List of Event Logs
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Query Parameters
Filter by an exact match of the audit log ID (indexed)
Filter by a partial match of the audit log ID
Filter by an exact match of the actor ID (indexed)
Filter by a partial match of the actor ID
Filter by an exact match of the actor model class (indexed)
Filter by a partial match of the actor model class
Filter by an exact match of the snake_case actor type (indexed)
Filter by a partial match of the actor type
Filter by an exact match of the event type (indexed)
Filter by a partial match of the event type
Filter by an exact match of the log level (indexed)
Filter by a partial match of the log level
Filter by an exact match of the parent ID (indexed)
Filter by a partial match of the parent ID
Filter by an exact match of the parent type (indexed)
Filter by a partial match of the parent type
Filter by an exact match of the record ID (indexed)
Filter by a partial match of the record ID
Filter by an exact match of the record type (indexed)
Filter by a partial match of the record type
Filter by an exact match of the related ID (indexed)
Filter by a partial match of the related ID
Filter by an exact match of the related type (indexed)
Filter by a partial match of the related type
Filter by an exact match of the subject ID (indexed)
Filter by a partial match of the subject ID
Filter by an exact match of the subject type (indexed)
Filter by a partial match of the subject type
Filter by an exact match of the old attribute value (encrypted)
Filter by a partial match of the old attribute value (encrypted)
Filter by an exact match of the new attribute value (encrypted)
Filter by a partial match of the new attribute value (encrypted)
Filter by an exact match of the record provider ID (encrypted)
Filter by a partial match of the record provider ID (encrypted)
Search metadata for any partial string match (encrypted)
Filter by an exact match of the actor session ID
Filter by a partial match of the actor session ID
Filter by an exact match of the attribute key
Filter by a partial match of the attribute key
Filter by an exact match of the count records
Filter by an exact match of the job batch
Filter by a partial match of the job batch
Filter by an exact match of the job ID
Filter by a partial match of the job ID
Filter by an exact match of the job platform
Filter by a partial match of the job platform
Filter by an exact match of the job pipeline ID
Filter by a partial match of the job pipeline ID
Filter by an exact match of the job transaction ID
Filter by a partial match of the job transaction ID
Filter by an exact match of the message
Filter by a partial match of the message
Filter by an exact match of the method
Filter by a partial match of the method
Filter by logs that occurred before a specific date (indexed)
Filter by logs that occurred after a specific date (indexed)
Filter by logs created before a specific date (indexed)
Filter by logs created after a specific date (indexed)
Filter by logs deleted before a specific date (trashed only)
Filter by logs deleted after a specific date (trashed only)
Filter by trashed status (with, only, or empty for none)
Response
"wslog_01hq8xyzabc123def456ghi789"
The ID of the workspace tenant this log is attributed to
"hqwks_01hq8xyzabc123def456ghi789"
The fully-qualified model class name of the tenant
"App\\Models\\FederationWorkspace"
The timestamp when the audit log was created
"2024-01-15T10:30:00Z"
The timestamp when the event occurred
"2024-01-15T10:30:00Z"
The industry standard log severity level
"info"
The type of event (e.g., namespace.resource.child_resource?.action.result?.context?)
"policy.user.create.success"
The method or action that triggered the log entry and line number
"\\App\\Actions\\V1\\PolicyUser\\CreatePolicyUser::handle:33"
The log message describing the action
"Policy User Qualified and Added to Manifest"
Error messages associated with the action
Additional metadata associated with the log entry. This provides context that the ID and type may not cover
The fully-qualified model class name of the actor who performed the action
"App\\Models\\WorkspaceUser"
The snake_case type of actor (e.g., workspace_user, workspace_service, workspace_integration)
"workspace_user"
The ID of the actor who performed the action
"wsusr_01hq8xyzabc123def456ghi789"
The name of the actor who performed the action
"Dade Murphy"
The alphadash handle of the actor that performed the action
"dmurphy"
The session ID of the actor
"A1b2c3D4e5f6G7h8I9J0k1l2m3n4o5p6q7r8s9t0"
The source of the actor (system, cli, api, web)
"web"
The snake_case or camelCase key in the database table (or API response) that was modified. This provides a before and after snapshot for database column or array values that are changed
"name"
The old database or API response value of the attribute before modification. Null for created records
"IT Team"
The new value of the attribute after modification
"Security Team"
The type of the parent resource
"google_workspace_group"
The ID of the parent resource
"gwgrp_01hq8xyzabc123def456ghi789"
The type of the record being acted upon
"policy_user"
The ID of the record being acted upon
"pousr_01hq8xyzabc123def456ghi789"
The Integration Provider API identifier of the record (if applicable)
"a1b2c3d4-e5f6-a7b8-c9d0-e1f2g3h4i5j6"
The ID of the related resource
"porul_01hq8xyzabc123def456ghi789"
The type of the related resource
"policy_rule"
The ID of the subject related to the action
"drusr_01hq8xyzabc123def456ghi789"
The type of the subject. The record type is the action that was performed. The subject is on behalf of who
"directory_user"
"workspace_service"
"workspace_user"
The count of records affected by this action (if applicable for bulk operations)
5
The batch identifier for grouped job operations
"xxxxx_01hq8xyzabc123def456ghi789"
The job ID associated with this log entry
"xxxxx_01hq8xyzabc123def456ghi789"
The platform where the job was executed
The pipeline ID for CI/CD operations
"123456789"
The timestamp when the job was executed
"2024-01-15T10:30:00Z"
The transaction ID for the job
"xxxxx_01hq8xyzabc123def456ghi789"