---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Query a log entry"
description: "`observability.log_entries.query` (POST /v1/{parent}/log_entries:query): Queries the environment's log entries over a bounded interval; follow a trace with `trace_id = '...'`."
type: reference
product: monitoring
summary: "Queries the environment's log entries over a bounded interval; follow a trace with `trace_id = '...'`."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Queries the environment's log entries over a bounded interval; follow a trace with `trace_id = "..."`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/log_entries:query`
- **Scope** `observability:read`
- **Effect** `read` — nothing is written.
- **Collection** [log_entries](/docs/api/log_entries)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The parent the method acts in. Required. |
| `filter` | `string` | AIP-160 filter over the typed, allowlisted fields. |
| `start_time` | `timestamp` | The interval start; required, at most 31 days before `end_time`. Required. |
| `end_time` | `timestamp` | The interval end; default now. |
| `order_by` | `string` | `time desc` (default) or `time asc`. |
| `page_size` | `int32` | At most this many; default 100, clamped to 1000. |
| `page_token` | `string` | `next_page_token` of the previous page; bound to tenant, interval, filter, and order. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `log_entries` | `LogEntry[]` | The page. |
| `next_page_token` | `string` | The token of the next page; empty on the last page. |

### LogEntry

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/log_entries/{log_entry}`. |
| `uid` | `string` | `log_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `log_time` | `timestamp` | When the event happened. Required. |
| `severity` | `LogSeverity` | The severity. Required. One of `trace`, `debug`, `info`, `warn`, `error`, `fatal`. |
| `body` | `string` | The message. Required. |
| `service_name` | `string` | The emitting service, for example `checkout-api`. |
| `attributes` | `map<string, string>` | Typed attributes, at most 64. |
| `trace_id` | `string` | W3C trace id (32 hex). |
| `span_id` | `string` | W3C span id (16 hex). |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`PAGE_TOKEN_MISMATCH`](/docs/api/errors/PAGE_TOKEN_MISMATCH) — A page token was reused with different parameters.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/log_entries:query" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"start_time":{}}'
```

**TypeScript**

```ts
const response = await sylphx.observability.logEntries.query({ parent: 'orgs/acme/projects/shop/envs/production', startTime: {} })
```

**Rust**

```rust
let mut req = sylphx::observability::QueryLogEntriesRequest::default();
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
req.start_time = Some(Default::default());
let response = sx.observability().log_entries().query(req).await?;
```

**CLI**

```bash
sylphx observability log-entries query orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "observability.log_entries.query", "args": {"parent":"orgs/acme/projects/shop/envs/production","start_time":{}} }
```
