Skip to content

Audit

Operations for the Audit service collection.

LanguageLast Update
Pythonv1.6.6
PowerShell
Go
TypeScript
Rust
Ruby

OperationDescription
CreateQueryJob
create_audit_query_job
Creates an asynchronous query job to retrieve audit log entries based on specified filters
ExportQueryResults
export_audit_query_results
Exports the results of a completed query job in CSV or JSON format
GetQueryResults
get_audit_query_results
Retrieves the results of a completed query job with pagination
PollQueryJobStatus
poll_audit_query_status
Checks the status of a previously created query job

Creates an asynchronous query job to retrieve audit log entries based on specified filters

Method POST
Route /audit-logs/queries/queryjobs/v1
Scope Audit: READ
PEP 8 create_audit_query_job
body body · dictionary
Full body payload as JSON formatted dictionary.
action body · array
The action value.
action_description body · array
The action_description value.
actor_id body · array
The actor_id value.
actor_ip body · array
The actor_ip value.
actor_type body · array
The actor_type value.
category body · array
The category value.
category_description body · array
The category_description value.
cid body · array
The cid value.
end_time body · string
The end_time value.
event_id body · array
The event_id value.
event_version body · array
The event_version value.
extensions body · object
The extensions value.
geo_city body · array
The geo_city value.
geo_country body · array
The geo_country value.
sort body · string
The sort value.
start_time body · string
The start_time value.
target_display_name body · array
The target_display_name value.
target_id body · array
The target_id value.
target_type body · array
The target_type value.
user_agent body · array
The user_agent value.
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
extensions = "string"
response = falcon.create_audit_query_job(action=["string"],
action_description=["string"],
actor_id=["string"],
actor_ip=["string"],
actor_type=["string"],
category=["string"],
category_description=["string"],
cid=["string"],
end_time="string",
event_id=["string"],
event_version=["string"],
extensions=extensions,
geo_city=["string"],
geo_country=["string"],
sort="string",
start_time="string",
target_display_name=["string"],
target_id=["string"],
target_type=["string"],
user_agent=["string"])
print(response)
[
"string"
]


Exports the results of a completed query job in CSV or JSON format

Method GET
Route /audit-logs/entities/queryjob-exports/v1
Scope Audit: READ
PEP 8 export_audit_query_results
id query · string
Job ID from a previously created query job
format query · string
Export format: csv or json
include_descriptions query · boolean
When true, includes descriptions for category and action fields (default: false)
include_extension_metadata query · boolean
When true, filters extension keys based on audit definition YAML and includes descriptions for extension keys (default: false)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.export_audit_query_results(id="string",
format="string",
include_descriptions=boolean,
include_extension_metadata=boolean)
print(response)


Retrieves the results of a completed query job with pagination

Method GET
Route /audit-logs/entities/queryjob-results/v1
Scope Audit: READ
PEP 8 get_audit_query_results
id query · string
Job ID from a previously created query job
offset query · integer
Starting position for pagination (default: 0)
limit query · integer
Maximum number of records to return (default: 100)
include_descriptions query · boolean
When true, includes descriptions for category and action fields (default: false)
include_extension_metadata query · boolean
When true, filters extension keys based on audit definition YAML and includes descriptions for extension keys (default: false)
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_audit_query_results(id="string",
offset=integer,
limit=integer,
include_descriptions=boolean,
include_extension_metadata=boolean)
print(response)
[
{
"action": "string",
"action_description": "string",
"action_timestamp": "string",
"actor_display_name": "string",
"actor_id": "string",
"actor_ip": "string",
"actor_type": 0,
"category": "string",
"category_description": "string",
"cid": "string",
"event_id": "string",
"event_version": "string",
"extensions": {},
"geo_city": "string",
"geo_country": "string",
"ingest_timestamp": "string",
"reason": "string",
"target_display_name": "string",
"target_id": "string",
"target_type": 0,
"user_agent": "string"
}
]


Checks the status of a previously created query job

Method GET
Route /audit-logs/entities/queryjobs/v1
Scope Audit: READ
PEP 8 poll_audit_query_status
id query · string
Job ID from a previously created query job
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Audit
falcon = Audit(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.poll_audit_query_status(id=id_list)
print(response)
[
{
"id": "string",
"status": "string",
"total_results": 0
}
]