RawLogResult contains a single result match that is one of unparsed raw log, telemetry event, or entity context event. Along with that this contains summary, id, logType of the log that generated the result.
| JSON representation |
|---|
{ "summary": string, "id": string, "logType": { object ( |
| Fields | |
|---|---|
summary |
If the result is unparsed log, summary will be a snippet for unparsed raw log. If the result is a telemetry event or a context event, it will be a description of the event. |
id |
Id for raw log / entity / event result. A base64-encoded string. |
logType |
Log type of the result. |
Union field
|
|
event |
Normalized UDM event from the raw log that matched search query. |
entity |
Normalized entity context event from the raw log that matched search query. |
snippet |
Raw log snippet in case of unparsed log. |
RawLogSnippet
RawLog contains raw log id, ingestion time, and a snippet of the log.
| JSON representation |
|---|
{ "id": string, "snippet": string, "ingestionTime": string } |
| Fields | |
|---|---|
id |
ID of the raw log. A base64-encoded string. |
snippet |
Snippet of the raw log. |
ingestionTime |
Ingestion time of the raw log. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |