Sumo Logic Log Searches Estimated Usage API

Log Search Estimated Usage API. Gets the estimated volume of data that would be scanned for a given log search in the Infrequent data tier, over a particular time range. In the Infrequent Data Tier, you pay per query, based on the amount data scanned. You can use this endpoint to get an estimate of the total data that would be scanned before running a query, and refine your query to scan less data, as necessary. For more information, see [Infrequent data tier](https://help.sumologic.com/?cid=11987).

Operations 4

POST /v1/logSearches/estimatedUsage Gets Estimated Usage Details #
POST /v1/logSearches/estimatedUsageByTier Gets Tier Wise Estimated Usage Details #
POST /v1/logSearches/estimatedUsageByMeteringType Gets Estimated Usage Details Per Metering Type #
POST /v1/logSearches/estimatedUsageByView Gets Estimated Usage Details Per View #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-logsearchesestimatedusage-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-logsearchesestimatedusage-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Log Searches Estimated Usage API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: logSearchesEstimatedUsage
  description: 'Log Search Estimated Usage API.


    Gets the estimated volume of data that would be scanned for a given log search in the Infrequent data tier, over a particular time range. In the Infrequent Data Tier, you pay per query, based on the amount data scanned. You can use this endpoint to get an estimate of the total data that would be scanned before running a query, and refine your query to scan less data, as necessary. For more information, see Infrequent data tier.'
  x-displayName: Log Search Estimated Usage
paths:
  /v1/logSearches/estimatedUsage:
    post:
      tags:
      - logSearchesEstimatedUsage
      summary: Gets Estimated Usage Details
      description: Gets the estimated volume of data that would be scanned for a given log search in the Infrequent data tier.
      operationId: getLogSearchEstimatedUsage
      parameters: []
      requestBody:
        description: The definition of the log search estimated usage.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogSearchEstimatedUsageRequest'
        required: true
      responses:
        '200':
          description: Log search information along with its estimated usage details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearchEstimatedUsageDefinition'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/logSearches/estimatedUsageByTier:
    post:
      tags:
      - logSearchesEstimatedUsage
      summary: Gets Tier Wise Estimated Usage Details
      description: Gets the estimated volume of data that would be scanned for a given log search per data tier.
      operationId: getLogSearchEstimatedUsageByTier
      parameters: []
      requestBody:
        description: The definition of the log search estimated usage.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV2'
        required: true
      responses:
        '200':
          description: Log search information along with its tier wise estimated usage details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearchEstimatedUsageByTierDefinition'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/logSearches/estimatedUsageByMeteringType:
    post:
      tags:
      - logSearchesEstimatedUsage
      summary: Gets Estimated Usage Details Per Metering Type
      description: Gets the estimated volume of data, per metering type, that would be scanned for running a given log search for a given timerange.
      operationId: getLogSearchEstimatedUsageByMeteringType
      parameters: []
      requestBody:
        description: The definition of the log search estimated usage.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV3'
        required: true
      responses:
        '200':
          description: Log search information along with its metering type wise estimated usage details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearchEstimatedUsageByMeteringTypeDefinition'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/logSearches/estimatedUsageByView:
    post:
      tags:
      - logSearchesEstimatedUsage
      summary: Gets Estimated Usage Details Per View
      description: Gets the estimated volume of data, per view, that would be scanned for running a given log search for a given timerange.
      operationId: logSearchesEstimatedUsageByView
      parameters: []
      requestBody:
        description: The definition of the log search estimated usage.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV3'
        required: true
      responses:
        '200':
          description: Log search information along with its view wise estimated usage details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearchEstimatedUsageByViewDefinition'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    LogSearchEstimatedUsageDefinition:
      allOf:
      - $ref: '#/components/schemas/LogSearchEstimatedUsageRequest'
      - required:
        - estimatedUsageDetails
        type: object
        properties:
          estimatedUsageDetails:
            $ref: '#/components/schemas/EstimatedUsageDetails'
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    AutoCompleteValueSyncDefinition:
      required:
      - label
      - value
      type: object
      properties:
        label:
          type: string
          description: The label of the autocomplete value.
        value:
          type: string
          description: The value of the autocomplete value.
    LogSearchEstimatedUsageRequestV2:
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryTimeRangeBaseExceptParsingMode'
      - required:
        - timezone
        type: object
        properties:
          timezone:
            type: string
            description: 'Time zone to get the estimated usage details. Follow the format in the [IANA Time Zone Database](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List).

