v1
latestOpenAPI 3.0.12026-07-22231676.5 KBSearch
Search Audit Logs
Takes a timestamp as a parameter and returns the audit log at or after the timestamp. Useful to begin pagination to get more logs.
For a complete list of all audit log types and their descriptions, see the Audit Logs Guide.
get/api/v1/logs/audit/search/
Query parameters
timeinteger required
UTC epoch timestamp, up to 1 year old from now
log_typestring
Optional filter to return only logs of a specific type. For Microsoft add-in activity, use add-in-specific log types such as user:word_add_in_docx_drafting or user:outlook_add_in_ask. See the Audit Logs Guide for a complete list of log types.
Example:auth:login
Response
Audit log entry at or after time
Example response
{
"log": {
"id": "0194f5c5-2021-75ae-b202-f049fca9dce2",
"ip": "0.0.0.0",
"timestamp": "2025-02-11T16:08:44.324452",
"type": "admin:fetch_workspace_history",
"user": "user@example.com",
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
}
}