Sumo Logic Log Searches Management API

Log Searches Management API. Whether you are running ad hoc searches during a forensic investigation or running standard searches for health checks, you can save any search to run again later. When you create a search that you would like to reuse, you can save it to the Library. From there you can run it again, share with others, edit the search, or create a Scheduled Search to run at a regularly scheduled time, and set up alerts. The saved search will also include any charts you have created in the Aggregates tab.

Business capability
Observability Management BC-4220.20

Operations 5

GET /v1/logSearches List All Saved Log Searches #
POST /v1/logSearches Save A Log Search #
GET /v1/logSearches/{id} Get The Saved Log Search #
PUT /v1/logSearches/{id} Update The Saved Log Search #
DELETE /v1/logSearches/{id} Delete The Saved Log Search #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-logsearchesmanagement-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-logsearchesmanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Log Searches Management API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: logSearchesManagement
  description: Log Searches Management API.
  x-displayName: Log Searches
paths:
  /v1/logSearches:
    get:
      tags:
      - logSearchesManagement
      summary: List All Saved Log Searches
      description: List all saved log searches viewable by the user.
      operationId: listLogSearches
      parameters:
      - name: limit
        in: query
        description: Limit the number of log searches returned in the response. The number of log searches returned may be less than the `limit`.
        required: false
        schema:
          maximum: 100
          minimum: 1
          type: integer
          format: int32
          default: 50
        example: 50
      - name: token
        in: query
        description: Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. `token` is set to null when no more pages are left.
        required: false
        schema:
          type: string
        example: GDCiRv4vebF3UWFJQ1kySXBOR3Bzh69GR0RyWm9vCtc
      responses:
        '200':
          description: Paginated list of log searches under the Personal folder created by the user.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedLogSearches'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    post:
      tags:
      - logSearchesManagement
      summary: Save A Log Search
      description: Save the log search in the content library.
      operationId: createLogSearch
      parameters: []
      requestBody:
        description: The definition of the saved log search.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SaveLogSearchRequest'
        required: true
      responses:
        '200':
          description: Newly saved log search.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearch'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-create: createLogSearch
  /v1/logSearches/{id}:
    get:
      tags:
      - logSearchesManagement
      summary: Get The Saved Log Search
      description: Get a saved log search from the content library by identifier.
      operationId: getLogSearch
      parameters:
      - name: id
        in: path
        description: Identifier of the saved log search.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Saved log search that was requested.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearch'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-read: getLogSearch
    put:
      tags:
      - logSearchesManagement
      summary: Update The Saved Log Search
      description: Update the saved log search with the specified identifier. Partial update is not supported, you must provide values for all fields.
      operationId: updateLogSearch
      parameters:
      - name: id
        in: path
        description: Identifier of the saved log search.
        required: true
        schema:
          type: string
      requestBody:
        description: An updated saved log search definition.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LogSearchDefinition'
        required: true
      responses:
        '200':
          description: The saved log search that was updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogSearch'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-update: updateLogSearch
    delete:
      tags:
      - logSearchesManagement
      summary: Delete The Saved Log Search
      description: Delete the saved log search from the content library.
      operationId: deleteLogSearch
      parameters:
      - name: id
        in: path
        description: Identifier of the saved log search.
        required: true
        schema:
          type: string
      responses:
        default:
          description: The operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '204':
          description: The saved log search was successfully deleted.
      x-tf-delete: deleteLogSearch
components:
  schemas:
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    AutoCompleteValueSyncDefinition:
      required:
      - label
      - value
      type: object
      properties:
        label:
          type: string
          description: The label of the autocomplete value.
        value:
          type: string
          description: The value of the autocomplete value.
    LogSearchScheduleSyncDefinition:
      required:
      - notification
      - parseableTimeRange
      - scheduleType
      - timeZone
      type: object
      properties:
        cronExpression:
          type: string
          description: Cron-like expression specifying the search's schedule. Field scheduleType must be set to "Custom", otherwise, scheduleType takes precedence over cronExpression.
          example: 0 0/15 * * * ? *
        displayableTimeRange:
          type: string
          description: A human-friendly text describing the query time range. For e.g. "-2h", "last three days", "team default time". This value can not be set via API.
          example: -2h
        parseableTimeRange:
          $ref: '#/components/schemas/ResolvableTimeRange'
        timeZone:
          type: string
          description: Time zone identifier for time specification. Either an abbreviation such as "PST", a full name such as "America/Los_Angeles", or a custom ID such as "GMT-8:00". Note that the support of abbreviations is for JDK 1.1.x compatibility only and full names should be used. The GMT time zone is chosen if the given time zone cannot be identified.
        threshold:
          $ref: '#/components/schemas/LogSearchNotificationThresholdSyncDefinition'
        notification:
          $ref: '#/components/schemas/ScheduleNotificationSyncDefinition'
        scheduleType:
          pattern: ^(RealTime|15Minutes|1Hour|2Hours|4Hours|6Hours|8Hours|12Hours|1Day|1Week|Custom)$
          type: string
          description: "Run schedule of the scheduled search. Set to \"Custom\" to specify the schedule with a CRON expression.Please note that with Custom, 1Day and 1Week schedule types you need to provide the corresponding cron expression to determine when to actually run the search. e.g. Sample Valid Cron for 1Day is \"0 0 16 ? * 2-6 *\". Possible schedule types are:\n  - `RealTime`\n  - `15Minutes`\n  - `1Hour`\n  - `2Hours`\n  - `4Hours`\n  - `6Hours`\n  - `8Hours`\n  - `12Hours`\n  - `1Day`\n  - `1Week`\n  - `Custom`"
        muteErrorEmails:
          type: boolean
          description: If enabled, emails are not sent out in case of errors with the search.
        parameters:
          maxLength: 50
          type: array
