Get account audit logs (Version 2)
Gets a list of audit logs for an account.
Security
API Token
The preferred authorization scheme for interacting with the Cloudflare API. Create a token.
API Email + API Key
The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.
The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.
Accepted Permissions (at least one required)
Query Parameters
Limits the returned results to logs older than the specified date. This can be a date string 2019-04-30 (interpreted in UTC) or an absolute timestamp that conforms to RFC3339.
Limits the returned results to logs newer than the specified date. This can be a date string 2019-04-30 (interpreted in UTC) or an absolute timestamp that conforms to RFC3339.
The cursor is an opaque token used to paginate through large sets of records. It indicates the position from which to continue when requesting the next set of records. A valid cursor value can be obtained from the cursor object in the result_info structure of a previous response.
The number limits the objects to return. The cursor attribute may be used to iterate over the next batch of objects if there are more than the limit.
Filters audit logs by one or more predefined product categories. Each product category expands into a curated set of resource_product values and is unioned with any explicit resource_product filter. Matched case-insensitively; unknown product categories return 400. Repeatable. Use the audit log product categories endpoint to discover the available values.
Get account audit logs (Version 2)
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/logs/audit \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"{
"errors": [
{
"message": "message"
}
],
"result": [
{
"id": "023e105f4ecef8ad9ca31a8372d0c353",
"account": {
"id": "4bb334f7c94c4a29a045f03944f072e5",
"name": "Example Account"
},
"action": {
"description": "Add Member",
"result": "success",
"time": "2024-04-26T17:31:07Z",
"type": "create"
},
"actor": {
"id": "f6b5de0326bb5182b8a4840ee01ec774",
"context": "dash",
"email": "alice@example.com",
"ip_address": "198.41.129.166",
"token_id": "token_id",
"token_name": "token_name",
"type": "user"
},
"raw": {
"cf_ray_id": "8e9b1c60ef9e1c9a",
"method": "POST",
"status_code": 200,
"uri": "/accounts/4bb334f7c94c4a29a045f03944f072e5/members",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Safari/605.1.15"
},
"resource": {
"id": "id",
"product": "members",
"request": {},
"response": {},
"scope": {},
"type": "type"
},
"zone": {
"id": "id",
"name": "example.com"
}
}
],
"result_info": {
"count": "1",
"cursor": "ASqdKd7dKgxh-aZ8bm0mZos1BtW4BdEqifCzNkEeGRzi_5SN_-362Y8sF-C1TRn60_6rd3z2dIajf9EAPyQ_NmIeAMkacmaJPXipqvP7PLU4t72wyqBeJfjmjdE="
},
"success": true
}Returns Examples
{
"errors": [
{
"message": "message"
}
],
"result": [
{
"id": "023e105f4ecef8ad9ca31a8372d0c353",
"account": {
"id": "4bb334f7c94c4a29a045f03944f072e5",
"name": "Example Account"
},
"action": {
"description": "Add Member",
"result": "success",
"time": "2024-04-26T17:31:07Z",
"type": "create"
},
"actor": {
"id": "f6b5de0326bb5182b8a4840ee01ec774",
"context": "dash",
"email": "alice@example.com",
"ip_address": "198.41.129.166",
"token_id": "token_id",
"token_name": "token_name",
"type": "user"
},
"raw": {
"cf_ray_id": "8e9b1c60ef9e1c9a",
"method": "POST",
"status_code": 200,
"uri": "/accounts/4bb334f7c94c4a29a045f03944f072e5/members",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Safari/605.1.15"
},
"resource": {
"id": "id",
"product": "members",
"request": {},
"response": {},
"scope": {},
"type": "type"
},
"zone": {
"id": "id",
"name": "example.com"
}
}
],
"result_info": {
"count": "1",
"cursor": "ASqdKd7dKgxh-aZ8bm0mZos1BtW4BdEqifCzNkEeGRzi_5SN_-362Y8sF-C1TRn60_6rd3z2dIajf9EAPyQ_NmIeAMkacmaJPXipqvP7PLU4t72wyqBeJfjmjdE="
},
"success": true
}