Retrieve audit logs
get_organization_audit_logsRetrieve audit logs for all users in an organization within a specified time range to monitor activity and investigate security events.
Instructions
This endpoint retrieves audit logs for all users in an organization for a specified time period. Read operation.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | Page number for pagination. | |
| account | No | Named private Gumloop account; selects private credentials and user/team identity. | |
| user_id | No | Your user id -- you must be an organization admin to retrieve organization logs. | |
| end_time | Yes | End timestamp for log filtering (ISO format). | |
| user_ids | No | Comma-separated list of user IDs whose events should be returned. | |
| page_size | No | Number of records per page. | |
| entity_ids | No | Comma-separated list of entity IDs (agents, workbooks, files) to filter by. The singular `entity_id` param accepts a single value. | |
| start_time | Yes | Start timestamp for log filtering (ISO format). | |
| event_types | No | Comma-separated list of event types to filter by (e.g. `user_sign_in,credential_retrieval`). The singular `event_type` param accepts a single value. | |
| ip_addresses | No | Comma-separated list of source IP addresses to filter by. The singular `ip_address` param accepts a single value. | |
| workspace_ids | No | Comma-separated list of workspace (team) IDs to filter by. The singular `workspace_id` param accepts a single value. | |
| organization_id | Yes | The ID of the organization to retrieve audit logs for. |