Skip to content

Read the audit log

GET
/v1/audit-log
curl --request GET \
--url 'http://localhost:8080/v1/audit-log?category=RECORD&principalKind=user&pageSize=50' \
--header 'Authorization: Bearer <token>'
Available inEmbeddedBundledCluster
AuthAuthenticated Bearer token

The audit log. Who did what, newest first, from the tenant’s records that carry an acting principal (RECORD), the requests the engine refused (ACCESS) and the changes made through the administration API (IDENTITY). Requires audit:read. Unknown or repeated parameters are refused.

x-tenant-id
string
>= 1 characters

Tenant selection. A principal of one tenant may omit it, and if sent it must name that tenant. A principal that may act in several tenants sends it on every request.

category
string
Allowed values: RECORD ACCESS IDENTITY
subject
string
>= 1 characters
principalKind
string
Allowed values: user service client static anonymous
intent
string

Record intent such as ASSIGNED or COMPLETED.

action
string
>= 1 characters

Command action carried by the record payload

valueType
string

Record family such as USER_TASK.

processInstanceKey

Positive signed 64-bit entity key encoded as a JSON string.

string format: int64
/^[1-9][0-9]*$/
from
string format: date-time

Inclusive RFC 3339 lower bound.

to
string format: date-time

Exclusive RFC 3339 upper bound.

cursor
string

The previous page’s cursor.

pageSize
integer
default: 50 <= 200

One newest-first page of audit entries

Media typeapplication/json
object
items
required
Array<object>
object
category
required
string
Allowed values: RECORD ACCESS IDENTITY
timestamp
required

Epoch microseconds.

integer format: int64
partitionId
required

The record’s partition; -1 for ACCESS and -2 for IDENTITY entries.

integer
position
required
integer format: int64
subject
string
principalKind
string
Allowed values: user service client static anonymous
tenantId
required
string
recordType
string
valueType
string
intent
string
status

HTTP status of a refused request or of an identity change.

integer
method
string
route
string
action

The record’s command action, or the change of an IDENTITY entry such as client.secret.rotate.

string
targets

Ids an identity change changed.

object
key
additional properties
string
result
string
Allowed values: DONE REFUSED
summary

What an identity change asked for; fields that could carry a secret are “(not recorded)”.

object
key
additional properties
any
key
required
string
processInstanceKey
string
nullable
correlationId
string
rejectionType
string
rejectionReason
string
cursor
required
string
nullable
Example
{
"items": [
{
"category": "RECORD",
"principalKind": "user",
"result": "DONE"
}
]
}

Invalid request

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:invalid-argument",
"title": "Bad Request",
"status": 400,
"detail": "The request is malformed",
"instance": "/v1/audit-log"
}

Authentication required

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "A valid bearer credential is required",
"instance": "/v1/audit-log"
}
WWW-Authenticate
string

The caller lacks the required permission.

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:forbidden",
"title": "Forbidden",
"status": 403,
"detail": "The principal lacks the action this route requires",
"instance": "/v1/audit-log"
}

Tenant-scoped resource not found

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:not-found",
"title": "Not Found",
"status": 404,
"detail": "The requested resource does not exist",
"instance": "/v1/audit-log"
}

Idempotency conflict

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:conflict",
"title": "Conflict",
"status": 409,
"detail": "The idempotency key is already associated with another request",
"instance": "/v1/audit-log"
}

Authenticated request exceeds its configured bound

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:payload-too-large",
"title": "Payload Too Large",
"status": 413,
"detail": "The request exceeds the configured size limit",
"instance": "/v1/audit-log"
}

Tenant quota exhausted

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:quota-exhausted",
"title": "Quota Exhausted",
"status": 429,
"detail": "The tenant active-instance quota is exhausted",
"instance": "/v1/audit-log"
}

Non-leaking internal failure

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:internal",
"title": "Internal Server Error",
"status": 500,
"detail": "The request could not be completed",
"instance": "/v1/audit-log"
}

The operation is on the reviewed allow-list of what this deployment mode cannot serve.

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:mode-not-supported",
"title": "Mode Not Supported",
"status": 501,
"detail": "GET /v1/audit-log is not supported in embedded mode",
"instance": "/v1/audit-log",
"mode": "embedded"
}

Backpressure or dependency unavailable

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:unavailable",
"title": "Service Unavailable",
"status": 503,
"detail": "The required engine service is not ready",
"instance": "/v1/audit-log"
}