Orkestia
Blog
Lumen

Use Lumen

App routes mapped to the Query API — dashboard, logs, groups, traces, metrics, rules

App: lumen.orkestia.dev — same org session as Enable. Every page below is a view over Query API (https://lumen-api.orkestia.dev/api/…) and Lumen MCP.

ingest (201) → searchable on GET /api/logs immediately
             → fingerprint processor → error group + alerts (async)
             → GET /api/error-groups · GET /api/traces/{id}

Routes → endpoints

App pathPrimary API
/GET /api/dashboard/summary, /top-error-groups, /events, /projects (window=15m|1h|6h|24h|7d)
/logsGET /api/logs (project, level, source, environment, release, fingerprint, q, from/to, limit≤500)
/error-groupsGET /api/error-groups (status=open default) + PATCH …/resolve|ignore|reopen|assign|severity
/traces, /spansGET /api/traces/{trace_id}, /spans/stats, /spans/slow (min_duration default 1000ms), /spans/errors
/metricsGET /api/metrics, /aggregate (interval, agg, group_by), /names
/admin/alert-rules/api/alert-rules — new_group | regressed | threshold; channels webhook | slack | email | ticket
/admin/ingest-rules/api/ingest-rules — drop | sample before persist
/admin/fingerprint-rules/api/fingerprint-rules — regex → sha256(fingerprint_key)
/projectsGET /api/projects (names that have ingested)
/billingGET /api/usage, /api/api-keys
/onboardingwaits until GET /api/projects is non-empty

Triage loop

A group is the unit of work, not a single log. Fingerprint algorithm: Send data.

  1. Open the group → 10 latest occurrences (GET /api/error-groups/{id}).
  2. Set severity (PATCH …/severity) before you wire alerts, or every new group pages.
  3. Follow trace_id (UUID on the original event) → span tree. Missing UUIDs: you still have the group, no timeline.
  4. resolve with root cause + solution — next similar hash hits triage memory (GET /api/memory/similar).
  5. ignore for known noise; reopen if it comes back (regressed).
curl -sG "https://lumen-api.orkestia.dev/api/error-groups" \
  --data-urlencode "status=open" \
  --data-urlencode "project=billing-api" \
  -H "Authorization: Bearer $ORKESTIA_TOKEN"

Collector signals in the app

WhatWhere
Pod logsLogs, source=kubernetes
EventsLogs, source=kubernetes-event
UsageMetrics k8s.node.*, k8s.pod.*, k8s.container.*
Collector healthproject lumen-collector: collector.up, collector.pipeline.*

Degraded: collector.up missing >1m, or collector.pipeline.failed / .dropped > 0, even if pods are Running. Install: Collector.

Rules (don't guess)

JSON shapes and CRUD: Query API → Rules. Ingest drops are permanent. Fingerprint rules reshape grouping going forward. channel=ticket emits Kafka lumen.alert.fired.