Audit Log Data :: Kloudfuse Docs
Audit Log Data
Audit logs capture authentication and authorization mutation events on the Kloudfuse platform. Each entry is a JSON object whose fields are indexed as Facets.
Finding Audit Logs
You can find audit logs using either filter:
| Filter |
What it selects |
source="kf-audit-log" |
All audit log entries across all services |
audit_log="true" |
Equivalent; matches the raw field written into each log entry |
Use source="kf-audit-log" as the base filter for all audit queries.
Events Captured
Audit logs record mutation and authentication events. Read-only operations and queries are not recorded.
action value |
Trigger |
logged in |
Successful login via SSO or basic auth |
logged out |
User-initiated logout |
user locked |
Failed login attempt on a locked account |
federation.join |
A remote cluster joined the federation |
Authentication events
action value |
Trigger |
create |
A user account was created (resource_type: user) |
update |
A user account was modified, including query priority changes |
delete |
A user account was deleted |
User management events
action value |
Trigger |
create |
A group was created (resource_type: group) |
update |
A group was modified |
delete |
A group was deleted |
add_user_to_group |
A user was added to a group |
remove_user_from_group |
A user was removed from a group |
Group management events
action value |
Trigger |
create |
A service account was created (resource_type: service_account) |
update |
A service account was modified |
delete |
A service account was deleted |
create_token |
A service account token was issued |
delete_token |
A service account token was revoked |
Service account events
action value |
Trigger |
create |
A policy was created (resource_type: policy) |
update |
A policy was modified |
delete |
A policy was deleted |
create_mapping |
A policy was mapped to an entity |
delete_mapping |
A policy mapping was removed |
authorization_failure |
A request was denied because the caller lacked sufficient permissions |
Policy and authorization events
action value |
Trigger |
create / update |
A folder permission mapping was created or updated (resource_type: folder_mapping) |
delete_mapping |
A folder permission mapping was removed |
DeleteFolder |
A dashboard folder was deleted |
Facets
All audit log fields are indexed as Facets and appear in the Facets panel on the left side of the Logs UI. Clicking a facet value adds it immediately as a filter to the current query.
| Facet |
Type |
Values / Notes |
action |
string |
logged in, logged out, user locked, create, update, delete, add_user_to_group, remove_user_from_group, create_token, delete_token, create_mapping, delete_mapping, authorization_failure, DeleteFolder, federation.join |
user_email |
string |
Email address of the user who performed the action |
role |
string |
admin or editor |
resource_type |
string |
auth, user, group, service_account, policy, policy_mapping, folder_mapping, class_default |
resource_name |
string |
Human-readable name of the affected resource — user email, group name, policy name, and so on |
status |
string |
success or failure |
error_code |
string |
HTTP status code on failure (for example 403); none on success |
duration_ms |
integer |
How long the operation took in milliseconds |
All Log Fields
In addition to the facets above, each audit log entry carries the following fields in the log body:
| Field |
Type |
Description |
resource_id |
string |
Unique ID of the affected resource; falls back to resource_name when no distinct ID exists |
user_id |
string |
Internal ID of the acting user |
user_agent |
string |
HTTP User-Agent of the calling client |
request_id |
string |
Unique request identifier for cross-service correlation |
error_message |
string |
Error detail on failure; none on success |
args |
string |
Additional context for the operation (varies by action type) |