Audit Log (Admin)

List Audit Log Entries

GET /api/v1/audit-log

Returns a paginated list of recorded administrative and authentication events, including sampled read-only key denials. Admin-only.

Query parameters:

Parameter Type Required Default Description
user_id string (UUID) No -- Filter by user UUID
entity_type string No -- Filter by entity type (see values below)
action string No -- Filter by action (see values below)
from string (RFC 3339) No -- Filter entries after this timestamp
to string (RFC 3339) No -- Filter entries before this timestamp
limit integer No 50 Page size
offset integer No 0 Pagination offset

entity_type values: network, autonomous_system, routing_domain, protocol_instance, area, collector, alert_rule, user, snmp_target, system_settings, maintenance_window, notification_channel, auth, auth_provider, scim_token

action values: create, update, delete, toggle, password_reset, login, login_failed, logout, password_change, token_replay, enable_local_login, provider_disabled, clear_mfa_requirement, mfa_required, mfa_enroll_required, mfa_enroll_started, mfa_enabled, mfa_disabled, mfa_reset, scim_provision, scim_deprovision

Authentication events (entity type auth) are recorded claim-independently: login, login_failed (with a reason in detail: unknown_user, bad_password, inactive, locked, sso_account, local_login_restricted), logout, password_change and token_replay (refresh-token replay detection, includes the revoked family). Failed logins have user_id: null when the username does not exist. Break-glass actions from the osprey auth recovery CLI appear with username set to cli:<os-user> and no IP address.

The filters also accept entity_type=api_key and action=api_key.read_only_denied. These records identify the key UUID and owner; detail contains method, status, upgrade and suppressed_since_last_record. See Read-only API Keys for sampling, retention and failure semantics. They are not a complete request ledger.

Response: 200 OK

{
  "entries": [
    {
      "id": "uuid",
      "user_id": "uuid",
      "username": "admin",
      "action": "create",
      "entity_type": "network",
      "entity_id": "uuid",
      "detail": { "name": "Example Network" },
      "ip_address": "192.0.2.100",
      "created_at": "2026-02-24T12:00:00Z"
    }
  ],
  "total": 42,
  "limit": 50,
  "offset": 0
}

Response fields:

Field Type Description
entries[].id string (UUID) Unique audit log entry ID
entries[].user_id string (UUID) ID of the user who performed the action
entries[].username string Username of the user who performed the action
entries[].action string The action performed
entries[].entity_type string The type of entity affected
entries[].entity_id string (UUID) ID of the affected entity
entries[].detail object Additional context about the action (varies by entity type)
entries[].ip_address string Client IP address of the request
entries[].created_at string (RFC 3339) Timestamp of the action
total integer Total number of matching entries (for pagination)
limit integer Page size used
offset integer Pagination offset used

Error responses: