v1

latestOpenAPI 3.0.12026-07-22231676.5 KB
Search

Search Audit Logs

Takes a timestamp as a parameter and returns the audit log at or after the timestamp. Useful to begin pagination to get more logs.

For a complete list of all audit log types and their descriptions, see the Audit Logs Guide.

get/api/v1/logs/audit/search/

Query parameters

timeinteger required

UTC epoch timestamp, up to 1 year old from now

log_typestring

Optional filter to return only logs of a specific type. For Microsoft add-in activity, use add-in-specific log types such as user:word_add_in_docx_drafting or user:outlook_add_in_ask. See the Audit Logs Guide for a complete list of log types.

Example:auth:login

Response

Audit log entry at or after time

Example response

{
  "log": {
    "id": "0194f5c5-2021-75ae-b202-f049fca9dce2",
    "ip": "0.0.0.0",
    "timestamp": "2025-02-11T16:08:44.324452",
    "type": "admin:fetch_workspace_history",
    "user": "user@example.com",
    "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
  }
}