List audit log events
curl --request GET \
--url https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"organizationId": "<string>",
"action": "<string>",
"category": "AUTHENTICATION",
"actorType": "USER",
"actorUserId": "<string>",
"actorEmail": "<string>",
"apiKeyId": "<string>",
"scimTokenId": "<string>",
"targetType": "<string>",
"targetId": "<string>",
"targetDisplay": "<string>",
"source": "WEB",
"ipAddress": "<string>",
"userAgent": "<string>",
"metadata": "<unknown>"
}
],
"pagination": {
"nextCursor": "<string>",
"hasMore": true
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "RateLimitExceeded",
"detail": "<string>",
"retryAfterMs": 123
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}Organizations
List audit log events
Returns immutable organization audit events in reverse chronological order for SIEM ingestion. Requires an Enterprise organization and an administrator API key.
GET
/
api
/
public
/
organizations
/
{orgId}
/
audit-logs
List audit log events
curl --request GET \
--url https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://charts.basedash.com/api/public/organizations/{orgId}/audit-logs")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"organizationId": "<string>",
"action": "<string>",
"category": "AUTHENTICATION",
"actorType": "USER",
"actorUserId": "<string>",
"actorEmail": "<string>",
"apiKeyId": "<string>",
"scimTokenId": "<string>",
"targetType": "<string>",
"targetId": "<string>",
"targetDisplay": "<string>",
"source": "WEB",
"ipAddress": "<string>",
"userAgent": "<string>",
"metadata": "<unknown>"
}
],
"pagination": {
"nextCursor": "<string>",
"hasMore": true
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}{
"error": {
"title": "RateLimitExceeded",
"detail": "<string>",
"retryAfterMs": 123
}
}{
"error": {
"title": "<string>",
"detail": "<string>"
}
}Authorizations
API key authentication using Bearer token format: Bearer <basedash_api_key>
Path Parameters
Organization ID
Query Parameters
Maximum number of items to return (1-100, default 50)
Required range:
1 <= x <= 100Cursor for pagination (ID of the last item from previous page)
Exact dot-namespaced action
Available options:
user.login, user.logout, member.joined, member.invited, member.invite_revoked, member.role_changed, member.deactivated, member.reactivated, group.created, group.updated, group.deleted, group.member_added, group.member_removed, grant.created, grant.updated, grant.deleted, data_source.created, data_source.updated, data_source.deleted, data_source.sync_requested, data_source.schema_synced, data_source.credentials_viewed, api_key.created, api_key.deleted, scim_token.created, scim_token.deleted, organization.created, organization.updated, organization.jwt_secret_viewed, organization.jwt_secret_copied, organization.billing_account_attached, organization.billing_account_detached, domain.created, domain.updated, domain.deleted, dashboard.created, dashboard.deleted, dashboard.archived, dashboard.restored, dashboard.public_sharing_enabled, dashboard.public_sharing_disabled, automation.created, automation.deleted, automation.archived, automation.restored, mcp_connector.created, mcp_connector.updated, mcp_connector.deleted, mcp_connector.tool_access_updated, public_api.request, scim.user_created, scim.user_updated, scim.user_deactivated, scim.group_created, scim.group_updated, scim.group_deleted, query.executed, query.mutating_executed, data.exported, ai.tool_executed Actor user ID
Available options:
AUTHENTICATION, MEMBERS, ACCESS_CONTROL, DATA_SOURCES, QUERIES, EXPORTS, AI, ORGANIZATION, CONTENT, INTEGRATIONS Inclusive lower timestamp or date boundary
Case-insensitive actor, action, target name, or target ID search
Available options:
WEB, PUBLIC_API, SCIM, SLACK, MCP, SYSTEM, PUBLIC_DASHBOARD Exact target resource type
Inclusive upper timestamp or date boundary
Was this page helpful?