hostname to search one core server. Each row's server says which server it came from.datetime-start or datetime-end, it covers the 30 minutes before the request. A longer window returns 400; it is never shortened for you.limit, 1000 by default and 10000 at most, across all servers. When there are more matches, X-NS-Result-Truncated is true.200 with the rows from the ones that did, and X-NS-Fanout-Missing names the ones left out. When none answer, you get 504 if they all ran out of time, otherwise 502.Authorization: Bearer ********************curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/sipflow/events?datetime-start=2026-10-11T08%3A00%3A00-04%3A00&datetime-end=2026-10-11T08%3A30%3A00-04%3A00&hostname=all&callid=0f1e2d3c4b5a69788796a5b4c3d2e1f0%40192.0.2.10&search=sip%3A1001%40example.com&event-type=sip&limit=undefined&sort=undefined' \
--header 'Authorization: Bearer <token>'[
{
"event-index": 918273,
"event-time": "2026-10-11T12:04:11+00:00",
"event-ts": "1791720251527",
"hostname": "core1.example.com",
"event-type": "sip",
"orig-callid": "0f1e2d3c4b5a69788796a5b4c3d2e1f0@192.0.2.10",
"served-callid": "0f1e2d3c4b5a69788796a5b4c3d2e1f0@192.0.2.10",
"event-text": "Received 1024 bytes from 192.0.2.10:5060\nINVITE sip:1001@example.com SIP/2.0\nVia: SIP/2.0/UDP 192.0.2.10:5060;branch=z9hG4bK776asdhds\nFrom: <sip:2125550100@192.0.2.10>;tag=1928301774\nTo: <sip:1001@example.com>\nCall-ID: 0f1e2d3c4b5a69788796a5b4c3d2e1f0@192.0.2.10\nCSeq: 1 INVITE",
"server": "core1.example.com"
}
]