OpenObserve Logs API

Logs data ingestion operations

OpenAPI Specification

openobserve-logs-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: openobserve Actions Logs API
  description: OpenObserve API documents [https://openobserve.ai/docs/](https://openobserve.ai/docs/)
  contact:
    name: OpenObserve
    url: https://openobserve.ai/
    email: hello@zinclabs.io
  license:
    name: AGPL-3.0
    identifier: AGPL-3.0
  version: 0.90.0
tags:
- name: Logs
  description: Logs data ingestion operations
paths:
  /api/{org_id}/_bulk:
    post:
      tags:
      - Logs
      summary: Bulk ingest logs (Elasticsearch compatible)
      description: Ingests multiple log records in bulk using Elasticsearch-compatible NDJSON format. Each line contains either an index/create action followed by the document data. This endpoint provides high-throughput ingestion for applications migrating from or integrating with Elasticsearch.
      operationId: LogsIngestionBulk
      parameters:
      - name: org_id
        in: path
        description: Organization name
        required: true
        schema:
          type: string
      requestBody:
        description: Ingest data (ndjson)
        content:
          application/json:
            schema:
              type: string
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
              example:
                took: 2
                errors: true
                items:
                - index:
                    _index: olympics
                    _id: 1
                    status: 200
                    error:
                      type: Too old data, only last 5 hours data can be ingested. Data discarded.
                      reason: Too old data, only last 5 hours data can be ingested. Data discarded.
                      index_uuid: '1'
                      shard: '1'
                      index: olympics
                    original_record:
                      athlete: CHASAPIS, Spiridon
                      city: BER
                      country: USA
                      discipline: Swimming
                      event: 100M Freestyle For Sailors
                      gender: Men
                      medal: Silver
                      onemore: 1
                      season: summer
                      sport: Aquatics
                      year: 1986
        '500':
          description: Failure
          content:
            application/json:
              schema:
                default: null
      security:
      - Authorization: []
      x-o2-mcp:
        enabled: false
  /api/{org_id}/loki/api/v1/push:
    post:
      tags:
      - Logs
      summary: Ingest logs via Loki API
      description: Ingests log data using Grafana Loki-compatible API format. Supports both JSON and Protocol Buffers content types with optional compression (gzip for JSON, snappy for Protobuf). Stream names are extracted from the 'stream_name' label in stream metadata. Provides seamless migration path from Loki deployments to OpenObserve while maintaining API compatibility.
      operationId: LogsIngestionLoki
      parameters:
      - name: org_id
        in: path
        description: Organization name
        required: true
        schema:
          type: string
      requestBody:
        description: Loki-compatible log push data in JSON format. Stream names are extracted from 'stream_name' label in the stream labels. Also supports Protobuf format (application/x-protobuf) with optional compression (gzip for JSON, snappy for Protobuf)
        content:
          application/json:
            schema:
              type: object
              description: 'Internal Loki JSON types for native Loki push API format

                Loki push request - matches native JSON format exactly'
              required:
              - streams
              properties:
                streams:
                  type: array
                  items:
                    $ref: '#/components/schemas/LokiStream'
                  description: Array of log streams, each containing labels and log entries
            example:
              streams:
              - stream:
                  stream_name: application_logs
                  service: api
                  environment: production
                values:
                - - '1609459200000000000'
                  - API request processed successfully
                - - '1609459201000000000'
                  - Database connection established
                  - trace_id: abc123
                    span_id: def456
        required: true
      responses:
        '204':
          description: Success - logs ingested successfully
        '400':
          description: 'Bad Request - Possible causes: empty stream data, invalid labels format (e.g., empty labels), invalid timestamp format (e.g., non-numeric timestamp), unsupported content type (only application/json and application/x-protobuf supported), unsupported content encoding (only gzip for JSON and snappy for Protobuf), protobuf decode errors, JSON parsing errors, or compression/decompression failures'
          content:
            text/plain:
              schema:
                type: string
        '500':
          description: Internal Server Error - Server error during log processing
          content:
            text/plain:
              schema:
                type: string
      security:
      - Authorization: []
      x-o2-mcp:
        enabled: false
  /api/{org_id}/{stream_name}/_json:
    post:
      tags:
      - Logs
      summary: Ingest logs via JSON array
      description: Ingests log data using a JSON array format where multiple log records are submitted as an array in a single request. This is ideal for batch processing scenarios where applications collect multiple log entries before sending them together for improved efficiency.
      operationId: LogsIngestionJson
      parameters:
      - name: org_id
        in: path
        description: Organization name
        required: true
        schema:
          type: string
      - name: stream_name
        in: path
        description: Stream name
        required: true
        schema:
          type: string
      requestBody:
        description: Ingest data (json array)
        content:
          application/json:
            schema:
              type: string
            example:
            - Year: 1896
              City: Athens
              Sport: Aquatics
              Discipline: Swimming
              Athlete: Alfred
              Country: HUN
            - Year: 1896
              City: Athens
              Sport: Aquatics
              Discipline: Swimming
              Athlete: HERSCHMANN
              Country: CHN
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
              example:
                code: 200
                status:
                - name: olympics
                  successful: 3
                  failed: 0
        '500':
          description: Failure
          content:
            application/json:
              schema:
                default: null
      security:
      - Authorization: []
      x-o2-mcp:
        description: Ingest logs via JSON array
        category: logs
  /api/{org_id}/{stream_name}/_multi:
    post:
      tags:
      - Logs
      summary: Ingest logs via multi-line JSON
      description: Ingests log data using multi-line JSON format where each line contains a separate JSON object representing a log record. This format is efficient for streaming applications and tools that generate logs in newline-delimited JSON format.
      operationId: LogsIngestionMulti
      parameters:
      - name: org_id
        in: path
        description: Organization name
        required: true
        schema:
          type: string
      - name: stream_name
        in: path
        description: Stream name
        required: true
        schema:
          type: string
      requestBody:
        description: Ingest data (multiple line json)
        content:
          application/json:
            schema:
              type: string
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
              example:
                code: 200
                status:
                - name: olympics
                  successful: 3
                  failed: 0
        '500':
          description: Failure
          content:
            application/json:
              schema:
                default: null
      security:
      - Authorization: []
      x-o2-mcp:
        enabled: false
components:
  schemas:
    LokiStream:
      type: object
      description: Loki stream containing labels and log entries
      required:
      - stream
      - values
      properties:
        stream:
          type: object
          description: 'Stream labels as key-value pairs (e.g., {"service": "api", "stream_name": "logs"})'
          additionalProperties:
            type: string
          propertyNames:
            type: string
        values:
          type: array
          items:
            $ref: '#/components/schemas/LokiEntry'
          description: Array of log entries, each containing timestamp, message, and optional structured metadata
    LokiEntry:
      type: object
      description: Loki log entry containing timestamp, message, and optional metadata
      required:
      - timestamp
      - line
      properties:
        line:
          type: string
          description: Log message content
        structured_metadata:
          type:
          - object
          - 'null'
          description: Optional structured metadata as key-value pairs
          additionalProperties:
            type: string
          propertyNames:
            type: string
        timestamp:
          type: string
          description: Timestamp as nanosecond unix epoch string (e.g., "1609459200000000000")
  securitySchemes:
    Authorization:
      type: apiKey
      in: header
      name: Authorization
    BasicAuth:
      type: http
      scheme: basic