> ## Documentation Index
> Fetch the complete documentation index at: https://opensre.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Coralogix

> Connect Coralogix so OpenSRE can query logs

## Overview

OpenSRE queries Coralogix with DataPrime to retrieve logs — correlating log patterns with incidents and identifying root causes.

## Prerequisites

* Coralogix account with DataPrime query access
* Logs Query API key

## Setup

### Option 1: Interactive CLI

```bash theme={null}
opensre integrations setup coralogix
```

You will be prompted for the DataPrime (Logs Query) API key, API URL, and optional application / subsystem filters.

### Option 2: Environment variables

Add to your `.env`:

```bash theme={null}
CORALOGIX_API_KEY=your-logs-api-key
CORALOGIX_API_URL=https://api.coralogix.com   # optional
CORALOGIX_APPLICATION_NAME=my-app             # optional filter
CORALOGIX_SUBSYSTEM_NAME=my-service           # optional filter
```

| Variable                     | Default                     | Description                                |
| ---------------------------- | --------------------------- | ------------------------------------------ |
| `CORALOGIX_API_KEY`          | —                           | **Required.** Coralogix Logs Query API key |
| `CORALOGIX_API_URL`          | `https://api.coralogix.com` | Endpoint for your Coralogix cluster        |
| `CORALOGIX_APPLICATION_NAME` | —                           | Filter queries to this application         |
| `CORALOGIX_SUBSYSTEM_NAME`   | —                           | Filter queries to this subsystem           |

### Option 3: Persistent store

```json theme={null}
{
  "version": 1,
  "integrations": [
    {
      "id": "coralogix-prod",
      "service": "coralogix",
      "status": "active",
      "credentials": {
        "api_key": "your-logs-api-key",
        "base_url": "https://api.coralogix.com",
        "application_name": "my-app",
        "subsystem_name": "my-service"
      }
    }
  ]
}
```

Store credentials use `base_url` (not `CORALOGIX_API_URL`).

### Option 4: Multi-instance

For multiple Coralogix accounts or regions, use [multi-instance](/docs/platform/multi-instance-integrations) with `CORALOGIX_INSTANCES`:

```bash theme={null}
CORALOGIX_INSTANCES='[
  {"name":"prod","tags":{"env":"prod"},"credentials":{"api_key":"...","base_url":"https://api.coralogix.com","application_name":"my-app"}},
  {"name":"eu","tags":{"env":"eu"},"credentials":{"api_key":"...","base_url":"https://api.eu1.coralogix.com"}}
]'
```

When `CORALOGIX_INSTANCES` is set, the single-instance `CORALOGIX_*` variables are ignored.

## Credentials

1. In Coralogix, go to **Data Flow** → **API Keys**
2. Click **+ New API Key**
3. Select **Logs Query** as the key type
4. Copy the key

## Tools

| Tool                   | Use it for                                                     |
| ---------------------- | -------------------------------------------------------------- |
| `query_coralogix_logs` | DataPrime log search for error signatures and incident context |

Arguments the planner commonly supplies:

| Argument             | Default | Description                        |
| -------------------- | ------- | ---------------------------------- |
| `query`              | —       | **Required.** DataPrime query text |
| `time_range_minutes` | `60`    | Lookback window                    |
| `limit`              | `50`    | Row cap                            |
| `application_name`   | —       | Optional application filter        |
| `subsystem_name`     | —       | Optional subsystem filter          |
| `trace_id`           | —       | Optional trace correlation         |

## Verify

```bash theme={null}
opensre integrations verify coralogix
```

Expected output:

```
SERVICE     SOURCE      STATUS   DETAIL
coralogix   local env   passed   Connected to https://api.coralogix.com (application my-app); DataPrime returned 0 row(s)
```

## Troubleshooting

| Symptom                         | Fix                                                                                                  |
| ------------------------------- | ---------------------------------------------------------------------------------------------------- |
| **401 Unauthorized**            | Check the API key and ensure it is a Logs Query key                                                  |
| **Connection timeout**          | Verify `CORALOGIX_API_URL` matches your cluster region                                               |
| **No results**                  | Confirm `CORALOGIX_APPLICATION_NAME` and `CORALOGIX_SUBSYSTEM_NAME` match your data                  |
| **Multiple Coralogix accounts** | Use `CORALOGIX_INSTANCES` — see [Multi-instance integrations](/docs/platform/multi-instance-integrations) |

## Security

* Use a **read-only** Logs Query key — avoid admin or send-data keys.
* Store the API key in `.env` or your secret manager — not in source control.

## Extras

### Cluster endpoints

| Region | API URL                         |
| ------ | ------------------------------- |
| US1    | `https://api.coralogix.com`     |
| EU1    | `https://api.eu1.coralogix.com` |
| EU2    | `https://api.eu2.coralogix.com` |
| AP1    | `https://api.ap1.coralogix.com` |
| AP2    | `https://api.ap2.coralogix.com` |
