access.log
The API Process serves the Cribl Stream UI and API. It records each request, including its status and response time, in $CRIBL_HOME/log/access.log.
Leader services keep separate access.log files under $CRIBL_HOME/log/service/. Each file records only requests handled by that service.
Use access.log when an API client, script, or UI action receives an unexpected response. Pair it with audit.log to identify the configuration change that followed the request.
To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.
Example Event
The following example shows a typical event in access.log. Event fields may vary depending on the process or action that generated the event.
{
"time": "2026-03-03T19:37:55.764Z",
"src": "10.10.4.27",
"user": "admin",
"method": "GET",
"url": "/api/v1/system/info",
"route": "/system/info",
"group": "default",
"status": 200,
"message": "GET /api/v1/system/info",
"response_time": 12,
"requestId": "b0f2b1e0-7a1e-4a4a-9a6f-7b2f2b9d5c31"
}Event Fields
The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.
| Field | Description |
|---|---|
time | UTC time when Cribl Stream wrote the event, after completing the request. |
src | Client IP address. If Cribl Stream trusts a proxy, this is the client address resolved through that proxy. Otherwise, it is the directly connected address. |
user | Display name of the signed-in user or API Credential, when available. Otherwise, the username, such as admin, or the API Credential client ID. Omitted when the request has no authentication token. |
actor_type | Included with the value api only when the request came from an API Credential. Otherwise omitted. |
method | HTTP method, such as GET or POST. |
url | Original request URL, including any Worker Group, Pack, or App prefixes and query parameters. |
route | Matched API route template. Replaces resource IDs with a placeholder, such as /system/inputs/:id. Omitted when no route matched. |
group | Worker Group identified from the request URL. Omitted when the request is not scoped to a Worker Group. |
pack | Pack named in the request path. Omitted when the request is not scoped to a Pack. |
status | HTTP response status code that Cribl Stream returned. |
message | HTTP method and url combined, such as GET /api/v1/health. |
response_time | Time from the start of request handling until the response was completed, in milliseconds. |
requestId | Request identifier. Matches the requestId in audit.log when the same request generated an audit event. |
http_user_agent | Client that Cribl Stream recognized. The product UI sends product-ui, an SDK sends a value such as cribl-sdk/python 0.0.43, and Cribl.Cloud infrastructure sends cribl. Omitted for other clients. |
cribl_app | App named in the request. Omitted when the request is not scoped to an App. |