              '
            example: America/Los_Angeles
    LogSearchEstimatedUsageByMeteringTypeDefinition:
      allOf:
      - $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV3'
      - required:
        - estimatedUsageDetails
        type: object
        properties:
          estimatedUsageDetails:
            type: array
            items:
              $ref: '#/components/schemas/EstimatedUsageDetailsWithMeteringType'
    LogSearchQueryEstimationBaseDefinition:
      required:
      - queryString
      - timeRange
      type: object
      properties:
        queryString:
          maxLength: 15000
          type: string
          description: Log search Query to compute the estimated volume of data scanned.
          example: error {{sourceCategory}}| count by _sourceCategory
        timeRange:
          $ref: '#/components/schemas/ResolvableTimeRange'
        queryParameters:
          maxLength: 50
          type: array
          description: 'Values for search template used in the search query. Learn more about the search templates here : https://help.sumologic.com/docs/search/get-started-with-search/build-search/search-templates/'
          items:
            $ref: '#/components/schemas/LogSearchQueryParameterSyncDefinitionBase'
        intervalTimeType:
          pattern: ^(messageTime|receiptTime|searchableTime)$
          type: string
          description: This parameter defines whether you want to run the search by messageTime, receiptTime, or searchableTime.  By default, the search will run by messageTime. If both runByReceiptTime and intervalTimeType parameters are present then  the preference will be given to the intervalTimeType.
          example: messageTime
          default: messageTime
          x-pattern-message: should be either 'messageTime' or 'receiptTime' or 'searchableTime'
      description: Base definition of the log search with query and timerange (without runByReceiptTime).
    EstimatedUsageDetails:
      type: object
      properties:
        dataScannedInBytes:
          type: integer
          description: Amount of data scanned in bytes, to run the query.
          format: int64
          example: 114086541
    AutoCompleteDefinition:
      required:
      - type
      type: object
      properties:
        type:
          type: string
          description: The autocomplete parameter type.
          example: SKIP_AUTOCOMPLETE
        autoCompleteKey:
          type: string
          description: The autocomplete key to be used to fetch autocomplete values.
          example: Ephemeral-3644138589235809747-1583470806220-parameter
        autoCompleteValues:
          type: array
          description: The array of label-value pairs for autocomplete.
          items:
            $ref: '#/components/schemas/AutoCompleteValueSyncDefinition'
        lookupMetaData:
          $ref: '#/components/schemas/AutoCompleteLookupMetaData'
    EstimatedUsageDetailsPerView:
      required:
      - usageDetails
      - viewName
      type: object
      properties:
        viewName:
          type: string
          description: Name of the view for which usage is estimated.
        usageDetails:
          type: array
          description: The scanning and data retrieval usages to run the query per view.
          items:
            $ref: '#/components/schemas/EstimatedUsageDetailsWithMeteringType'
    LogSearchQueryTimeRangeBaseExceptParsingMode:
      required:
      - queryString
      - timeRange
      type: object
      properties:
        queryString:
          maxLength: 15000
          type: string
          description: Query to perform.
          example: error {{sourceCategory}}| count by _sourceCategory
        timeRange:
          $ref: '#/components/schemas/ResolvableTimeRange'
        runByReceiptTime:
          type: boolean
          description: This has the value `true` if the search is to be run by receipt time and `false` if it is to be run by message time.
          example: false
          default: false
        queryParameters:
          maxLength: 50
          type: array
          description: 'Values for search template used in the search query. Learn more about the search templates here : https://help.sumologic.com/docs/search/get-started-with-search/build-search/search-templates/'
          items:
            $ref: '#/components/schemas/LogSearchQueryParameterSyncDefinitionBase'
        intervalTimeType:
          pattern: ^(messageTime|receiptTime|searchableTime)$
          type: string
          description: This parameter defines whether you want to run the search by messageTime, receiptTime, or searchableTime.  By default, the search will run by messageTime. If both runByReceiptTime and intervalTimeType parameters are present then  the preference will be given to the intervalTimeType.
          example: messageTime
          default: messageTime
          x-pattern-message: should be either 'messageTime' or 'receiptTime' or 'searchableTime'
      description: Definition of the saved log search with query and timerange.
    ResolvableTimeRange:
      required:
      - type
      type: object
      properties:
        type:
          type: string
          description: Type of the time range. Value must be either `CompleteLiteralTimeRange` or `BeginBoundedTimeRange`.
      example:
        type: BeginBoundedTimeRange
        from:
          type: RelativeTimeRangeBoundary
          relativeTime: -15m
      discriminator:
        propertyName: type
    EstimatedUsageDetailsWithMeteringType:
      type: object
      properties:
        meteringType:
          type: string
          description: 'Name of the metering type. Metering type indicates how the data scanned within a particular data tier is actually metered and billed. Supported Values are Continuous, Frequent, Infrequent, ContinuousSecurity and FlexSecurity.

            '
          example: Continuous
        dataScannedInBytes:
          type: integer
          description: Amount of data scanned in bytes, to run the query.
          format: int64
          example: 114086541
        tier:
          type: string
          description: Name of the data tier. Supported Values are Continuous, Frequent, Infrequent and Flex.
          example: Continuous
        scanCreditAccounted:
          type: boolean
          description: 'Whether particular metering type is accounted against a customer''s credit on a per scan basis.  e.g Data belonging to "Flex" and "Infrequent" metering type is accounted for credits on per scan basis. For other metering types, eg. "Continuous" it''s charged upfront during ingestion.

