Skip to main content
A reader, not a gate: exits 0 whether or not it found anything, and 2 only when the event log cannot be read.

Text

Newest first by last seen. reproducible until appears on incidents when retention is configured.

JSON

total_matching and truncated are always present, so a shortened list can never be mistaken for a clean one. Events follow the drift event schema.

incidents export

Writes a self-contained bundle to stdout: the event, the already-redacted recording and the contract version. No salt, no token, no configuration. One fingerprint writes one bundle; --since writes a JSON array of every incident in the window. See Incident bundles and the bundle format.