Audit Log Endpoint

 

The Audit Log endpoint can be used to inspect the system audit log.

Fetch Audit Log

 
This method requires the VIEW_AUDIT_LOG permission.

This method will return summary information about the audit log, including timestamps, type codes, user id, etc.


To invoke:

GET http://localhost:9000/audit-log

You may also add the following URL parameters:

ParameterTypeRequiredDefaultDescription
moduleIdstringNoFirst available moduleThe name of the audit module
userIdintNo-The ID of the user
fromdateNo-The inclusive start range time (in FHIR dateTime format)
todateNo-The inclusive end range time (in FHIR dateTime format)
pageIndexintNo0The page number to return
pageSizeintNo100The number of rows to return per page (maximum: 10000)
usernamestringNo-Filter by username
auditActionstringNo-Filter by audit action type code
transactionGuidstringNo-Filter by transaction GUID
targetResourceIdsstringNo-Filter by target resource IDs (can be specified multiple times)

The server will produce a response resembling the following:

{
  "pageIndex": 0,
  "pageSize": 0,
  "totalRecords": 1,
  "audit-events": [
    {
      "endpointModuleId": "admin_web",
      "endpointNodeId": "Master",
      "id": 53,
      "userModuleId": "local_security",
      "userNodeId": "Master",
      "remoteAddress": "0:0:0:0:0:0:0:1",
      "timestamp": "2017-10-06T17:05:59.942-04:00",
      "typeCode": "USERMGR_CREATE_USER",
      "typeDisplay": "Create a new user",
      "typeSystem": "https://smilecdr.com/ns/CodeSystem/CdrAuditEvents",
      "familyName": "Admin",
      "givenName": "GenericUser",
      "userId": 2,
      "username": "ADMIN"
    }]

}

For brevity only 1 event is shown but a real response might contain many more.

Note the following details:

  • "typeCode": "ADMINWEB_LOGIN" – this code gives the type of audit event;

Fetch Individual Event

 
This method requires the VIEW_AUDIT_LOG permission.

This method will return the details of a given audit log, including request URL, detailed timing information, and request/response bodies for some audit types. Note this information may have special privacy and security implications so you should consider carefully before exposing this data.


To invoke (substitute an event ID into the path below):

GET http://localhost:9000/audit-log/event/{audit_event_id}

You may also add the following URL parameter:

ParameterTypeRequiredDefaultDescription
includeBodybooleanNofalseInclude the request/response body in the response

The server will produce a response resembling the following:

{
  "endpointModuleId": "admin_web",
  "endpointNodeId": "Master",
  "id": 52,
  "userModuleId": "local_security",
  "userNodeId": "Master",
  "remoteAddress": "0:0:0:0:0:0:0:1",
  "timestamp": "2017-10-06T17:05:01.898-04:00",
  "typeCode": "ADMINWEB_LOGIN",
  "typeDisplay": "Log into the Web Admin Console",
  "typeSystem": "https://smilecdr.com/ns/CodeSystem/CdrAuditEvents",
  "familyName": "Admin",
  "givenName": "GenericUser",
  "userId": 2,
  "username": "ADMIN"
}

Fetch Individual Event by Module

 
This method requires the VIEW_AUDIT_LOG permission.

This method will return the details of a given audit event from a specific audit module, including request URL, detailed timing information, and request/response bodies for some audit types. Note this information may have special privacy and security implications so you should consider carefully before exposing this data.


To invoke (substitute a module ID and event ID into the path below):

GET http://localhost:9000/audit-log/event/{moduleId}/{audit_event_id}

The following path elements are required:

ParameterTypeRequiredDescription
moduleIdstringYesThe Audit Log module ID that stores the audit records
audit_event_idlongYesThe ID of the specific audit event to retrieve

The server will produce a response resembling the following:

{
  "endpointModuleId": "admin_web",
  "endpointNodeId": "Master",
  "id": 52,
  "userModuleId": "local_security",
  "userNodeId": "Master",
  "remoteAddress": "0:0:0:0:0:0:0:1",
  "timestamp": "2017-10-06T17:05:01.898-04:00",
  "typeCode": "ADMINWEB_LOGIN",
  "typeDisplay": "Log into the Web Admin Console",
  "typeSystem": "https://smilecdr.com/ns/CodeSystem/CdrAuditEvents",
  "familyName": "Admin",
  "givenName": "GenericUser",
  "userId": 2,
  "username": "ADMIN"
}

Fetch Module IDs

 

This method returns the list of available Audit Log module IDs. This is useful for discovering which modules are configured and can be queried via the other Audit Log endpoints.

To invoke:

GET http://localhost:9000/audit-log/modules

The server will produce a response resembling the following:

["audit"]

Fetch Event Types

 

This method returns the complete list of valid audit event type codes along with their human-readable descriptions.

To invoke:

GET http://localhost:9000/audit-log/event-types

The server will produce a response resembling the following:

{
  "eventTypes" : [ {
    "code" : "ADMINWEB_LOGIN",
    "description" : "Log into the Web Admin Console"
  }, {
    "code" : "USERMGR_CREATE_USER",
    "description" : "Create a new user"
  } ]
}

For brevity only a few entries are shown; the actual response includes all available audit event type codes.

Export Audit Events as CSV

 
This method requires the VIEW_AUDIT_LOG permission.

This method exports audit events as a CSV file packaged in a ZIP archive. It accepts the same filter parameters as the Fetch Audit Log endpoint (except pagination parameters).

To invoke:

GET http://localhost:9000/audit-log/export?from=2017-01-01T00:00:00Z&to=2017-12-31T00:00:00Z

You may also add the following URL parameters:

ParameterTypeRequiredDefaultDescription
moduleIdstringNoFirst available moduleThe name of the audit module
userIdintNo-The ID of the user
fromdateNo-The inclusive start range time (in FHIR dateTime format)
todateNo-The inclusive end range time (in FHIR dateTime format)
usernamestringNo-Filter by username
auditActionstringNo-Filter by audit action type code
transactionGuidstringNo-Filter by transaction GUID
targetResourceIdsstringNo-Filter by target resource IDs (can be specified multiple times)

The server will return a response with content type application/zip containing a single CSV file named auditlog-search-results.csv.