Read the audit log
HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("http://localhost:8080/v1/audit-log?category=RECORD&principalKind=user&pageSize=50")) .header("Authorization", "Bearer <token>") .method("GET", HttpRequest.BodyPublishers.noBody()) .build();HttpResponse<String> response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());System.out.println(response.body());const url = 'http://localhost:8080/v1/audit-log?category=RECORD&principalKind=user&pageSize=50';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'http://localhost:8080/v1/audit-log?category=RECORD&principalKind=user&pageSize=50' \ --header 'Authorization: Bearer <token>'The audit log. Who did what, newest first, from the tenant’s records that carry an acting principal (RECORD), the requests the engine refused (ACCESS) and the changes made through the administration API (IDENTITY). Requires audit:read. Unknown or repeated parameters are refused.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters”Tenant selection. A principal of one tenant may omit it, and if sent it must name that tenant. A principal that may act in several tenants sends it on every request.
Query Parameters
Section titled “Query Parameters”Record intent such as ASSIGNED or COMPLETED.
Command action carried by the record payload
Record family such as USER_TASK.
Positive signed 64-bit entity key encoded as a JSON string.
Inclusive RFC 3339 lower bound.
Exclusive RFC 3339 upper bound.
The previous page’s cursor.
Responses
Section titled “ Responses ”One newest-first page of audit entries
object
object
Epoch microseconds.
The record’s partition; -1 for ACCESS and -2 for IDENTITY entries.
HTTP status of a refused request or of an identity change.
The record’s command action, or the change of an IDENTITY entry such as client.secret.rotate.
Ids an identity change changed.
object
What an identity change asked for; fields that could carry a secret are “(not recorded)”.
object
Example
{ "items": [ { "category": "RECORD", "principalKind": "user", "result": "DONE" } ]}Invalid request
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:invalid-argument", "title": "Bad Request", "status": 400, "detail": "The request is malformed", "instance": "/v1/audit-log"}Authentication required
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:unauthorized", "title": "Unauthorized", "status": 401, "detail": "A valid bearer credential is required", "instance": "/v1/audit-log"}Headers
Section titled “Headers”The caller lacks the required permission.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:forbidden", "title": "Forbidden", "status": 403, "detail": "The principal lacks the action this route requires", "instance": "/v1/audit-log"}Tenant-scoped resource not found
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:not-found", "title": "Not Found", "status": 404, "detail": "The requested resource does not exist", "instance": "/v1/audit-log"}Idempotency conflict
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:conflict", "title": "Conflict", "status": 409, "detail": "The idempotency key is already associated with another request", "instance": "/v1/audit-log"}Authenticated request exceeds its configured bound
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:payload-too-large", "title": "Payload Too Large", "status": 413, "detail": "The request exceeds the configured size limit", "instance": "/v1/audit-log"}Tenant quota exhausted
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:quota-exhausted", "title": "Quota Exhausted", "status": 429, "detail": "The tenant active-instance quota is exhausted", "instance": "/v1/audit-log"}Non-leaking internal failure
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:internal", "title": "Internal Server Error", "status": 500, "detail": "The request could not be completed", "instance": "/v1/audit-log"}The operation is on the reviewed allow-list of what this deployment mode cannot serve.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:mode-not-supported", "title": "Mode Not Supported", "status": 501, "detail": "GET /v1/audit-log is not supported in embedded mode", "instance": "/v1/audit-log", "mode": "embedded"}Backpressure or dependency unavailable
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:unavailable", "title": "Service Unavailable", "status": 503, "detail": "The required engine service is not ready", "instance": "/v1/audit-log"}