v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-1362360.8 KB
activities

Start receiving notifications for account activities. For more information, see Receiving Push Notifications.

post/admin/reports/v1/activity/users/{userKey}/applications/{applicationName}/watch

Path parameters

userKeystring required

Represents the profile ID or the user email for which the data should be filtered. Can be all for all information, or userKey for a user's unique Google Workspace profile ID or their primary email address. Must not be a deleted user. For a deleted user, call users.list in Directory API with showDeleted=true, then use the returned ID as the userKey.

applicationName'access_transparency' | 'admin' | 'calendar' | 'chat' | 'drive' | 'gcp' | 'gplus' | 'groups' | 'groups_enterprise' | 'jamboard' | 'login' | 'meet' | 'mobile' | 'rules' | 'saml' | 'token' | 'user_accounts' | 'context_aware_access' | 'chrome' | 'data_studio' | 'keep' | 'classroom' required

Application name for which the events are to be retrieved.

Query parameters

actorIpAddressstring

The Internet Protocol (IP) Address of host where the event was performed. This is an additional way to filter a report's summary using the IP address of the user whose activity is being reported. This IP address may or may not reflect the user's physical location. For example, the IP address can be the user's proxy server's address or a virtual private network (VPN) address. This parameter supports both IPv4 and IPv6 address versions.

customerIdstring

The unique ID of the customer to retrieve data for.

endTimestring

Sets the end of the range of time shown in the report. The date is in the RFC 3339 format, for example 2010-10-28T10:26:35.000Z. The default value is the approximate time of the API request. An API report has three basic time concepts: - Date of the API's request for a report: When the API created and retrieved the report. - Report's start time: The beginning of the timespan shown in the report. The startTime must be before the endTime (if specified) and the current time when the request is made, or the API returns an error. - Report's end time: The end of the timespan shown in the report. For example, the timespan of events summarized in a report can start in April and end in May. The report itself can be requested in August. If the endTime is not specified, the report returns all activities from the startTime until the current time or the most recent 180 days if the startTime is more than 180 days in the past.

eventNamestring

The name of the event being queried by the API. Each eventName is related to a specific Google Workspace service or feature which the API organizes into types of events. An example is the Google Calendar events in the Admin console application's reports. The Calendar Settings type structure has all of the Calendar eventName activities reported by the API. When an administrator changes a Calendar setting, the API reports this activity in the Calendar Settings type and eventName parameters. For more information about eventName query strings and parameters, see the list of event names for various applications above in applicationName.

filtersstring

The filters query string is a comma-separated list composed of event parameters manipulated by relational operators. Event parameters are in the form {parameter1 name}{relational operator}{parameter1 value},{parameter2 name}{relational operator}{parameter2 value},... These event parameters are associated with a specific eventName. An empty report is returned if the request's parameter doesn't belong to the eventName. For more information about the available eventName fields for each application and their associated parameters, go to the ApplicationName table, then click through to the Activity Events page in the Appendix for the application you want. In the following Drive activity examples, the returned list consists of all edit events where the doc_id parameter value matches the conditions defined by the relational operator. In the first example, the request returns all edited documents with a doc_id value equal to 12345. In the second example, the report returns any edited documents where the doc_id value is not equal to 98765. The <> operator is URL-encoded in the request's query string (%3C%3E): GET...&eventName=edit&filters=doc_id==12345 GET...&eventName=edit&filters=doc_id%3C%3E98765 A filters query supports these relational operators: * ==—'equal to'. * <>—'not equal to'. Must be URL-encoded (%3C%3E). * <—'less than'. Must be URL-encoded (%3C). * <=—'less than or equal to'. Must be URL-encoded (%3C=). * >—'greater than'. Must be URL-encoded (%3E). * >=—'greater than or equal to'. Must be URL-encoded (%3E=). Note: The API doesn't accept multiple values of the same parameter. If a parameter is supplied more than once in the API request, the API only accepts the last value of that parameter. In addition, if an invalid parameter is supplied in the API request, the API ignores that parameter and returns the response corresponding to the remaining valid parameters. If no parameters are requested, all parameters are returned.

groupIdFilterstring

Deprecated. This field is deprecated and is no longer supported. Comma separated group ids (obfuscated) on which user activities are filtered, i.e. the response will contain activities for only those users that are a part of at least one of the group ids mentioned here. Format: "id:abc123,id:xyz456" Important: To filter by groups, you must explicitly add the groups to your filtering groups allowlist. For more information about adding groups to filtering groups allowlist, see Filter results by Google Group

maxResultsinteger

Determines how many activity records are shown on each response page. For example, if the request sets maxResults=1 and the report has two activities, the report has two pages. The response's nextPageToken property has the token to the second page. The maxResults query string is optional in the request. The default value is 1000.

orgUnitIDstring

Deprecated. This field is deprecated and is no longer supported. ID of the organizational unit to report on. Activity records will be shown only for users who belong to the specified organizational unit. Data before Dec 17, 2018 doesn't appear in the filtered results.

pageTokenstring

The token to specify next page. A report with multiple pages has a nextPageToken property in the response. In your follow-on request getting the next page of the report, enter the nextPageToken value in the pageToken query string.

startTimestring

Sets the beginning of the range of time shown in the report. The date is in the RFC 3339 format, for example 2010-10-28T10:26:35.000Z. The report returns all activities from startTime until endTime. The startTime must be before the endTime (if specified) and the current time when the request is made, or the API returns an error.

Request body

paramsobject

Additional parameters controlling delivery channel behavior. Optional.

expirationstring int64

Date and time of notification channel expiration, expressed as a Unix timestamp, in milliseconds. Optional.

kindstring

Identifies this as a notification channel used to watch for changes to a resource, which is "api#channel".

typestring

The type of delivery mechanism used for this channel. The value should be set to "web_hook".

addressstring

The address where notifications are delivered for this channel.

tokenstring

An arbitrary string delivered to the target address with each notification delivered over this channel. Optional.

idstring

A UUID or similar unique string that identifies this channel.

payloadboolean

A Boolean value to indicate whether payload is wanted. A payload is data that is sent in the body of an HTTP POST, PUT, or PATCH message and contains important information about the request. Optional.

resourceIdstring

An opaque ID that identifies the resource being watched on this channel. Stable across different API versions.

resourceUristring

A version-specific identifier for the watched resource.

Response

Successful response