get_authz_audit
Query authorization audit logs with filters for user, action, result, resource, or event class, plus pagination, to investigate access decisions and policy activity.
Instructions
Query the authorization audit log with filters and pagination.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | Page number | |
| size | No | Page size | |
| event | No | Include rows matching any of these details.event classes | |
| since | No | Start timestamp (ISO 8601) | |
| until | No | End timestamp (ISO 8601) | |
| action | No | Filter by audit action | |
| result | No | Filter by result outcome | |
| user_id | No | Filter by user ID | |
| actor_id | No | Filter by credential actor UUID | |
| actor_type | No | Filter by credential actor type; unknown also includes legacy rows without a type | |
| resource_id | No | Filter by resource ID | |
| exclude_event | No | Exclude these details.event classes; legacy unclassified rows remain included | |
| resource_type | No | Filter by resource type | |
| exclude_action | No | Exclude rows matching any of these action names |