            '
          example: false
      description: Estimated Usage details for the given log search query with the above timerange.
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    LogSearchQueryTimeRangeBase:
      description: Definition of the saved log search with query and timerange.
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryTimeRangeBaseExceptParsingMode'
      - $ref: '#/components/schemas/LogSearchQueryParsingMode'
    LogSearchEstimatedUsageRequestV3:
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryEstimationQueryDefinition'
      - required:
        - timezone
        type: object
        properties:
          timezone:
            type: string
            description: 'Time zone to get the estimated usage details. Follow the format in the [IANA Time Zone Database](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List).

              '
            example: America/Los_Angeles
          emulateSearchContext:
            $ref: '#/components/schemas/EmulateSearchContext'
    EmulateSearchContext:
      type: object
      properties:
        roleIds:
          type: array
          description: List of role IDs to emulate the search context for.
          example:
          - 000000000000000C
          items:
            type: string
        userId:
          type: string
          description: User ID to emulate the search context for.
          example: 000000000000019F
      description: 'Contains keys like "roleIds" with a list of role IDs or "userId" as a string.

        '
    LogSearchEstimatedUsageByViewDefinition:
      allOf:
      - $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV3'
      - required:
        - estimatedUsageDetails
        type: object
        properties:
          estimatedUsageDetails:
            type: array
            items:
              $ref: '#/components/schemas/EstimatedUsageDetailsPerView'
    LogSearchEstimatedUsageByTierDefinition:
      allOf:
      - $ref: '#/components/schemas/LogSearchEstimatedUsageRequestV2'
      - required:
        - estimatedUsageDetails
        type: object
        properties:
          estimatedUsageDetails:
            type: array
            items:
              $ref: '#/components/schemas/EstimatedUsageDetailsWithTier'
    AutoCompleteLookupMetaData:
      type: object
      properties:
        fileName:
          type: string
          description: The lookup file name to use as a source for autocomplete values.
          example: users.csv
        valueColumn:
          type: string
          description: The column from the lookup file to use as the value.
          example: user_id
        labelColumn:
          type: string
          description: The column from the lookup file to use as the label.
          example: user_name
      x-class-extra-annotation: '@com.fasterxml.jackson.annotation.JsonInclude(com.fasterxml.jackson.annotation.JsonInclude.Include.NON_NULL)'
    LogSearchQueryParameterSyncDefinitionBase:
      required:
      - dataType
      - name
      - value
      type: object
      properties:
        autoComplete:
          $ref: '#/components/schemas/AutoCompleteDefinition'
        name:
          maxLength: 50
          pattern: ^[a-zA-Z0-9_]+$
          type: string
          description: The name of the parameter.
          example: sourceCategory
          x-pattern-message: Name must be between 1 and 50 Characters. Can only consist alphanumeric and underscore characters.
        description:
          maxLength: 256
          pattern: ^[a-zA-Z0-9@ \-_\.]+$
          type: string
          description: A description of the parameter.
          example: source category for the string
          x-pattern-message: Description must be between 1 and 256 Characters. Can only consist alphanumeric, @, underscore and dash characters.
        dataType:
          pattern: ^(NUMBER|STRING|ANY|KEYWORD)$
          type: string
          description: "The data type of the parameter. Supported values are:\n  1. `NUMBER`\n  2. `STRING`\n  3. `ANY`\n  4. `KEYWORD`"
          example: STRING
        value:
          maxLength: 256
          type: string
          description: A value for the parameter. Should be compatible with the type set in dataType field.
          example: apache
    LogSearchEstimatedUsageRequest:
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryTimeRangeBase'
      - required:
        - timezone
        type: object
        properties:
          timezone:
            type: string
            description: 'Time zone to get the estimated usage details. Follow the format in the [IANA Time Zone Database](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List).

              '
            example: America/Los_Angeles
    LogSearchQueryParsingMode:
      type: object
      properties:
        parsingMode:
          pattern: ^(AutoParse|Manual)$
          type: string
          description: "Define the parsing mode to scan the JSON format log messages. Possible values are:\n  1. `AutoParse`\n  2. `Manual`\nIn AutoParse mode, the system automatically figures out fields to parse based on the search query. While in the Manual mode, no fields are parsed out automatically. For more information see [Dynamic Parsing](https://help.sumologic.com/?cid=0011)."
          example: AutoParse
          default: Manual
      description: Definition of log search parsing mode
    LogSearchQueryEstimationQueryDefinition:
      description: Definition of the log search with query and timerange.
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryEstimationBaseDefinition'
      - type: object
        properties:
          runByReceiptTime:
            type: boolean
            description: This has the value `true` if the search is to be run by receipt time and `false` if it is to be run by message time.
            example: false
            default: false
    EstimatedUsageDetailsWithTier:
      type: object
      properties:
        tier:
          type: string
          description: Name of the data tier. Supported Values are Continuous, Frequent, Infrequent
          example: Continuous
        dataScannedInBytes:
          type: integer
          description: Amount of data scanned in bytes, to run the query.
          format: int64
          example: 114086541
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement