On This Page

Home / Stream/ Monitor Health and Metrics/ Internal Logs/audit.log

audit.log ​

The API Process serves the Cribl Stream UI and API. It writes audit.log to $CRIBL_HOME/log/ and records actions on files and settings. The Leader writes every audit event.

To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.

Example Event ​

The following example shows a typical event in audit.log. Event fields may vary depending on the process or action that generated the event.

{
  "time": "2026-03-03T19:38:02.118Z",
  "action": "update",
  "type": "pipelines",
  "user": "admin",
  "principal": "admin",
  "id": "main",
  "requestId": "b0f2b1e0-7a1e-4a4a-9a6f-7b2f2b9d5c31"
}

Event Fields ​

These fields are common in this log. An event omits fields that do not apply, and it can include additional fields.

FieldDescription
timeUTC time when Cribl Stream wrote the event.
actionOperation performed, such as create, update, patch, delete, commit, or deploy.
typeCategory of the changed object, such as pipelines. The value ai-settings indicates changes on the AI Settings page.
userDisplay name of the signed-in user or API Credential, when available. Otherwise, the username or API Credential client ID.
principalAccount that authenticated. This can differ from user when the display name and the account identifier are different.
idIdentifier of the changed object.
requestIdRequest identifier. Matches the requestId in access.log for the same request.
packPack named in the request path. Omitted when the request is not scoped to a Pack.
groupWorker Group recorded when a Config Helper forwarded the event. Omitted when the Leader API Process wrote the event.
serviceName of the Leader service that forwarded the event. Omitted for events written by the Leader API Process or a Config Helper.
nameName of the changed object, when it has a name separate from id. A Route change includes the Route name.
oldIdxPrevious position of the object. Present on a reorder.
newIdxNew position of the object. Present on a reorder.
outcomeResult of the action, such as success or failure. Omitted when the event does not record a result.
reasonExplanation recorded with the action. Present when the event includes a failure or limit.