          description: 'A list of scheduled search template parameters to be used while executing the query. This is different from the queryParameters field in parent object as this field will be  used for execution as  per the schedule. The parent object field is for search itself, not part of execution.  Learn more about the search templates here :  https://help.sumologic.com/docs/search/get-started-with-search/build-search/search-templates/'
          items:
            $ref: '#/components/schemas/ScheduleSearchParameterSyncDefinition'
    ScheduleSearchParameterSyncDefinition:
      required:
      - name
      - value
      type: object
      properties:
        name:
          maxLength: 60
          type: string
          description: Name of scheduled search parameter.
        value:
          maxLength: 300
          type: string
          description: Value of scheduled search parameter.
    LogSearchNotificationThresholdSyncDefinition:
      required:
      - count
      - operator
      type: object
      properties:
        thresholdType:
          pattern: ^(message|group)$
          type: string
          description: "This property is deprecated. The system will automatically infer the value of this field from the query going forward, so the user-specified value will no longer be honored.\nThreshold type. Possible values are:\n 1. `message`\n 2. `group`\n\nUse `group` as threshold type if the search query is of aggregate type. For non-aggregate queries, set it to `message`."
        operator:
          pattern: ^(eq|gt|ge|lt|le)$
          type: string
          description: "Criterion to be applied when comparing actual result count with expected count. Possible values are:\n 1. `eq`\n 2. `gt`\n 3. `ge`\n 4. `lt`\n 5. `le`"
        count:
          type: integer
          description: Expected result count.
    MetadataModel:
      required:
      - createdAt
      - createdBy
      - modifiedAt
      - modifiedBy
      type: object
      properties:
        createdAt:
          type: string
          description: Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        createdBy:
          type: string
          description: Identifier of the user who created the resource.
          example: 0000000006743FDD
        modifiedAt:
          type: string
          description: Last modification timestamp in UTC.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        modifiedBy:
          type: string
          description: Identifier of the user who last modified the resource.
          example: 0000000006743FE8
    ScheduleNotificationSyncDefinition:
      required:
      - taskType
      type: object
      properties:
        taskType:
          type: string
          description: Delivery channel for notifications.
      discriminator:
        propertyName: taskType
    SaveLogSearchRequest:
      type: object
      description: The definition of the log search to save in the content library.
      allOf:
      - $ref: '#/components/schemas/LogSearchDefinition'
      - required:
        - parentId
        properties:
          parentId:
            type: string
            description: Identifier of a folder where to save the log search.
            example: 000000000000001A
    AutoCompleteDefinition:
      required:
      - type
      type: object
      properties:
        type:
          type: string
          description: The autocomplete parameter type.
          example: SKIP_AUTOCOMPLETE
        autoCompleteKey:
          type: string
          description: The autocomplete key to be used to fetch autocomplete values.
          example: Ephemeral-3644138589235809747-1583470806220-parameter
        autoCompleteValues:
          type: array
          description: The array of label-value pairs for autocomplete.
          items:
            $ref: '#/components/schemas/AutoCompleteValueSyncDefinition'
        lookupMetaData:
          $ref: '#/components/schemas/AutoCompleteLookupMetaData'
    LogSearchQueryTimeRangeBaseExceptParsingMode:
      required:
      - queryString
      - timeRange
      type: object
      properties:
        queryString:
          maxLength: 15000
          type: string
          description: Query to perform.
          example: error {{sourceCategory}}| count by _sourceCategory
        timeRange:
          $ref: '#/components/schemas/ResolvableTimeRange'
        runByReceiptTime:
          type: boolean
          description: This has the value `true` if the search is to be run by receipt time and `false` if it is to be run by message time.
          example: false
          default: false
        queryParameters:
          maxLength: 50
          type: array
          description: 'Values for search template used in the search query. Learn more about the search templates here : https://help.sumologic.com/docs/search/get-started-with-search/build-search/search-templates/'
          items:
            $ref: '#/components/schemas/LogSearchQueryParameterSyncDefinitionBase'
        intervalTimeType:
          pattern: ^(messageTime|receiptTime|searchableTime)$
          type: string
          description: This parameter defines whether you want to run the search by messageTime, receiptTime, or searchableTime.  By default, the search will run by messageTime. If both runByReceiptTime and intervalTimeType parameters are present then  the preference will be given to the intervalTimeType.
          example: messageTime
          default: messageTime
          x-pattern-message: should be either 'messageTime' or 'receiptTime' or 'searchableTime'
      description: Definition of the saved log search with query and timerange.
    ResolvableTimeRange:
      required:
      - type
      type: object
      properties:
        type:
          type: string
          description: Type of the time range. Value must be either `CompleteLiteralTimeRange` or `BeginBoundedTimeRange`.
      example:
        type: BeginBoundedTimeRange
        from:
          type: RelativeTimeRangeBoundary
          relativeTime: -15m
      discriminator:
        propertyName: type
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    PaginatedLogSearches:
      required:
      - logSearches
      type: object
      properties:
        logSearches:
          type: array
          description: List of log searches.
          items:
            $ref: '#/components/schemas/LogSearch'
        warnings:
          type: array
          description: List of warning messages for invalid log search definitions.
          items:
            type: string
            example: 'Invalid saved search: <saved_search_name>. Please validate your saved search.'
        token:
          type: string
          description: Next continuation token. `token` is set to null when no more pages are left.
          example: GDCiRv4vebF3UWFJQ1kySXBOR3Bzh69GR0RyWm9vCtc
    LogSearchDefinition:
      type: object
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryTimeRangeBase'
      - required:
        - name
        properties:
          name:
            maxLength: 255
            minLength: 1
            pattern: ^[a-zA-Z0-9 +%-@.,_()\\]+$
            type: string
            description: Name of the item in the content library.
            example: Short title
          description:
            maxLength: 255
            type: string
            description: Item description in the content library.
            example: Long and detailed description
          schedule:
            $ref: '#/components/schemas/LogSearchScheduleSyncDefinition'
          properties:
            maxLength: 65536
            type: string
            description: 'Aggregate Results Settings and View configurations, Legends settings, and different visualisation settings overrides. Leave this field empty to use the defaults.

