ui-access.log
The API Process serves the Cribl Stream UI and API. It writes ui-access.log to $CRIBL_HOME/log/ and records interactions with UI pages as URLs, such as /settings/apidocs or /dashboard/logs.
Use ui-access.log to correlate a user’s path through the UI with the API requests in access.log and the changes in audit.log.
To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.
Example Event
The following example shows a typical event in ui-access.log. Event fields may vary depending on the process or action that generated the event.
{
"time": "2026-03-03T19:37:50.402Z",
"url": "/dashboard/logs",
"user": "admin",
"src": "10.10.4.27",
"http_user_agent": "Mozilla/5.0"
}Event Fields
The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.
| Field | Description |
|---|---|
time | UTC time of the UI interaction, as reported by the page. |
url | UI path that the user opened, such as /dashboard/logs. |
user | Display name of the signed-in user, when available. Otherwise, the username. Omitted when the request has no authentication token. |
actor_type | Included with the value api only when the request came from an API Credential. Otherwise omitted. |
src | Client IP address of the connection that reported the page view. |
http_user_agent | Browser or other client that opened the page. |