Help Center/ SecMaster/ API Reference/ API/ Playbook Instance Management/ Querying Playbook Instance Audit Logs
Updated on 2024-12-25 GMT+08:00

Querying Playbook Instance Audit Logs

Function

Querying Playbook Instance Audit Logs

Calling Method

For details, see Calling APIs.

URI

POST /v1/{project_id}/workspaces/{workspace_id}/soc/playbooks/instances/auditlogs

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Project ID.

workspace_id

Yes

String

Workspace ID

Table 2 Query Parameters

Parameter

Mandatory

Type

Description

offset

Yes

Long

offset

limit

Yes

Long

limit

sort_key

No

String

sort_key

sort_dir

No

String

sort_dir. asc, desc

Request Parameters

Table 3 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

User token.

It can be obtained by calling the IAM API used to obtain a user token. The value of X-Subject-Token in the response header is a token.

content-type

Yes

String

application/json;charset=UTF-8

Table 4 Request body parameters

Parameter

Mandatory

Type

Description

instance_type

No

String

Instance type (AOP_WORKFLOW for workflows, SCRIPT for scripts, and PLAYBOOK for playbooks).

action_id

No

String

Workflow ID.

action_name

No

String

Workflow name.

instance_id

No

String

Instance ID.

parent_instance_id

No

String

Instance ID of the parent node.

log_level

No

String

Log Level

input

No

String

Input.

output

No

String

Output.

error_msg

No

String

Error Message

start_time

No

String

Start time.

end_time

No

String

End time.

status

No

String

Status. (RUNNING, FINISHED, FAILED, RETRYING, and TERMINATED)

trigger_type

No

String

Triggering type. TIMER indicates scheduled triggering, and EVENT indicates event triggering.

Response Parameters

Status code: 200

Table 5 Response header parameters

Parameter

Type

Description

X-request-id

String

Request ID, in the format request_uuid-timestamp-hostname.

Table 6 Response body parameters

Parameter

Type

Description

count

Integer

Total records.

audit_logs

Array of AuditLogInfo objects

Review response list.

Table 7 AuditLogInfo

Parameter

Type

Description

instance_type

String

Instance type (AOP_WORKFLOW for workflows, SCRIPT for scripts, and PLAYBOOK for playbooks).

action_id

String

Workflow ID.

action_name

String

Workflow name.

instance_id

String

Instance ID.

parent_instance_id

String

Instance ID of the parent node.

log_level

String

Log Level

input

String

Input.

output

String

Output.

error_msg

String

Error Message

start_time

String

Start time.

end_time

String

End time.

status

String

Status. (RUNNING, FINISHED, FAILED, RETRYING, and TERMINATED)

trigger_type

String

Triggering type. TIMER indicates scheduled triggering, and EVENT indicates event triggering.

Status code: 400

Table 8 Response header parameters

Parameter

Type

Description

X-request-id

String

Request ID, in the format request_uuid-timestamp-hostname.

Table 9 Response body parameters

Parameter

Type

Description

code

String

Error Code

message

String

Error Description

Example Requests

Query playbook instance review logs. Details - Instance type - APP, AOP_WORKFLOW, SCRIPT, PLAYBOOK, TASK, DEBUG; Workflow ID - 909494e3-558e-46b6-a9eb-07a8e18ca62f; Workflow name - DisabledIp; Instance ID - 909494e3-558e-46b6-a9eb-07a8e18ca62f; Parent instance ID - 909494e3-558e-46b6-a9eb-07a8e18ca62f; Log level - DEBUG, INFO WARN; Input - input; Output - output; Error message - error_msg. Start time - 2021-01-30 23:00:00;End time - 2021-01-31 23:00:00; Status - CREATED, RUNNING, FINISHED, RETRYING, TERMINATING, TERMINATED, FAILED Trigger type - DEBUG, TIMER, EVENT, or MANUAL.

{
  "instance_type" : "APP, AOP_WORKFLOW, SCRIPT, PLAYBOOK, TASK, DEBUG",
  "action_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
  "action_name" : "DisabledIp",
  "instance_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
  "parent_instance_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
  "log_level" : "DEBUG INFO WARN",
  "input" : "input",
  "output" : "output",
  "error_msg" : "error_msg",
  "start_time" : "2021-01-30T23:00:00Z",
  "end_time" : "2021-01-31T23:00:00Z",
  "status" : "CREATED, RUNNING, FINISHED, RETRYING, TERMINATING, TERMINATED, FAILED",
  "trigger_type" : "DEBUG, TIMER, EVENT, MANUAL"
}

Example Responses

Status code: 200

Response when the request is successful.

{
  "count" : 41,
  "audit_logs" : [ {
    "instance_type" : "APP, AOP_WORKFLOW, SCRIPT, PLAYBOOK, TASK, DEBUG",
    "action_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
    "action_name" : "DisabledIp",
    "instance_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
    "parent_instance_id" : "909494e3-558e-46b6-a9eb-07a8e18ca62f",
    "log_level" : "DEBUG INFO WARN",
    "input" : "input",
    "output" : "output",
    "error_msg" : "error_msg",
    "start_time" : "2021-01-30T23:00:00Z",
    "end_time" : "2021-01-31T23:00:00Z",
    "status" : "CREATED, RUNNING, FINISHED, RETRYING, TERMINATING, TERMINATED, FAILED",
    "trigger_type" : "DEBUG, TIMER, EVENT, MANUAL"
  } ]
}

Status Codes

Status Code

Description

200

Response when the request is successful.

400

Response when the request failed.

Error Codes

See Error Codes.