1790000000000000002"}}

See Logs and Network logs.