EvoTrail API › Audit trail
Search the audit trail
Events from every product the key may read, newest first. Filters combine.
Paged by cursor: pass next_cursor back as cursor while has_more is true.
The list rows leave out before, after and metadata; read one event for
those.
Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read; Catalog's rows are for owners and administrators only.
Authorization
bearerAuth(evotrail:audit:read)apiKeyHeader(evotrail:audit:read)
Parameters
Query parameters
productarray of ProductOnly these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.actor_idstringWho did it: a user, API key or agent id.actor_typestringactionstringAn exact action, or a prefix ending in*(alert.*). Lower case, digits,_and..resource_typestringresource_idstringteam_idstringEvents on resources of this team.request_idstringEvery event one API request caused.ipstringAn IPv4 or IPv6 address.classstringfromstringYYYY-MM-DD(UTC) or RFC 3339. Default 30 days beforeto.tostringYYYY-MM-DD(inclusive) or RFC 3339. Default now.limitintegercursorstringnext_cursorfrom the previous page.
Responses
200
A page of events.
dataobject requireditemsarray of AuditEventShow AuditEvent properties
idstring (uuid) requiredevent_idstring requiredThe producing product's own id for the event.sourcestring requiredThe service that reported it.productProduct requiredteam_idstring | nullThe team the resource belongs to.actorobject requiredtypestringidstring | nullnamestring | nullteamsarray of string | null
actionstring required<resource>.<verb>, for examplealert.acknowledgedormember.role_changed.classstring requiredauditis a change to configuration or access (kept 365 days);activityis day-to-day work (kept 90 days).resourceobject requiredtypestring | nullidstring | nullnamestring | null
request_idstring | nullipstring | nullKept 90 days.user_agentstring | nullKept 90 days.occurred_atstring (date-time) requiredhas_detailsboolean requiredWhetherbefore,afterormetadataexist; read the single event to get them.beforeanyThe resource before the change (single-event read only). Secrets are masked by the producer.afteranyThe resource after the change (single-event read only).metadataanyAnything else the product recorded (single-event read only).
next_cursorstringAbsent on the last page.has_morebooleanproductsarray of ProductThe products searched.fromstring (date-time)tostring (date-time)
successboolean required
400
A range or filter is not valid (VALIDATION_ERROR); the message names it.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
403
The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThis request's id, also inX-Request-ID.
successboolean
Example request
curl -X GET 'https://evohub.io/api/v1/evotrail/audit' \
-H 'Authorization: Bearer <TOKEN>'