              This property contains JSON object encoded as a string.

              '
            example: '{ "key": "value" }'
    LogSearchQueryTimeRangeBase:
      description: Definition of the saved log search with query and timerange.
      allOf:
      - $ref: '#/components/schemas/LogSearchQueryTimeRangeBaseExceptParsingMode'
      - $ref: '#/components/schemas/LogSearchQueryParsingMode'
    LogSearch:
      allOf:
      - $ref: '#/components/schemas/LogSearchDefinition'
      - $ref: '#/components/schemas/MetadataModel'
      - required:
        - id
        type: object
        properties:
          id:
            type: string
            description: Identifier of the saved log search.
            example: 000000000000001A
          parentId:
            type: string
            description: Identifier of the parent element in the content library, such as folder.
            example: 0000000000007D2B
      x-tf-generated-properties: id,parentId,name,description,schedule,queryString,timeRange,runByReceiptTime,queryParameters,parsingMode,intervalTimeType
      x-tf-resource-name: LogSearch
    AutoCompleteLookupMetaData:
      type: object
      properties:
        fileName:
          type: string
          description: The lookup file name to use as a source for autocomplete values.
          example: users.csv
        valueColumn:
          type: string
          description: The column from the lookup file to use as the value.
          example: user_id
        labelColumn:
          type: string
          description: The column from the lookup file to use as the label.
          example: user_name
      x-class-extra-annotation: '@com.fasterxml.jackson.annotation.JsonInclude(com.fasterxml.jackson.annotation.JsonInclude.Include.NON_NULL)'
    LogSearchQueryParameterSyncDefinitionBase:
      required:
      - dataType
      - name
      - value
      type: object
      properties:
        autoComplete:
          $ref: '#/components/schemas/AutoCompleteDefinition'
        name:
          maxLength: 50
          pattern: ^[a-zA-Z0-9_]+$
          type: string
          description: The name of the parameter.
          example: sourceCategory
          x-pattern-message: Name must be between 1 and 50 Characters. Can only consist alphanumeric and underscore characters.
        description:
          maxLength: 256
          pattern: ^[a-zA-Z0-9@ \-_\.]+$
          type: string
          description: A description of the parameter.
          example: source category for the string
          x-pattern-message: Description must be between 1 and 256 Characters. Can only consist alphanumeric, @, underscore and dash characters.
        dataType:
          pattern: ^(NUMBER|STRING|ANY|KEYWORD)$
          type: string
          description: "The data type of the parameter. Supported values are:\n  1. `NUMBER`\n  2. `STRING`\n  3. `ANY`\n  4. `KEYWORD`"
          example: STRING
        value:
          maxLength: 256
          type: string
          description: A value for the parameter. Should be compatible with the type set in dataType field.
          example: apache
    LogSearchQueryParsingMode:
      type: object
      properties:
        parsingMode:
          pattern: ^(AutoParse|Manual)$
          type: string
          description: "Define the parsing mode to scan the JSON format log messages. Possible values are:\n  1. `AutoParse`\n  2. `Manual`\nIn AutoParse mode, the system automatically figures out fields to parse based on the search query. While in the Manual mode, no fields are parsed out automatically. For more information see [Dynamic Parsing](https://help.sumologic.com/?cid=0011)."
          example: AutoParse
          default: Manual
      description: Definition of log search parsing mode
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement