---
title: Get user audit logs
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[User](https://developers.cloudflare.com/api/python/resources/user)

[Audit Logs](https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get user audit logs

user.audit\_logs.list(AuditLogListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[AuditLog](<https://developers.cloudflare.com/api/python/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)>)]

GET/user/audit\_logs

Gets a list of audit logs for a user account. Can be filtered by who made the change, on which zone, and the timeframe of the change.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Account Settings Write``Account Settings Read`

##### ParametersExpand Collapse

id: Optional\[str]

Finds a specific log by its ID.

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20id%20%3E%20(schema)>)

<details>

<summary>

action: Optional\[<a href="https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs/methods/list#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)">Action</a>]

</summary>

type: Optional\[str]

Filters by the action type.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)>)

<details>

<summary>

actor: Optional\[<a href="https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs/methods/list#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)">Actor</a>]

</summary>

email: Optional\[str]

Filters by the email address of the actor that made the change.

formatemail

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

ip: Optional\[str]

Filters by the IP address of the request that made the change by specific IP address or valid CIDR Range.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20actor%20%3E%20(schema)>)

<details>

<summary>

before: Optional\[Union\[Union\[null, null], Union\[str, datetime]]]

Limits the returned results to logs older than the specified date. A <code>full-date</code> that conforms to RFC3339.

</summary>

One of the following:

Union\[null, null]

Limits the returned results to logs older than the specified date. A <code>full-date</code> that conforms to RFC3339.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

Union\[str, datetime]

Limits the returned results to logs older than the specified date. A <code>date-time</code> that conforms to RFC3339.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20before%20%3E%20(schema)>)

<details>

<summary>

direction: Optional\[Literal\["desc", "asc"]]

Changes the direction of the chronological sorting.

</summary>

One of the following:

"desc"

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"asc"

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)>)

export: Optional\[[bool](<https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs/methods/list#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)>)]

Indicates that this request is an export of logs in CSV format.

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)>)

hide\_user\_logs: Optional\[[bool](<https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs/methods/list#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20hide_user_logs%20%3E%20(schema)>)]

Indicates whether or not to hide user level audit logs.

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20hide_user_logs%20%3E%20(schema)>)

page: Optional\[float]

Defines which page of results to return.

minimum1

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page%20%3E%20(schema)>)

per\_page: Optional\[float]

Sets the number of results to return per page.

maximum1000

minimum1

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page%20%3E%20(schema)>)

<details>

<summary>

since: Optional\[Union\[Union\[null, null], Union\[str, datetime]]]

Limits the returned results to logs newer than the specified date. A <code>full-date</code> that conforms to RFC3339.

</summary>

One of the following:

Union\[null, null]

Limits the returned results to logs newer than the specified date. A <code>full-date</code> that conforms to RFC3339.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

Union\[str, datetime]

Limits the returned results to logs newer than the specified date. A <code>date-time</code> that conforms to RFC3339.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)>)

<details>

<summary>

zone: Optional\[<a href="https://developers.cloudflare.com/api/python/resources/user/subresources/audit_logs/methods/list#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone%20%3E%20(schema)">Zone</a>]

</summary>

name: Optional\[str]

Filters by the name of the zone associated to the change.

<a href="#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.audit_logs%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class AuditLog: …

</summary>

id: Optional\[str]

A string that uniquely identifies the audit log.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

action: Optional\[Action]

</summary>

result: Optional\[bool]

A boolean that indicates if the action attempted was successful.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(property)%20result">Link to this property</a>

type: Optional\[str]

A short string that describes the action that was performed.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

<details>

<summary>

actor: Optional\[Actor]

</summary>

id: Optional\[str]

The ID of the actor that performed the action. If a user performed the action, this will be their User ID.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20id">Link to this property</a>

email: Optional\[str]

The email of the user that performed the action.

formatemail

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20email">Link to this property</a>

ip: Optional\[str]

The IP address of the request that performed the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20ip">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["user", "admin", "Cloudflare"]]

The type of actor, whether a User, Cloudflare Admin, or an Automated System.

</summary>

One of the following:

"user"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"admin"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"Cloudflare"

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20actor">Link to this property</a>

interface: Optional\[str]

The source of the event.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20interface">Link to this property</a>

metadata: Optional\[object]

An object which can lend more context to the action being logged. This is a flexible value and varies between different actions.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20metadata">Link to this property</a>

new\_value: Optional\[str]

The new value of the resource that was modified.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20newValue">Link to this property</a>

old\_value: Optional\[str]

The value of the resource before it was modified.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20oldValue">Link to this property</a>

<details>

<summary>

owner: Optional\[Owner]

</summary>

id: Optional\[str]

Identifier

maxLength32

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20owner%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20owner">Link to this property</a>

<details>

<summary>

resource: Optional\[Resource]

</summary>

id: Optional\[str]

An identifier for the resource that was affected by the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource%20%3E%20(property)%20id">Link to this property</a>

type: Optional\[str]

A short string that describes the resource that was affected by the action.

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20resource">Link to this property</a>

when: Optional\[datetime]

A UTC RFC3339 timestamp that specifies when the action being logged occured.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)%20%3E%20(property)%20when">Link to this property</a>

</details>

[Link to this property](<#(resource)%20%24shared%20%3E%20(model)%20audit_log%20%3E%20(schema)>)

### Get user audit logs

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
page = client.user.audit_logs.list()
page = page.result[0]
print(page.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "d5b0f326-1232-4452-8858-1089bd7168ef",
      "action": {
        "result": true,
        "type": "change_setting"
      },
      "actor": {
        "id": "f6b5de0326bb5182b8a4840ee01ec774",
        "email": "michelle@example.com",
        "ip": "198.41.129.166",
        "type": "user"
      },
      "interface": "API",
      "metadata": {
        "name": "security_level",
        "type": "firewall",
        "value": "high",
        "zone_name": "example.com"
      },
      "newValue": "low",
      "oldValue": "high",
      "owner": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353"
      },
      "resource": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "type": "zone"
      },
      "when": "2017-04-26T17:31:07Z"
    }
  ],
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "d5b0f326-1232-4452-8858-1089bd7168ef",
      "action": {
        "result": true,
        "type": "change_setting"
      },
      "actor": {
        "id": "f6b5de0326bb5182b8a4840ee01ec774",
        "email": "michelle@example.com",
        "ip": "198.41.129.166",
        "type": "user"
      },
      "interface": "API",
      "metadata": {
        "name": "security_level",
        "type": "firewall",
        "value": "high",
        "zone_name": "example.com"
      },
      "newValue": "low",
      "oldValue": "high",
      "owner": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353"
      },
      "resource": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "type": "zone"
      },
      "when": "2017-04-26T17:31:07Z"
    }
  ],
  "success": true
}
```