Audit
Operations for the Audit service collection.
| Language | Last Update |
|---|---|
| Python | v1.6.6 |
| PowerShell | |
| Go | |
| TypeScript | |
| Rust | |
| Ruby |
Table of Contents
Section titled “Table of Contents”| Operation | Description |
|---|---|
CreateQueryJobcreate_audit_query_job | Creates an asynchronous query job to retrieve audit log entries based on specified filters |
ExportQueryResultsexport_audit_query_results | Exports the results of a completed query job in CSV or JSON format |
GetQueryResultsget_audit_query_results | Retrieves the results of a completed query job with pagination |
PollQueryJobStatuspoll_audit_query_status | Checks the status of a previously created query job |
CreateQueryJob
Section titled “CreateQueryJob”Creates an asynchronous query job to retrieve audit log entries based on specified filters
Method POST
Route /audit-logs/queries/queryjobs/v1
Scope Audit: READ
PEP 8
create_audit_query_jobParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
action body · array
The action value.
action_description body · array
The action_description value.
actor_id body · array
The actor_id value.
actor_ip body · array
The actor_ip value.
actor_type body · array
The actor_type value.
category body · array
The category value.
category_description body · array
The category_description value.
cid body · array
The cid value.
end_time body · string
The end_time value.
event_id body · array
The event_id value.
event_version body · array
The event_version value.
extensions body · object
The extensions value.
geo_city body · array
The geo_city value.
geo_country body · array
The geo_country value.
sort body · string
The sort value.
start_time body · string
The start_time value.
target_display_name body · array
The target_display_name value.
target_id body · array
The target_id value.
target_type body · array
The target_type value.
user_agent body · array
The user_agent value.
Code Examples
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
extensions = "string"
response = falcon.create_audit_query_job(action=["string"], action_description=["string"], actor_id=["string"], actor_ip=["string"], actor_type=["string"], category=["string"], category_description=["string"], cid=["string"], end_time="string", event_id=["string"], event_version=["string"], extensions=extensions, geo_city=["string"], geo_country=["string"], sort="string", start_time="string", target_display_name=["string"], target_id=["string"], target_type=["string"], user_agent=["string"])print(response)from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
extensions = "string"
response = falcon.CreateQueryJob(action=["string"], action_description=["string"], actor_id=["string"], actor_ip=["string"], actor_type=["string"], category=["string"], category_description=["string"], cid=["string"], end_time="string", event_id=["string"], event_version=["string"], extensions=extensions, geo_city=["string"], geo_country=["string"], sort="string", start_time="string", target_display_name=["string"], target_id=["string"], target_type=["string"], user_agent=["string"])print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = { "action": ["string"], "action_description": ["string"], "actor_id": ["string"], "actor_ip": ["string"], "actor_type": ["string"], "category": ["string"], "category_description": ["string"], "cid": ["string"], "end_time": "string", "event_id": ["string"], "event_version": ["string"], "extensions": {}, "geo_city": ["string"], "geo_country": ["string"], "sort": "string", "start_time": "string", "target_display_name": ["string"], "target_id": ["string"], "target_type": ["string"], "user_agent": ["string"]}
response = falcon.command("CreateQueryJob", body=body_payload)print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ "string"]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ "string" ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ "string" ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ "string" ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ "string" ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ "string" ]}ExportQueryResults
Section titled “ExportQueryResults”Exports the results of a completed query job in CSV or JSON format
Method GET
Route /audit-logs/entities/queryjob-exports/v1
Scope Audit: READ
PEP 8
export_audit_query_resultsParameters
Section titled “Parameters”id query · string
Job ID from a previously created query job
format query · string
Export format: csv or json
include_descriptions query · boolean
When true, includes descriptions for category and action fields (default: false)
include_extension_metadata query · boolean
When true, filters extension keys based on audit definition YAML and includes descriptions for extension keys (default: false)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.export_audit_query_results(id="string", format="string", include_descriptions=boolean, include_extension_metadata=boolean)print(response)from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.ExportQueryResults(id="string", format="string", include_descriptions=boolean, include_extension_metadata=boolean)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("ExportQueryResults", id="string", format="string", include_descriptions=boolean, include_extension_metadata=boolean)print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
GetQueryResults
Section titled “GetQueryResults”Retrieves the results of a completed query job with pagination
Method GET
Route /audit-logs/entities/queryjob-results/v1
Scope Audit: READ
PEP 8
get_audit_query_resultsParameters
Section titled “Parameters”id query · string
Job ID from a previously created query job
offset query · integer
Starting position for pagination (default: 0)
limit query · integer
Maximum number of records to return (default: 100)
include_descriptions query · boolean
When true, includes descriptions for category and action fields (default: false)
include_extension_metadata query · boolean
When true, filters extension keys based on audit definition YAML and includes descriptions for extension keys (default: false)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_audit_query_results(id="string", offset=integer, limit=integer, include_descriptions=boolean, include_extension_metadata=boolean)print(response)from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.GetQueryResults(id="string", offset=integer, limit=integer, include_descriptions=boolean, include_extension_metadata=boolean)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("GetQueryResults", id="string", offset=integer, limit=integer, include_descriptions=boolean, include_extension_metadata=boolean)print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "action": "string", "action_description": "string", "action_timestamp": "string", "actor_display_name": "string", "actor_id": "string", "actor_ip": "string", "actor_type": 0, "category": "string", "category_description": "string", "cid": "string", "event_id": "string", "event_version": "string", "extensions": {}, "geo_city": "string", "geo_country": "string", "ingest_timestamp": "string", "reason": "string", "target_display_name": "string", "target_id": "string", "target_type": 0, "user_agent": "string" } ]}PollQueryJobStatus
Section titled “PollQueryJobStatus”Checks the status of a previously created query job
Method GET
Route /audit-logs/entities/queryjobs/v1
Scope Audit: READ
PEP 8
poll_audit_query_statusParameters
Section titled “Parameters”id query · string
Job ID from a previously created query job
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.poll_audit_query_status(id=id_list)print(response)from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.PollQueryJobStatus(id=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("PollQueryJobStatus", id="string")print(response)Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Examples coming soon.
Responses
[ { "id": "string", "status": "string", "total_results": 0 }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }, "resources": [ { "id": "string", "status": "string", "total_results": 0 } ]}