Query audit logs
Audit Logs
Query audit logs
Query and aggregate audit logs. Admin role with auditView privilege required.
GET
Query audit logs
Authorizations
Bearer token authentication. Supports two token types:
- JWT Access Token — obtained via
POST /v1/auth/login - Personal Access Token (PAT) — created via
POST /v1/api-tokens, format:cmnd_<tokenId>.<secret>
Query Parameters
Maximum number of records to return
Offset for pagination
Filter by event category
Filter by action type
Filter by severity level
Start date filter
End date filter
Filter by user ID
Field to aggregate results by

