Audit Log (Admin)
List Audit Log Entries
GET /api/v1/audit-log
Returns a paginated list of recorded administrative and authentication events, including sampled read-only key denials. Admin-only.
Query parameters:
| Parameter |
Type |
Required |
Default |
Description |
user_id |
string (UUID) |
No |
-- |
Filter by user UUID |
entity_type |
string |
No |
-- |
Filter by entity type (see values below) |
action |
string |
No |
-- |
Filter by action (see values below) |
from |
string (RFC 3339) |
No |
-- |
Filter entries after this timestamp |
to |
string (RFC 3339) |
No |
-- |
Filter entries before this timestamp |
limit |
integer |
No |
50 |
Page size |
offset |
integer |
No |
0 |
Pagination offset |
entity_type values: network, autonomous_system, routing_domain, protocol_instance, area, collector, alert_rule, user, snmp_target, system_settings, maintenance_window, notification_channel, auth, auth_provider, scim_token
action values: create, update, delete, toggle, password_reset, login, login_failed, logout, password_change, token_replay, enable_local_login, provider_disabled, clear_mfa_requirement, mfa_required, mfa_enroll_required, mfa_enroll_started, mfa_enabled, mfa_disabled, mfa_reset, scim_provision, scim_deprovision
Authentication events (entity type auth) are recorded claim-independently: login, login_failed (with a reason in detail: unknown_user, bad_password, inactive, locked, sso_account, local_login_restricted), logout, password_change and token_replay (refresh-token replay detection, includes the revoked family). Failed logins have user_id: null when the username does not exist. Break-glass actions from the osprey auth recovery CLI appear with username set to cli:<os-user> and no IP address.
The filters also accept entity_type=api_key and action=api_key.read_only_denied.
These records identify the key UUID and owner; detail contains method, status,
upgrade and suppressed_since_last_record. See Read-only API Keys
for sampling, retention and failure semantics. They are not a complete request ledger.
Response: 200 OK
{
"entries": [
{
"id": "uuid",
"user_id": "uuid",
"username": "admin",
"action": "create",
"entity_type": "network",
"entity_id": "uuid",
"detail": { "name": "Example Network" },
"ip_address": "192.0.2.100",
"created_at": "2026-02-24T12:00:00Z"
}
],
"total": 42,
"limit": 50,
"offset": 0
}
Response fields:
| Field |
Type |
Description |
entries[].id |
string (UUID) |
Unique audit log entry ID |
entries[].user_id |
string (UUID) |
ID of the user who performed the action |
entries[].username |
string |
Username of the user who performed the action |
entries[].action |
string |
The action performed |
entries[].entity_type |
string |
The type of entity affected |
entries[].entity_id |
string (UUID) |
ID of the affected entity |
entries[].detail |
object |
Additional context about the action (varies by entity type) |
entries[].ip_address |
string |
Client IP address of the request |
entries[].created_at |
string (RFC 3339) |
Timestamp of the action |
total |
integer |
Total number of matching entries (for pagination) |
limit |
integer |
Page size used |
offset |
integer |
Pagination offset used |
Error responses:
400 Bad Request -- Invalid query parameter value (e.g., malformed UUID, invalid timestamp, unknown entity_type or action)
401 Unauthorized -- Missing or invalid access token
403 Forbidden -- Non-admin user