Skip to main content

audit_logs

Creates, updates, deletes, gets or lists an audit_logs resource.

Overview

Nameaudit_logs
TypeResource
Iddatadog.organization.audit_logs

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringUnique ID of the event. (example: AAAAAWgN8Xwgr1vKDQAAAABBV2dOOFh3ZzZobm1mWXJFYTR0OA)
attributesobjectJSON object containing all event attributes and their associated values.
typestringType of the event. (audit) (default: audit, example: audit)

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
list_audit_logsselectfilter[query], filter[from], filter[to], sort, page[cursor], page[limit]List endpoint returns events that match a Audit Logs search query.<br />[Results are paginated][1].<br /><br />Use this endpoint to see your latest Audit Logs events.<br /><br />[1]: https:​//docs.datadoghq.com/logs/guide/collect-multiple-logs-with-pagination
search_audit_logsexecList endpoint returns Audit Logs events that match an Audit search query.<br />[Results are paginated][1].<br /><br />Use this endpoint to build complex Audit Logs events filtering and search.<br /><br />[1]: https:​//docs.datadoghq.com/logs/guide/collect-multiple-logs-with-pagination

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
sitestringThe Datadog site (region) for your organization, for example datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com, ap2.datadoghq.com, datadoghq.eu, ddog-gov.com. Resolved from the DD_SITE environment variable when set. Optional: defaults to datadoghq.com, or the value of the DD_SITE environment variable when set; a WHERE value overrides both.
filter[from]string (date-time)Minimum timestamp for requested events. (example: 2019-01-02T09:42:36.320Z)
filter[query]stringSearch query following Audit Logs syntax. (example: @type:session @application_id:xxxx)
filter[to]string (date-time)Maximum timestamp for requested events. (example: 2019-01-03T09:42:36.320Z)
page[cursor]stringList following results with a cursor provided in the previous query. (example: eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==)
page[limit]integer (int32)Maximum number of events in the response. (example: 25)
sortstringOrder of events in results.

SELECT examples

List endpoint returns events that match a Audit Logs search query.<br />[Results are paginated][1].<br /><br />Use this endpoint to see your latest Audit Logs events.<br /><br />[1]: https:​//docs.datadoghq.com/logs/guide/collect-multiple-logs-with-pagination

SELECT
id,
attributes,
type
FROM datadog.organization.audit_logs
WHERE filter[query] = '{{ filter[query] }}'
AND filter[from] = '{{ filter[from] }}'
AND filter[to] = '{{ filter[to] }}'
AND sort = '{{ sort }}'
AND page[cursor] = '{{ page[cursor] }}'
AND page[limit] = '{{ page[limit] }}'
;

Lifecycle Methods

EXEC variables use wire (API) names.

List endpoint returns Audit Logs events that match an Audit search query.<br />[Results are paginated][1].<br /><br />Use this endpoint to build complex Audit Logs events filtering and search.<br /><br />[1]: https:​//docs.datadoghq.com/logs/guide/collect-multiple-logs-with-pagination

EXEC datadog.organization.audit_logs.search_audit_logs
@@json=
'{
"filter": "{{ filter }}",
"options": "{{ options }}",
"page": "{{ page }}",
"sort": "{{ sort }}"
}'
;