Home / API Documentation / Platform management / Auditing / Query audit

Query audit

Requests

HTTP request

GET /v1/kubernetes-audits

List audits based on user specified conditions

Query parameters

Name Type Required Description
start_time number Truetimestamp of start time range
end_time number Truetimestamp of end time range
size number Truepage size
pageno number Truerequest page number
cluster string Truename of cluster
scope string Falsescope of audit, choices: all, user, system
user_name string FalseUsername of audit creator
resource_name string Falsename of audit target object
resourcce_type string Falsekind of audit target object
operation_type string Falseoperation types, create, update, delete and so on
scope string Falsescope of audit, choices: all, user, system
source_ip string Falseip address of source audit request
response_status string Falseresponse status, choices: Success, Failure

Responses

Content-Type application/json

Status code: 200

OK

Sample response

List of audit objects

{
   "Items": [
     {
       "Annotations": null,
       "AuditID": "4f7f7b44-2b0c-471c-940b-e8bf19ec893e",
       "Cluster": "global",
       "ImpersonatedUser": null,
       "Level": "RequestResponse",
       "ObjectRef": {
         "APIGroup": "auth.alauda.io",
         "APIVersion": "v1",
         "Name": "admin@cpaas.io",
         "Namespace": "",
         "Resource": "users",
         "ResourceVersion": "",
         "Subresource": "",
         "UID": ""
       },
       "ReferObject": "admin@cpaas.io",
       "RequestObject": {},
       "RequestReceivedTimestamp": "2022-02-07T09:48:05.342650Z",
       "RequestURI": "/api/v1/token/callback?code=hsq2jd345albkglro4uxsdevji2dk6w5wimkljir7aedsga4wtm\u0026state=alauda-console",
       "ResponseObject": {
         "Access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImU4N2QzY2I5MmRmOTQzZTY1MThmODk3ODljMGVlZWJiOTA2MjQxZjgifQ.eyJpc3MiOiJodHRwczovLzE5Mi4xNjguMTMwLjEzNi9kZXgiLCJzdWIiOiJDaVF3T0dFNE5qZzBZaTFrWWpnNExUUmlOek10T1RCaE9TMHpZMlF4TmpZeFpqVTBOallTQld4dlkyRnMiLCJhdWQiOiJhbGF1ZGEtYXV0aCIsImV4cCI6MTY0NDMxMzY4NSwiaWF0IjoxNjQ0MjI3Mjg1LCJub25jZSI6ImFsYXVkYS1jb25zb2xlIiwiYXRfaGFzaCI6Ik0yUVV5WnIzUGlsZkY4SFAtTHlfdUEiLCJlbWFpbCI6ImFkbWluQGNwYWFzLmlvIiwiZW1haWxfdmVyaWZpZWQiOnRydWUsIm5hbWUiOiJhZG1pbiIsInByZWZlcnJlZF91c2VybmFtZSI6ImFkbWluQGNwYWFzLmlvIiwiZXh0Ijp7ImlzX2FkbWluIjp0cnVlLCJjb25uX2lkIjoibG9jYWwifX0.e9DCAu8kDUPfyUSidmEwU77kfyXl7bD3qDLUPcUKgyrEyTAXk51Az23234x9HVaY3fJQPtcDvexCch5T0WbYWcrVvvk5L0ipWPH5RV1G4HT4zJcSemAPSI3t16t9RGeaOW8se5D2BNhiTEt11KXW6Ybs2wTBSrF6nlkb8t0Nz2pqOEvrB5D05jLftaBpEzQ6PgdjZfL_p0UeHnXh-cw1_fq5P1BSIi8VQbha0cDMV9yOaTk4hhMELeYZB8rGY526_IZcJJWwp7liHngWanx9FSK7oXlvttPXp2zc27YyecHLotm0XrE-EhWD6iWTsCEM_SL5BuXisJgItUzFdImr2A",
         "Expire_at": "2022-02-08T09:48:05Z",
         "Id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImU4N2QzY2I5MmRmOTQzZTY1MThmODk3ODljMGVlZWJiOTA2MjQxZjgifQ.eyJpc3MiOiJodHRwczovLzE5Mi4xNjguMTMwLjEzNi9kZXgiLCJzdWIiOiJDaVF3T0dFNE5qZzBZaTFrWWpnNExUUmlOek10T1RCaE9TMHpZMlF4TmpZeFpqVTBOallTQld4dlkyRnMiLCJhdWQiOiJhbGF1ZGEtYXV0aCIsImV4cCI6MTY0NDMxMzY4NSwiaWF0IjoxNjQ0MjI3Mjg1LCJub25jZSI6ImFsYXVkYS1jb25zb2xlIiwiYXRfaGFzaCI6IlFIc0Z4UDZ1Z3ljV2R1dDlOcFU4UUEiLCJjX2hhc2giOiJkVUZIRVFsalNsaG5tZXBjOVhoU1FnIiwiZW1haWwiOiJhZG1pbkBjcGFhcy5pbyIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJuYW1lIjoiYWRtaW4iLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJhZG1pbkBjcGFhcy5pbyIsImV4dCI6eyJpc19hZG1pbiI6dHJ1ZSwiY29ubl9pZCI6ImxvY2FsIn19.x4wnB15BtFJCl6ncV8Ddp164xOlhMcZOTmU75Rr077yPJWUt9U6XYycJEPRLDNhtw5usB-67R4TNL9ydAqD54a8fJRh_YUtnjQAqoNGNnwH-bw-zepfS88B0ENUHrwbKfGvUe7btk29aJW_II3gSDwCcM1YArxHD6vFzbHtVKlfHM4vL5_9k0Z4TM49sli6ZNKbIKD_cp7EbxJ_1miRJrywk4Tv99HqA17vVIIEKX8ybQL0gSiAek8spBDKN3ar8ZNRr0Kerse219wgHNTLBcCvwobsaIvIDVyf-Dw9Oj8yZg95veYqeLtnJtRGH8XAe1kmgpDmNrr6JV9p8OkSjXg",
         "Issued_at": "2022-02-07T09:48:05Z",
         "Refresh_token": "CjNvbnhyd280cXRqa2w2M2dsNnRldHd6YTdtNmhhcTJyNGM1empscHFwbmp5bDdlbmpiYzQSM3VnbWk3Y2d3eG1tc2ZwZHB5ZDV6a282YnIyank2aHozNGlia2xtNWZ6anJ6aGY0ZWFoZQ",
         "Token_type": "bearer"
       },
       "ResponseStatus": {
         "code": 200,
         "metadata": {},
         "status": "Success"
       },
       "SourceIPs": [
         "60.9.140.26",
         "10.0.128.88"
       ],
       "Stage": "ResponseComplete",
       "StageTimestamp": "2022-02-07T09:48:05.612652Z",
       "User": {
         "username": "admin@cpaas.io"
       },
       "UserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.15.776.507 Safari/537.36",
       "Verb": "login"
     }
   ],
   "apiVersion": "audit.k8s.io/v1",
   "kind": "EventList",
   "total_items": 1,
   "total_page": 1
 }

