---
title: "POST /_system/auditrequests - Audit Logs · RUAL Documentation"
description: "Search and retrieve system audit requests (requires view_audit_logs or is_root_user permission)"
canonical: https://docs.rual.nl/cluster/api/audit-logs/system-auditrequests-post
language: en
---

# POST /_system/auditrequests

Search and retrieve system audit requests (requires view_audit_logs or is_root_user permission)

| Key | Type | Example | Description |
| --- | --- | --- | --- |
| **[authorization](https://docs.rual.nl/cluster/api#token-providing)** required | `string` | `"Bearer access_token"` | Access token |

| Key | Type | Example | Description |
| --- | --- | --- | --- |
| **count** optional | `boolean` | `4` | Return count instead of results |
| **filters** optional | `object` | {} | Additional search filters |
| **limit** optional | `integer` | `50` | Maximum number of results |
| **offset** optional | `integer` | `0` | Number of results to skip |
| **query** optional | `string` | `"example"` | Search query string |
| **sort** optional | `array` | [{}] |  |

```
[
  {
    "_meta": {
      "created": 1782166695,
      "entity": 1,
      "guid": "a23575f49d0af385314c1f02280163374297e018a692e5e4ab85eb307ebf6ebc",
      "modified": 1782166695,
      "updated": 1782166695
    },
    "duration": 12.5,
    "ip_address": "192.168.1.100",
    "method": "GET",
    "path": "/api/v1/users/search",
    "status_code": 200,
    "user": {
      "_meta": {
        "cms": 1782080295147,
        "created": 1782080295,
        "entity": 1,
        "expiry": -1,
        "guid": "a23575f49d0af385314c1f02280163374297e018a692e5e4ab85eb307ebf6ebc",
        "removed": 0,
        "ums": 1782166695813,
        "update_hash": "60e27209fa93063b5605e41605c2722ed428cae0",
        "updated": 1782166695
      },
      "username": "joe"
    },
    "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0 Safari/537.36"
  }
]
```

```
{
  "code": 401,
  "error": "INVALID_ACCESS_TOKEN"
}
```

| Status | Error Code | Description |
| --- | --- | --- |
| `401` | `INVALID_ACCESS_TOKEN` | Authentication required or invalid token |

| Permission | Description |
| --- | --- |
| `Bearer token` | Access token required via Authorization header, x-authtoken, x-token, query param, or cookie |
| `auditrequests_create` | Required scope: auditrequests_create |
