---
title: "Search, filter and group Event Logs for a Shield Zone"
method: POST
path: "/shield/event-logs/{shieldZoneId}/search"
tags: ["Event Logs"]
---

# Search, filter and group Event Logs for a Shield Zone

`POST /shield/event-logs/{shieldZoneId}/search`

## Path parameters

- `shieldZoneId` integer, required — The ID of the Shield Zone.

## Request body

- EventLogsSearchRequest — Request body for searching a Shield Zone's Event Logs within a time window.
  - `from` integer — Window start as Unix time in milliseconds (UTC). Required.
  - `to` integer — Window end as Unix time in milliseconds (UTC). Required; must be after BunnyNet.Shield.Api.Entities.Waf.WafLogging.EventLogsSearchRequest.from and within the last 72 hours.
  - `query` string, nullable — Optional free-text search across IP, ruleId, URL, User-Agent and rule name.
  - `filters` EventLogsFilter[], nullable — Optional filters, combined with AND. Repeated values within one filter combine with OR.
    - `field` string, nullable — Dimension to filter on: feature, ruleId, ip, ja4, ua, url, asn, country or action.
    - `op` string, nullable — Operator: eq, in, contains, cidr (ip only, IPv4/IPv6) or wildcard ('*' matches any run).
    - `value` string[], nullable — Value(s) for the filter; multiple values are OR-combined.
  - `groupBy` string[], nullable — Optional ordered dimensions to group by, e.g. ["ip","ja4"]. Omit for flat rows. Allowed: feature, ruleId, ip, ja4, ua, url, asn, country, action.
  - `page` integer — Zero-based page index.
  - `pageSize` integer — Page size; clamped to 1–500 (defaults to 50 when unset).

## Response `200`

OK

- EventLogsSearchResponse — Result of an Event Logs search. Exactly one of BunnyNet.Shield.Api.Entities.Waf.WafLogging.EventLogsSearchResponse.rows or BunnyNet.Shield.Api.Entities.Waf.WafLogging.EventLogsSearchResponse.groups is populated.
  - `rows` EventRow[], nullable — Flat event rows (populated when the request had no groupBy).
    - `logId` string, nullable — Unique event identifier.
    - `timestamp` integer — Event time as Unix time in milliseconds (UTC).
    - `log` unknown
    - `fields` object, nullable — Resolved dimension values for the event (e.g. ip, ruleId, url, ja4).
  - `groups` EventGroup[], nullable — Aggregated groups (populated when the request had a groupBy).
    - `key` object, nullable — The group key: each requested groupBy dimension mapped to its value.
    - `count` integer — Number of events in the group.
    - `firstSeen` integer — Earliest event time in the group (Unix time in milliseconds, UTC).
    - `lastSeen` integer — Most recent event time in the group (Unix time in milliseconds, UTC).
    - `context` object, nullable — Context aggregates for the group: country, asn, per-action counts (blocked/challenged/logged), and features/ruleIds touched. Counts are numbers; features/ruleIds are comma-joined strings.
  - `total` integer — Total flat rows, or total distinct groups when grouped.
  - `totalPages` integer — Total number of pages for the current page size.
  - `page` integer — Zero-based index of the returned page.
  - `errorResponse` GenericRequestResponse — Generic response object containing status information for API operations.
    - `statusCode` 100 | 101 | 102 | 103 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 226 | 300 | 301 | 302 | 303 | 304 | 305 | 306 | 307 | 308 | 400 | 401 | 402 | 403 | 404 | 405 | 406 | 407 | 408 | 409 | 410 | 411 | 412 | 413 | 414 | 415 | 416 | 417 | 421 | 422 | 423 | 424 | 426 | 428 | 429 | 431 | 451 | 500 | 501 | 502 | 503 | 504 | 505 | 506 | 507 | 508 | 510 | 511 — 100 = Continue 101 = SwitchingProtocols 102 = Processing 103 = EarlyHints 200 = OK 201 = Created 202 = Accepted 203 = NonAuthoritativeInformation 204 = NoContent 205 = ResetContent 206 = PartialContent 207 = MultiStatus 208 = AlreadyReported 226 = IMUsed 300 = MultipleChoices 300 = Ambiguous 301 = MovedPermanently 301 = Moved 302 = Found 302 = Redirect 303 = SeeOther 303 = RedirectMethod 304 = NotModified 305 = UseProxy 306 = Unused 307 = TemporaryRedirect 307 = RedirectKeepVerb 308 = PermanentRedirect 400 = BadRequest 401 = Unauthorized 402 = PaymentRequired 403 = Forbidden 404 = NotFound 405 = MethodNotAllowed 406 = NotAcceptable 407 = ProxyAuthenticationRequired 408 = RequestTimeout 409 = Conflict 410 = Gone 411 = LengthRequired 412 = PreconditionFailed 413 = RequestEntityTooLarge 414 = RequestUriTooLong 415 = UnsupportedMediaType 416 = RequestedRangeNotSatisfiable 417 = ExpectationFailed 421 = MisdirectedRequest 422 = UnprocessableEntity 422 = UnprocessableContent 423 = Locked 424 = FailedDependency 426 = UpgradeRequired 428 = PreconditionRequired 429 = TooManyRequests 431 = RequestHeaderFieldsTooLarge 451 = UnavailableForLegalReasons 500 = InternalServerError 501 = NotImplemented 502 = BadGateway 503 = ServiceUnavailable 504 = GatewayTimeout 505 = HttpVersionNotSupported 506 = VariantAlsoNegotiates 507 = InsufficientStorage 508 = LoopDetected 510 = NotExtended 511 = NetworkAuthenticationRequired
    - `success` boolean — Indicates whether the operation was successful.
    - `message` string, nullable — Human-readable message describing the result of the operation.
    - `errorKey` string, nullable — Unique error key for programmatic error handling, if applicable.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `500` — Internal Server Error

---

[API](https://skmtc.net/bunny/apis/bunny-net-cdn-logging.md) · [All operations](https://skmtc.net/bunny/apis/bunny-net-cdn-logging/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/bunny/bunny-net-cdn-logging/revisions/9e622620664b/schema)
