EvoTrail API › Audit trail
Export the audit trail as CSV
Every event the filters match, newest first, streamed as CSV with the columns
occurred_at, product, action, class, actor_type, actor_id, actor_name, resource_type, resource_id, resource_name, team_id, request_id, ip, user_agent, event_id, id. More than 100,000 matching events is refused: narrow
the range or filters. A cell that starts with =, +, -, @, a tab or a
carriage return is prefixed with '. The export is itself recorded in the
trail as evotrail audit.exported.
Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read.
Authorization
bearerAuth(evotrail:audit:read)apiKeyHeader(evotrail:audit:read)
Parameters
Query parameters
productarray of ProductOnly these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.actor_idstringWho did it: a user, API key or agent id.actor_typestringactionstringAn exact action, or a prefix ending in*(alert.*). Lower case, digits,_and..resource_typestringresource_idstringteam_idstringEvents on resources of this team.request_idstringEvery event one API request caused.ipstringAn IPv4 or IPv6 address.classstringfromstringYYYY-MM-DD(UTC) or RFC 3339. Default 30 days beforeto.tostringYYYY-MM-DD(inclusive) or RFC 3339. Default now.
Responses
200
The CSV, as an attachment named evotrail-audit-<from>-<to>.csv.
400
A filter is not valid (VALIDATION_ERROR), or more than 100,000 events match (EXPORT_TOO_LARGE).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
403
The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
Example request
curl -X GET 'https://evohub.io/api/v1/evotrail/audit/export.csv' \
-H 'Authorization: Bearer <TOKEN>'