Skip to main content
GET
List of Event Logs

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

filter[updated_before]
string
filter[updated_after]
string
filter
string
page
string
sort
string
filter[id]
string

Filter by an exact match of the audit log ID (indexed)

Filter by a partial match of the audit log ID

filter[actor_id]
string

Filter by an exact match of the actor ID (indexed)

Filter by a partial match of the actor ID

filter[actor_model]
string

Filter by an exact match of the actor model class (indexed)

Filter by a partial match of the actor model class

filter[actor_type]
string

Filter by an exact match of the snake_case actor type (indexed)

Filter by a partial match of the actor type

filter[event_type]
string

Filter by an exact match of the event type (indexed)

Filter by a partial match of the event type

filter[level]
string

Filter by an exact match of the log level (indexed)

Filter by a partial match of the log level

filter[parent_id]
string

Filter by an exact match of the parent ID (indexed)

Filter by a partial match of the parent ID

filter[parent_type]
string

Filter by an exact match of the parent type (indexed)

Filter by a partial match of the parent type

filter[record_id]
string

Filter by an exact match of the record ID (indexed)

Filter by a partial match of the record ID

filter[record_type]
string

Filter by an exact match of the record type (indexed)

Filter by a partial match of the record type

Filter by an exact match of the related ID (indexed)

Filter by a partial match of the related ID

Filter by an exact match of the related type (indexed)

Filter by a partial match of the related type

filter[subject_id]
string

Filter by an exact match of the subject ID (indexed)

Filter by a partial match of the subject ID

filter[subject_type]
string

Filter by an exact match of the subject type (indexed)

Filter by a partial match of the subject type

filter[attribute_value_old]
string

Filter by an exact match of the old attribute value (encrypted)

Filter by a partial match of the old attribute value (encrypted)

filter[attribute_value_new]
string

Filter by an exact match of the new attribute value (encrypted)

Filter by a partial match of the new attribute value (encrypted)

filter[record_provider_id]
string

Filter by an exact match of the record provider ID (encrypted)

Filter by a partial match of the record provider ID (encrypted)

Search metadata for any partial string match (encrypted)

filter[actor_session_id]
string

Filter by an exact match of the actor session ID

Filter by a partial match of the actor session ID

filter[attribute_key]
string

Filter by an exact match of the attribute key

Filter by a partial match of the attribute key

filter[count_records]
string

Filter by an exact match of the count records

filter[job_batch]
string

Filter by an exact match of the job batch

Filter by a partial match of the job batch

filter[job_id]
string

Filter by an exact match of the job ID

Filter by a partial match of the job ID

filter[job_platform]
string

Filter by an exact match of the job platform

Filter by a partial match of the job platform

filter[job_pipeline_id]
string

Filter by an exact match of the job pipeline ID

Filter by a partial match of the job pipeline ID

filter[job_transaction_id]
string

Filter by an exact match of the job transaction ID

Filter by a partial match of the job transaction ID

filter[message]
string

Filter by an exact match of the message

Filter by a partial match of the message

filter[method]
string

Filter by an exact match of the method

Filter by a partial match of the method

filter[occurred_before]
string

Filter by logs that occurred before a specific date (indexed)

filter[occurred_after]
string

Filter by logs that occurred after a specific date (indexed)

filter[created_before]
string

Filter by logs created before a specific date (indexed)

filter[created_after]
string

Filter by logs created after a specific date (indexed)

filter[deleted_before]
string

Filter by logs deleted before a specific date (trashed only)

filter[deleted_after]
string

Filter by logs deleted after a specific date (trashed only)

filter[trashed]
string

Filter by trashed status (with, only, or empty for none)

Response

id
string
required
Example:

"wslog_01hq8xyzabc123def456ghi789"

tenant_id
string | null
required

The ID of the workspace tenant this log is attributed to

Example:

"hqwks_01hq8xyzabc123def456ghi789"

tenant_model
string | null
required

The fully-qualified model class name of the tenant

Example:

"App\\Models\\FederationWorkspace"

created_at
string<date-time>
required

The timestamp when the audit log was created

Example:

"2024-01-15T10:30:00Z"

occurred_at
string<date-time> | null
required

The timestamp when the event occurred

Example:

"2024-01-15T10:30:00Z"

level
string | null
required

The industry standard log severity level

Example:

"info"

event_type
string | null
required

The type of event (e.g., namespace.resource.child_resource?.action.result?.context?)