Parameters

Name Type Description
Items array items
Path: Items
Items[] object Audit object holding the info
Path: Items[]
Items[].Annotations object Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. More info: http://kubernetes.io/docs/user-guide/annotations
Path: Items[].Annotations
Items[].AuditID string Unique audit ID, generated for each request.
Path: Items[].AuditID
Items[].Cluster string The name of the cluster which the object belongs to.
Path: Items[].Cluster
Items[].ImpersonatedUser object UserInfo holds the information about the user needed to implement the user.Info interface.
Path: Items[].ImpersonatedUser
Items[].Level string Level defines the amount of information logged during auditing.
Path: Items[].Level
Items[].ObjectRef object ObjectReference contains enough information to let you inspect or modify the referred object.
Path: Items[].ObjectRef
Items[].ReferObject string The name of ObjectRef.
Path: Items[].ReferObject
Items[].RequestReceivedTimestamp string (date-time) Time is a wrapper around time.Time which supports correct marshaling to YAML and JSON. Wrappers are provided for many of the factory methods that the time package offers.
Path: Items[].RequestReceivedTimestamp
Items[].RequestURI string RequestURI is the request URI as sent by the client to a server.
Path: Items[].RequestURI
Items[].ResponseStatus object Status is a return value for calls that don't return other objects.
Path: Items[].ResponseStatus
ResponseStatus.code integer (int32) Suggested HTTP return code for this status, 0 if not set.
Path: Items[].ResponseStatus.code
ResponseStatus.metadata object ListMeta describes metadata that synthetic resources must have, including lists and various status objects. A resource may have only one of {ObjectMeta, ListMeta}.
Path: Items[].ResponseStatus.metadata
ResponseStatus.status string Status of the operation. One of: "Success" or "Failure". More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
Path: Items[].ResponseStatus.status
Items[].Stage string Stage of the request handling when this event instance was generated.
Path: Items[].Stage
Items[].StageTimestamp string (date-time) Time is a wrapper around time.Time which supports correct marshaling to YAML and JSON. Wrappers are provided for many of the factory methods that the time package offers.
Path: Items[].StageTimestamp
Items[].User object UserInfo holds the information about the user needed to implement the user.Info interface.
Path: Items[].User
User.username string The name that uniquely identifies this user among all active users.
Path: Items[].User.username
Items[].UserAgent string UserAgent records the user agent string reported by the client.
Path: Items[].UserAgent
Items[].Verb string Verb is the kubernetes verb associated with the request.
Path: Items[].Verb

Other status codes