EvoTrail API › Audit trail
Count the audit trail by dimension
How many events match the filters, counted by product, action, actor, actor type, resource type, class and team. Each dimension is counted without its own filter, so the other values stay visible. Actions, actors, resource types and teams list the top 50.
Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read.
Authorization
bearerAuth(evotrail:audit:read)apiKeyHeader(evotrail:audit:read)
Parameters
Query parameters
productarray of ProductOnly these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.actor_idstringWho did it: a user, API key or agent id.actor_typestringactionstringAn exact action, or a prefix ending in*(alert.*). Lower case, digits,_and..resource_typestringresource_idstringteam_idstringEvents on resources of this team.request_idstringEvery event one API request caused.ipstringAn IPv4 or IPv6 address.classstringfromstringYYYY-MM-DD(UTC) or RFC 3339. Default 30 days beforeto.tostringYYYY-MM-DD(inclusive) or RFC 3339. Default now.
Responses
200
Counts per dimension.
dataobject requiredproductsarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
actionsarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
actorsarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
actor_typesarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
resource_typesarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
classesarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
teamsarray of FacetShow Facet properties
valuestringlabelstringA display name, for actors.countinteger
successboolean required
400
A range or filter is not valid (VALIDATION_ERROR); the message names it.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
403
The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
Example request
curl -X GET 'https://evohub.io/api/v1/evotrail/audit/facets' \
-H 'Authorization: Bearer <TOKEN>'