Table of Contents

Class AuditLog

Namespace
Cloudflare.NET.AuditLogs.Models
Assembly
Cloudflare.NET.dll

Represents an audit log entry recording an action taken on account resources.

Audit logs are retained for 18 months (v1 API) or 30 days (v2 API). Use filtering parameters to narrow results when querying large datasets.

public record AuditLog : IEquatable<AuditLog>
Inheritance
AuditLog
Implements
Inherited Members

Remarks

The timestamp location differs between API versions:

  • v1 API: Uses the when field at the top level
  • v2 API: Uses action.time instead
Use the Timestamp property to get the timestamp regardless of API version.

Constructors

AuditLog(string, AuditLogAccount?, AuditLogAction, AuditLogActor, DateTime?, string?, JsonElement?, string?, string?, AuditLogOwner?, AuditLogResource?, AuditLogZone?, AuditLogRaw?)

Represents an audit log entry recording an action taken on account resources.

Audit logs are retained for 18 months (v1 API) or 30 days (v2 API). Use filtering parameters to narrow results when querying large datasets.

public AuditLog(string Id, AuditLogAccount? Account, AuditLogAction Action, AuditLogActor Actor, DateTime? When = null, string? Interface = null, JsonElement? Metadata = null, string? NewValue = null, string? OldValue = null, AuditLogOwner? Owner = null, AuditLogResource? Resource = null, AuditLogZone? Zone = null, AuditLogRaw? Raw = null)

Parameters

Id string

Unique identifier for this audit log entry.

Account AuditLogAccount

Account where the action occurred.

Action AuditLogAction

Details about the action performed.

Actor AuditLogActor

Information about who performed the action.

When DateTime?

When the action occurred (v1 API, RFC3339 timestamp). Use Timestamp for cross-version compatibility.

Interface string

Interface used for the action (e.g., "API", "UI").

Metadata JsonElement?

Additional metadata about the action.

NewValue string

New value after the action (for change operations).

OldValue string

Previous value before the action (for change operations).

Owner AuditLogOwner

Owner (account) of the resource.

Resource AuditLogResource

The resource that was acted upon.

Zone AuditLogZone

Zone context for zone-scoped actions.

Raw AuditLogRaw

Raw HTTP request details (v2 API only).

Remarks

The timestamp location differs between API versions:

  • v1 API: Uses the when field at the top level
  • v2 API: Uses action.time instead
Use the Timestamp property to get the timestamp regardless of API version.

Properties

Account

Account where the action occurred.

[JsonPropertyName("account")]
public AuditLogAccount? Account { get; init; }

Property Value

AuditLogAccount

Action

Details about the action performed.

[JsonPropertyName("action")]
public AuditLogAction Action { get; init; }

Property Value

AuditLogAction

Actor

Information about who performed the action.

[JsonPropertyName("actor")]
public AuditLogActor Actor { get; init; }

Property Value

AuditLogActor

Id

Unique identifier for this audit log entry.

[JsonPropertyName("id")]
public string Id { get; init; }

Property Value

string

Interface

Interface used for the action (e.g., "API", "UI").

[JsonPropertyName("interface")]
public string? Interface { get; init; }

Property Value

string

Metadata

Additional metadata about the action.

[JsonPropertyName("metadata")]
public JsonElement? Metadata { get; init; }

Property Value

JsonElement?

NewValue

New value after the action (for change operations).

[JsonPropertyName("newValue")]
public string? NewValue { get; init; }

Property Value

string

OldValue

Previous value before the action (for change operations).

[JsonPropertyName("oldValue")]
public string? OldValue { get; init; }

Property Value

string

Owner

Owner (account) of the resource.

[JsonPropertyName("owner")]
public AuditLogOwner? Owner { get; init; }

Property Value

AuditLogOwner

Raw

Raw HTTP request details (v2 API only).

[JsonPropertyName("raw")]
public AuditLogRaw? Raw { get; init; }

Property Value

AuditLogRaw

Resource

The resource that was acted upon.

[JsonPropertyName("resource")]
public AuditLogResource? Resource { get; init; }

Property Value

AuditLogResource

Timestamp

Gets the timestamp when the action occurred, regardless of API version. Returns When (v1 API) or Time (v2 API).

[JsonIgnore]
public DateTime Timestamp { get; }

Property Value

DateTime

When

When the action occurred (v1 API, RFC3339 timestamp). Use Timestamp for cross-version compatibility.

[JsonPropertyName("when")]
public DateTime? When { get; init; }

Property Value

DateTime?

Zone

Zone context for zone-scoped actions.

[JsonPropertyName("zone")]
public AuditLogZone? Zone { get; init; }

Property Value

AuditLogZone