0 whether or not it found anything, and 2 only when the event log cannot be read.
Text
reproducible until appears on incidents when retention is configured.
JSON
total_matching and truncated are always present, so a shortened list can never be mistaken for a clean one. Events follow the drift event schema.
incidents export
--since writes a JSON array of every incident in the window. See Incident bundles and the bundle format.