---
title: Get account audit logs
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Audit Logs](https://developers.cloudflare.com/api/go/resources/audit_logs)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get account audit logs

client.AuditLogs.List(ctx, params) (\*V4PagePaginationArray\[[AuditLog](<https://developers.cloudflare.com/api/go/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/audit\_logs

Gets a list of audit logs for an account. Can be filtered by who made the change, on which zone, and the timeframe of the change.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Account Settings Write``Account Settings Read`

##### ParametersExpand Collapse

<details>

<summary>

params AuditLogListParams

</summary>

AccountID param.Field\[string]

Path param: Identifier

maxLength32

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

ID param.Field\[string]Optional

Query param: Finds a specific log by its ID.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20id">Link to this property</a>

<details>

<summary>

Action param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)">AuditLogListParamsAction</a>]Optional

Query param

</summary>

Type stringOptional

Filters by the action type.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action">Link to this property</a>

<details>

<summary>

Actor param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)">AuditLogListParamsActor</a>]Optional

Query param

</summary>

Email stringOptional

Filters by the email address of the actor that made the change.

formatemail

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

IP stringOptional

Filters by the IP address of the request that made the change by specific IP address or valid CIDR Range.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor">Link to this property</a>

<details>

<summary>

Before param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)">AuditLogListParamsBeforeUnion</a>]Optional

Query param: Limits the returned results to logs older than the specified date. A <code>full-date</code> that conforms to RFC3339.

</summary>

UnionTime

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

UnionTime

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before">Link to this property</a>

<details>

<summary>

Direction param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">AuditLogListParamsDirection</a>]Optional

Query param: Changes the direction of the chronological sorting.

</summary>

const AuditLogListParamsDirectionDesc <a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">AuditLogListParamsDirection</a> = "desc"

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AuditLogListParamsDirectionAsc <a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">AuditLogListParamsDirection</a> = "asc"

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction">Link to this property</a>

Export param.Field\[bool]Optional

Query param: Indicates that this request is an export of logs in CSV format.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export">Link to this property</a>

HideUserLogs param.Field\[bool]Optional

Query param: Indicates whether or not to hide user level audit logs.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20hide_user_logs">Link to this property</a>

Page param.Field\[float64]Optional

Query param: Defines which page of results to return.

minimum1

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page">Link to this property</a>

PerPage param.Field\[float64]Optional

Query param: Sets the number of results to return per page.

maximum1000

minimum1

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page">Link to this property</a>

<details>

<summary>

Since param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)">AuditLogListParamsSinceUnion</a>]Optional

Query param: Limits the returned results to logs newer than the specified date. A <code>full-date</code> that conforms to RFC3339.

</summary>

UnionTime

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

UnionTime

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since">Link to this property</a>

<details>

<summary>

Zone param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/audit_logs/methods/list#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone%20%3E%20(schema)">AuditLogListParamsZone</a>]Optional

Query param

</summary>

Name stringOptional

Filters by the name of the zone associated to the change.

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone">Link to this property</a>

</details>

[Link to this property](<#(resource)%20audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type AuditLog struct{…}

</summary>

ID stringOptional

A string that uniquely identifies the audit log.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Action AuditLogActionOptional

</summary>

Result boolOptional

A boolean that indicates if the action attempted was successful.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(property)%20result">Link to this property</a>

Type stringOptional

A short string that describes the action that was performed.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

<details>

<summary>

Actor AuditLogActorOptional

</summary>

ID stringOptional

The ID of the actor that performed the action. If a user performed the action, this will be their User ID.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20id">Link to this property</a>

Email stringOptional

The email of the user that performed the action.

formatemail

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20email">Link to this property</a>

IP stringOptional

The IP address of the request that performed the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20ip">Link to this property</a>

<details>

<summary>

Type AuditLogActorTypeOptional

The type of actor, whether a User, Cloudflare Admin, or an Automated System.

</summary>

One of the following:

const AuditLogActorTypeUser AuditLogActorType = "user"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const AuditLogActorTypeAdmin AuditLogActorType = "admin"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const AuditLogActorTypeCloudflare AuditLogActorType = "Cloudflare"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor">Link to this property</a>

Interface stringOptional

The source of the event.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20interface">Link to this property</a>

Metadata unknownOptional

An object which can lend more context to the action being logged. This is a flexible value and varies between different actions.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20metadata">Link to this property</a>

NewValue stringOptional

The new value of the resource that was modified.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20newValue">Link to this property</a>

OldValue stringOptional

The value of the resource before it was modified.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20oldValue">Link to this property</a>

<details>

<summary>

Owner AuditLogOwnerOptional

</summary>

ID stringOptional

Identifier

maxLength32

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20owner%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20owner">Link to this property</a>

<details>

<summary>

Resource AuditLogResourceOptional

</summary>

ID stringOptional

An identifier for the resource that was affected by the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource%20%3E%20(property)%20id">Link to this property</a>

Type stringOptional

A short string that describes the resource that was affected by the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource">Link to this property</a>

When TimeOptional

A UTC RFC3339 timestamp that specifies when the action being logged occured.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20when">Link to this property</a>

</details>

[Link to this property](<#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)>)

### Get account audit logs

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/audit_logs"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.AuditLogs.List(context.TODO(), audit_logs.AuditLogListParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "d5b0f326-1232-4452-8858-1089bd7168ef",
      "action": {
        "result": true,
        "type": "change_setting"
      },
      "actor": {
        "id": "f6b5de0326bb5182b8a4840ee01ec774",
        "email": "michelle@example.com",
        "ip": "198.41.129.166",
        "type": "user"
      },
      "interface": "API",
      "metadata": {
        "name": "security_level",
        "type": "firewall",
        "value": "high",
        "zone_name": "example.com"
      },
      "newValue": "low",
      "oldValue": "high",
      "owner": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353"
      },
      "resource": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "type": "zone"
      },
      "when": "2017-04-26T17:31:07Z"
    }
  ],
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "d5b0f326-1232-4452-8858-1089bd7168ef",
      "action": {
        "result": true,
        "type": "change_setting"
      },
      "actor": {
        "id": "f6b5de0326bb5182b8a4840ee01ec774",
        "email": "michelle@example.com",
        "ip": "198.41.129.166",
        "type": "user"
      },
      "interface": "API",
      "metadata": {
        "name": "security_level",
        "type": "firewall",
        "value": "high",
        "zone_name": "example.com"
      },
      "newValue": "low",
      "oldValue": "high",
      "owner": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353"
      },
      "resource": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "type": "zone"
      },
      "when": "2017-04-26T17:31:07Z"
    }
  ],
  "success": true
}
```