On This Page

Home / Stream/ Monitor Health and Metrics/ Internal Logs/access.log

access.log ​

The API Process serves the Cribl Stream UI and API. It records each request, including its status and response time, in $CRIBL_HOME/log/access.log.

Leader services keep separate access.log files under $CRIBL_HOME/log/service/. Each file records only requests handled by that service.

Use access.log when an API client, script, or UI action receives an unexpected response. Pair it with audit.log to identify the configuration change that followed the request.

To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.

Example Event ​

The following example shows a typical event in access.log. Event fields may vary depending on the process or action that generated the event.

{
  "time": "2026-03-03T19:37:55.764Z",
  "src": "10.10.4.27",
  "user": "admin",
  "method": "GET",
  "url": "/api/v1/system/info",
  "route": "/system/info",
  "group": "default",
  "status": 200,
  "message": "GET /api/v1/system/info",
  "response_time": 12,
  "requestId": "b0f2b1e0-7a1e-4a4a-9a6f-7b2f2b9d5c31"
}

Event Fields ​

The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.

FieldDescription
timeUTC time when Cribl Stream wrote the event, after completing the request.
srcClient IP address. If Cribl Stream trusts a proxy, this is the client address resolved through that proxy. Otherwise, it is the directly connected address.
userDisplay name of the signed-in user or API Credential, when available. Otherwise, the username, such as admin, or the API Credential client ID. Omitted when the request has no authentication token.
actor_typeIncluded with the value api only when the request came from an API Credential. Otherwise omitted.
methodHTTP method, such as GET or POST.
urlOriginal request URL, including any Worker Group, Pack, or App prefixes and query parameters.
routeMatched API route template. Replaces resource IDs with a placeholder, such as /system/inputs/:id. Omitted when no route matched.
groupWorker Group identified from the request URL. Omitted when the request is not scoped to a Worker Group.
packPack named in the request path. Omitted when the request is not scoped to a Pack.
statusHTTP response status code that Cribl Stream returned.
messageHTTP method and url combined, such as GET /api/v1/health.
response_timeTime from the start of request handling until the response was completed, in milliseconds.
requestIdRequest identifier. Matches the requestId in audit.log when the same request generated an audit event.
http_user_agentClient that Cribl Stream recognized. The product UI sends product-ui, an SDK sends a value such as cribl-sdk/python 0.0.43, and Cribl.Cloud infrastructure sends cribl. Omitted for other clients.
cribl_appApp named in the request. Omitted when the request is not scoped to an App.