Skip to content

`GET /v1/orgs/{org}/audit-log/export`.

GET
/v1/orgs/{org}/audit-log/export
curl --request GET \
--url 'https://api.updawg.net/v1/orgs/example/audit-log/export?format=example'
org
required
string

Organization slug.

format
required
string

csv or json.

action
string

Only this action, exactly.

since
string format: date-time

Entries at or after this (RFC 3339).

until
string format: date-time

Entries before this (RFC 3339).

The log, newest first, as a download: CSV with metadata as a JSON column, or a JSON array of entries.

Array<object>
object
action
required

host.decommissioned, policy.updated, … Dotted, noun first.

string
actor
required
object
email

Absent for a user this organization can no longer see, such as a removed member. The entry is still theirs.

string | null
kind
required

user, system or policy. ⚠️ policy is an auto-merge — nobody approved it, a rule did — and is not the same as system.

string
name
string | null
user_id
string | null
at
required
string format: date-time
id
required
string
ip

Where the request came from, when one did.

string | null
metadata
required

What the action recorded about itself. Its shape is the action’s.

object
key
additional properties
One of:
string
target
One of:
object
id
required

With the kind’s usual prefix (hst_…), or bare for a kind this build does not know.

string
kind
required

host, group, policy, …

string
Examplegenerated
[
{
"action": "example",
"actor": {
"email": "example",
"kind": "example",
"name": "example",
"user_id": "example"
},
"at": "2026-04-15T12:00:00Z",
"id": "example",
"ip": "example",
"metadata": {
"additionalProperty": {
"additionalProperty": {}
}
},
"target": {
"id": "example",
"kind": "example"
}
}
]

An unknown or repeated parameter, a format other than csv or json, a time that does not parse, or more entries than one export holds — narrow since and until.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No session.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Not permitted for this role.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No such organization, or not yours.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}