Skip to main content
POST

Authorizations

Authorization
string
header
required

OAuth 2.0 client credentials. Exchange your client_id and client_secret for an access token scoped to the organisation that provides data access.

Headers

Cula-Organisation-Id
string
required

ID of the organisation the request operates on behalf of (e.g. org_...). Must be an organisation the API client has access to.

Example:

"org_01k83mfmhgchya944v86ryvhpq"

Body

application/json
type
enum<string>
required

Whether the annotation marks a single instant or a time range.

Available options:
instant
occurred_at
string<date-time>
required

The annotated instant as an ISO 8601 timestamp with an explicit UTC offset (Z or ±hh:mm).

Example:

"2026-05-01T12:30:00Z"

text
string
required

Free-text note describing the annotated event that affected machine data. Must not be blank; surrounding whitespace is trimmed.

Maximum string length: 5000
Example:

"Kiln restarted after the morning inspection"

machine_variables
object[]
required

The machine variables to link the annotation to; all must be available at site. May be empty.

Maximum array length: 100
site
object
required

The site the annotation belongs to. Reference it either by its ID or by its external ID, but not both.

external_id
string

A optional custom ID that can be set to an internal ID from your system. This ID must be unique within all objects of the organisation you operate in. You can later use this external ID to reference and query this object. Be aware that you can update this ID later. If you need an immutable ID, use the object ID returned when creating the object.

Required string length: 1 - 100
Pattern: ^[A-Za-z0-9\-_]+$
Example:

"ANNOTATION-EXT-0001"

Response

The created machine data annotation.

id
string
required

Unique identifier of the machine data annotation.

Example:

"mda_01k7v3n9cbp2s0w8qh4xr6fzje"

external_id
string | null
required

The external ID you assigned to this annotation, if any.

Example:

"ANNOTATION-EXT-0001"

type
enum<string>
required

Whether the annotation marks a single instant or a time range.

Available options:
instant
occurred_at
string<date-time>
required

The annotated instant as a UTC ISO 8601 timestamp.

Example:

"2026-05-01T12:30:00.000Z"

site
object
required

The site the annotation belongs to.

created_at
string<date-time>
required

Time the annotation was created.

Example:

"2026-05-06T19:34:00.000Z"

text
string
required

Free-text note describing the annotated event that affected machine data.

Example:

"Kiln restarted after the morning inspection"

machine_variables
object[]
required

The machine variables the annotation is linked to.