---
title: "POST /_system/auditlogs - Audit Logs · RUAL Documentation"
description: "Search and retrieve system audit logs (requires view_audit_logs or is_root_user permission)"
canonical: https://docs.rual.nl/cluster/api/audit-logs/system-auditlogs-post
language: en
---

# POST /_system/auditlogs

Search and retrieve system audit logs (requires view_audit_logs or is_root_user permission)

| Key | Type | Example | Description |
| --- | --- | --- | --- |
| **[authorization](https://docs.rual.nl/cluster/api#token-providing)** required | `string` | `"Bearer access_token"` | Access token |

| Key | Type | Example | Description |
| --- | --- | --- | --- |
| **count** optional | `boolean` | `4` | Return count instead of results |
| **filters** optional | `object` | {} | Additional search filters |
| **limit** optional | `integer` | `50` | Maximum number of results |
| **offset** optional | `integer` | `0` | Number of results to skip |
| **query** optional | `string` | `"example"` | Search query string |
| **sort** optional | `array` | [{}] |  |

```
[
  {
    "_meta": {
      "created": 1782166695,
      "entity": 1,
      "guid": "a23575f49d0af385314c1f02280163374297e018a692e5e4ab85eb307ebf6ebc",
      "modified": 1782166695,
      "updated": 1782166695
    },
    "action": "core_upgrades",
    "category": "modified_version",
    "data": {
      "order_guid": "a23575f49d0af385314c1f02280163374297e018a692e5e4ab85eb307ebf6ebc",
      "retries": 0
    },
    "entity": 1,
    "user": {
      "_meta": {
        "cms": 1782080295147,
        "created": 1782080295,
        "entity": 1,
        "expiry": -1,
        "guid": "a23575f49d0af385314c1f02280163374297e018a692e5e4ab85eb307ebf6ebc",
        "removed": 0,
        "ums": 1782166695813,
        "update_hash": "60e27209fa93063b5605e41605c2722ed428cae0",
        "updated": 1782166695
      },
      "firstname": "Joe",
      "lastname": "Doe",
      "username": "joe"
    }
  }
]
```

```
{
  "code": 401,
  "error": "INVALID_ACCESS_TOKEN"
}
```

| Status | Error Code | Description |
| --- | --- | --- |
| `401` | `INVALID_ACCESS_TOKEN` | Authentication required or invalid token |

| Permission | Description |
| --- | --- |
| `Bearer token` | Access token required via Authorization header, x-authtoken, x-token, query param, or cookie |
| `auditlogs_create` | Required scope: auditlogs_create |