Example:

"policy.user.create.success"

method
string | null
required

The method or action that triggered the log entry and line number

Example:

"\\App\\Actions\\V1\\PolicyUser\\CreatePolicyUser::handle:33"

message
string | null
required

The log message describing the action

Example:

"Policy User Qualified and Added to Manifest"

errors
string[] | null
required

Error messages associated with the action

Example:
metadata
string[] | null
required

Additional metadata associated with the log entry. This provides context that the ID and type may not cover

Example:
actor_model
string | null
required

The fully-qualified model class name of the actor who performed the action

Example:

"App\\Models\\WorkspaceUser"

actor_type
string | null
required

The snake_case type of actor (e.g., workspace_user, workspace_service, workspace_integration)

Example:

"workspace_user"

actor_id
string | null
required

The ID of the actor who performed the action

Example:

"wsusr_01hq8xyzabc123def456ghi789"

actor_name
string | null
required

The name of the actor who performed the action

Example:

"Dade Murphy"

actor_handle
string | null
required

The alphadash handle of the actor that performed the action

Example:

"dmurphy"

actor_session_id
string | null
required

The session ID of the actor

Example:

"A1b2c3D4e5f6G7h8I9J0k1l2m3n4o5p6q7r8s9t0"

actor_source
string | null
required

The source of the actor (system, cli, api, web)

Example:

"web"

attribute_key
string | null
required

The snake_case or camelCase key in the database table (or API response) that was modified. This provides a before and after snapshot for database column or array values that are changed

Example:

"name"

attribute_value_old
string | null
required

The old database or API response value of the attribute before modification. Null for created records

Example:

"IT Team"

attribute_value_new
string | null
required

The new value of the attribute after modification

Example:

"Security Team"

parent_type
string | null
required

The type of the parent resource

Example:

"google_workspace_group"

parent_id
string | null
required

The ID of the parent resource

Example:

"gwgrp_01hq8xyzabc123def456ghi789"

record_type
string | null
required

The type of the record being acted upon

Example:

"policy_user"

record_id
string | null
required

The ID of the record being acted upon

Example:

"pousr_01hq8xyzabc123def456ghi789"

record_provider_id
string | null
required

The Integration Provider API identifier of the record (if applicable)

Example:

"a1b2c3d4-e5f6-a7b8-c9d0-e1f2g3h4i5j6"

The ID of the related resource

Example:

"porul_01hq8xyzabc123def456ghi789"

The type of the related resource

Example:

"policy_rule"

subject_id
string | null
required

The ID of the subject related to the action

Example:

"drusr_01hq8xyzabc123def456ghi789"

subject_type
string | null
required

The type of the subject. The record type is the action that was performed. The subject is on behalf of who

Examples:

"directory_user"

"workspace_service"

"workspace_user"

count_records
integer | null
required

The count of records affected by this action (if applicable for bulk operations)

Example:

5

job_batch
string | null
required

The batch identifier for grouped job operations

Example:

"xxxxx_01hq8xyzabc123def456ghi789"

job_id
string | null
required

The job ID associated with this log entry

Example:

"xxxxx_01hq8xyzabc123def456ghi789"

job_platform
string | null
required

The platform where the job was executed

job_pipeline_id
string | null
required

The pipeline ID for CI/CD operations

Example:

"123456789"

job_timestamp
string<date-time> | null
required

The timestamp when the job was executed

Example:

"2024-01-15T10:30:00Z"

job_transaction_id
string | null
required

The transaction ID for the job

Example:

"xxxxx_01hq8xyzabc123def456ghi789"