LaserData Cloud
API Reference

Audit

Read tenant audit records and the resource details attached to each event

API Variables
ld-api-key
{tenant_id}

Set variables to auto-fill all examples and run requests in-browser.

Audit in the Console records tenant activity. Use these endpoints through the main API at https://api.laserdata.cloud for programmatic access. Records are appended without changing earlier entries.

These requests require audit:read.

Event Types

List Audit Event Types

GET
/audit/types

List all supported audit event type identifiers.

bash
curl https://api.laserdata.cloud/audit/types \
-H "ld-api-key: YOUR_API_KEY"

Audit Log

Query Tenant Audit Log

GET
/audit/tenants/{tenant_id}

Query the full audit log for a tenant, with filtering and pagination.

bash
curl "https://api.laserdata.cloud/audit/tenants/{tenant_id}?page=1&results=10" \
-H "ld-api-key: YOUR_API_KEY"
{
  "items": [
    {
      "type": "deployment_created",
      "name": "Deployment Created",
      "author": { "id": 608123456789012345, "name": "Jane Smith" },
      "api_key": { "id": 67890, "name": "ci-deploy-key" },
      "user": null,
      "division": { "id": 615380456123456790, "name": "Platform Engineering" },
      "environment": { "id": 615380456123456791, "name": "production" },
      "deployment": { "id": 611298765432109056, "name": "events-prod" },
      "data": {
        "cloud": "aws",
        "area": "us",
        "region": "us-east-1",
        "variant": "managed",
        "tier": "large",
        "cluster_kind": "standalone",
        "public_ip": "static",
        "storage_type": "network_balanced",
        "storage_size": 500,
        "target_network_tput": 10000,
        "encrypted": true,
        "protected": true,
        "retention": { "telemetry": { "logs_days": 90, "metrics_days": 90, "heartbeats_days": 90 } },
        "code": "abc123",
        "name": "events-prod",
        "domain": "events-prod-abc123.laserdata.cloud",
        "nodes": [
          {
            "id": 610809900976570889,
            "name": "node-1",
            "image_id": "ami-0abc123",
            "variant": "ubuntu_x64",
            "storage_type": "network_balanced"
          }
        ]
      },
      "correlation_id": "8f4a2b6c9d1e4f3a8b5c7d9e0f1a2b3c",
      "timestamp": "2025-01-15T10:30:00Z"
    }
  ],
  "page": 1,
  "total_results": 1,
  "total_pages": 1
}

Entries use the SDK's TenantAuditInfo structure:

FieldDescription
typeEvent type slug (e.g. deployment_created, member_invited, access_rule_added)
nameHuman-readable label for the event type
authorThe human who triggered the action. {id, name} or null for system events. Always set when an interactive session or an API key is involved (the user that owns the key).
api_keyThe API key that authored the call when the action came from automation. Omitted for actions taken from an interactive Console session. {id, name}. Lets you tell direct user activity apart from key-driven activity for SOC 2 / ISO machine-identity tracking.
userThe user the action was performed on (member operations, role assignments). null when not applicable
division / environment / deploymentResource scope. Each is {id, name} or null depending on what the event touches
dataEvent-type-specific payload. Shape varies per event (see below). Can be null for events without an extra payload
correlation_idUUID linking this event to others triggered by the same request or workflow. null if untracked
timestampISO 8601 time when the event was recorded

data contains event-specific details:

  • deployment_created records {cloud, area, region, variant, tier, cluster_kind, public_ip, storage_type, storage_size, target_network_tput?, encrypted, protected, retention, code, name, domain?, nodes[]}. Each node includes id, name, image_id, variant, storage_type.
  • deployment_upgraded records {from_tier, to_tier, from_storage, to_storage}.
  • deployment_deleted records {name, code, reason?}.
  • access_rule_added and access_rule_deleted record {cidrs, description?, rules}, including protocol toggles.
  • member_invited records {email, roles}.
  • api_key_created and api_key_deleted record {name, role_id, division_id?}.
  • config_activated records {config_id, kind, name, version}.
  • connector_activated and connector_deleted record {connector_type, connector_key, instance_key, instance_id, version}. connector_type is source or sink. connector_key identifies the catalog plugin, and instance_key is its deployment-specific hyphenated name. instance_id is numeric, and version is the plugin SemVer. The owning deployment, environment, and division appear in the top-level scope fields.

Use /audit/types to retrieve the complete event-type list for your tenant.

Query ParameterDescription
pagePage number
resultsItems per page (max 100)
fromStart time (ISO 8601)
toEnd time (ISO 8601)
userFilter by subject user id
authorFilter by acting user id
api_keyFilter by API key id (only events authored via that key)
divisionFilter by division id
environmentFilter by environment id
deploymentFilter by deployment id
typesComma-separated list of event types to include
correlation_idFind all events sharing a correlation UUID

On this page