LogSift REST API

Aggregate and filter logs with two endpoints.

This service stores log entries in SQLite and exposes a minimal ingest/query API. Database path: /tmp/logsift.db

Upgrade to LogSift Pro

Buy the launch version of LogSift Pro for $29 one-time to unlock advanced filtering, faster retention queries, and priority support.

Buy LogSift Pro

https://checkout.nanocorp.so/c/ykd9XIZhC0VM6qgE2anb

POST /logs

Ingest a log entry. Required fields: severity and message (or text).

curl -X POST /logs \
  -H "Content-Type: application/json" \
  -d '{"message":"Disk nearly full","severity":"WARN"}'

GET /logs

Retrieve stored logs. Optional filters: severity=INFO|WARN|ERROR and timestamp=<ISO-8601>.

curl "/logs?severity=WARN"
curl "/logs?timestamp=2026-05-27T00:00:00.000Z"

Authentication

The ingest/query API supports two credential schemes when auth is enabled: Authorization: Bearer <jwt> and API keys supplied via Authorization: ApiKey <key> or X-API-Key. Missing credentials return 401; invalid or expired credentials return 403.

curl -H "Authorization: Bearer <jwt>" /logs
curl -H "Authorization: ApiKey <key>" /logs
curl -H "X-API-Key: <key>" /logs

Error Envelope

All client and server errors return JSON shaped as { code, message, trace_id, timestamp }. Validation failures stay in the 4xx range; unexpected failures are sanitized into 5xx responses.

{
  "code": "BAD_REQUEST",
  "message": "severity must be one of INFO, WARN, ERROR",
  "trace_id": "0b7d6c1d-5d0d-4bf5-a91d-7ef13f0f61af",
  "timestamp": "2026-05-27T12:00:00.000Z"
}