Get audit log
tailscale_get_audit_logRetrieve tailnet audit logs to see who changed what and when, with optional filters for actor, target, or event. Ideal for troubleshooting and compliance.
Instructions
Get the tailnet audit/configuration log. Shows who changed what and when -- useful for troubleshooting and compliance. Optional actor, target and event filters narrow the query server-side, so a targeted question doesn't have to pull the whole window.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end | No | End time in RFC3339 format. Optional: when omitted the tool sends the current time, which Tailscale's API requires. | |
| actor | No | Server-side filter: one exact actor ID, or '~text' to wildcard-match a login or display name (e.g. '~bob'). One value per call -- how the API reads a repeated filter key is not verified yet. | |
| event | No | Server-side filter: one event type from Tailscale's audit event list, e.g. 'TAILNET.UPDATE.ACL', 'TAILNET.UPDATE.DNS_CONFIG', 'NODE.CREATE', 'NODE.DELETE', 'API_KEY.CREATE', 'USER.UPDATE.USER_ROLE', 'WEBHOOK_ENDPOINT.CREATE'. Not a closed set -- the list keeps growing. One value per call, as for actor. | |
| start | Yes | Start time in RFC3339 format (e.g. '2026-04-01T00:00:00Z'). Required. | |
| target | No | Server-side filter: one string, matched against any part of any of an entry's targets (ID or name). One value per call, as for actor. |