audit.log
The API Process serves the Cribl Stream UI and API. It writes audit.log to $CRIBL_HOME/log/ and records actions on files and settings. The Leader writes every audit event.
To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.
Example Event
The following example shows a typical event in audit.log. Event fields may vary depending on the process or action that generated the event.
{
"time": "2026-03-03T19:38:02.118Z",
"action": "update",
"type": "pipelines",
"user": "admin",
"principal": "admin",
"id": "main",
"requestId": "b0f2b1e0-7a1e-4a4a-9a6f-7b2f2b9d5c31"
}Event Fields
These fields are common in this log. An event omits fields that do not apply, and it can include additional fields.
| Field | Description |
|---|---|
time | UTC time when Cribl Stream wrote the event. |
action | Operation performed, such as create, update, patch, delete, commit, or deploy. |
type | Category of the changed object, such as pipelines. The value ai-settings indicates changes on the AI Settings page. |
user | Display name of the signed-in user or API Credential, when available. Otherwise, the username or API Credential client ID. |
principal | Account that authenticated. This can differ from user when the display name and the account identifier are different. |
id | Identifier of the changed object. |
requestId | Request identifier. Matches the requestId in access.log for the same request. |
pack | Pack named in the request path. Omitted when the request is not scoped to a Pack. |
group | Worker Group recorded when a Config Helper forwarded the event. Omitted when the Leader API Process wrote the event. |
service | Name of the Leader service that forwarded the event. Omitted for events written by the Leader API Process or a Config Helper. |
name | Name of the changed object, when it has a name separate from id. A Route change includes the Route name. |
oldIdx | Previous position of the object. Present on a reorder. |
newIdx | New position of the object. Present on a reorder. |
outcome | Result of the action, such as success or failure. Omitted when the event does not record a result. |
reason | Explanation recorded with the action. Present when the event includes a failure or limit. |