Skip to content
Ona Docs

GetAuditLog

client.Events.Get(ctx, body) (*EventGetResponse, error)
POST/gitpod.v1.EventService/GetAuditLog

Gets one audit-log entry, including any typed details stored for it.

Use this method to:

  • Inspect the details of a specific audit-log entry
  • Retrieve the evidence associated with a Veto Exec audit event

Examples

  • Get an audit-log entry:

    auditLogEntryId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
ParametersExpand Collapse
body EventGetParams
AuditLogEntryID param.Field[string]

audit_log_entry_id is the ID of the audit-log entry to retrieve.

formatuuid
ReturnsExpand Collapse
type EventGetResponse struct{…}
Entry EventGetResponseEntry

entry contains the common audit-log fields also returned by ListAuditLogs.

ID stringOptional
Action stringOptional
ActorID stringOptional
ActorPrincipal PrincipalOptional
One of the following:
const PrincipalUnspecified Principal = "PRINCIPAL_UNSPECIFIED"
const PrincipalAccount Principal = "PRINCIPAL_ACCOUNT"
const PrincipalUser Principal = "PRINCIPAL_USER"
const PrincipalRunner Principal = "PRINCIPAL_RUNNER"
const PrincipalEnvironment Principal = "PRINCIPAL_ENVIRONMENT"
const PrincipalServiceAccount Principal = "PRINCIPAL_SERVICE_ACCOUNT"
const PrincipalRunnerManager Principal = "PRINCIPAL_RUNNER_MANAGER"
CreatedAt TimeOptional

A Timestamp represents a point in time independent of any time zone or local calendar, encoded as a count of seconds and fractions of seconds at nanosecond resolution. The count is relative to an epoch at UTC midnight on January 1, 1970, in the proleptic Gregorian calendar which extends the Gregorian calendar backwards to year one.

All minutes are 60 seconds long. Leap seconds are “smeared” so that no leap second table is needed for interpretation, using a 24-hour linear smear.

The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By restricting to that range, we ensure that we can convert to and from RFC 3339 date strings.

Examples

Example 1: Compute Timestamp from POSIX time().

 Timestamp timestamp;
 timestamp.set_seconds(time(NULL));
 timestamp.set_nanos(0);

Example 2: Compute Timestamp from POSIX gettimeofday().

 struct timeval tv;
 gettimeofday(&tv, NULL);

 Timestamp timestamp;
 timestamp.set_seconds(tv.tv_sec);
 timestamp.set_nanos(tv.tv_usec * 1000);

Example 3: Compute Timestamp from Win32 GetSystemTimeAsFileTime().

 FILETIME ft;
 GetSystemTimeAsFileTime(&ft);
 UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

 // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
 // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
 Timestamp timestamp;
 timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
 timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

Example 4: Compute Timestamp from Java System.currentTimeMillis().

 long millis = System.currentTimeMillis();

 Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
     .setNanos((int) ((millis % 1000) * 1000000)).build();

Example 5: Compute Timestamp from Java Instant.now().

 Instant now = Instant.now();

 Timestamp timestamp =
     Timestamp.newBuilder().setSeconds(now.getEpochSecond())
         .setNanos(now.getNano()).build();

Example 6: Compute Timestamp from current time in Python.

 timestamp = Timestamp()
 timestamp.GetCurrentTime()

JSON Mapping

In JSON format, the Timestamp type is encoded as a string in the RFC 3339 format. That is, the format is “{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z” where {year} is always expressed using four digits while {month}, {day}, {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), are optional. The “Z” suffix indicates the timezone (“UTC”); the timezone is required. A proto3 JSON serializer should always use UTC (as indicated by “Z”) when printing the Timestamp type and a proto3 JSON parser should be able to accept both UTC and other timezones (as indicated by an offset).

For example, “2017-01-15T01:30:15.01Z” encodes 15.01 seconds past 01:30 UTC on January 15, 2017.

In JavaScript, one can convert a Date object to this format using the standard toISOString() method. In Python, a standard datetime.datetime object can be converted to this format using strftime with the time format spec ‘%Y-%m-%dT%H:%M:%S.%fZ’. Likewise, in Java, one can use the Joda Time’s ISODateTimeFormat.dateTime() to obtain a formatter capable of generating timestamps in this format.

formatdate-time
Kind EventGetResponseEntryKindOptional

AuditLogEntryKind identifies the semantic event represented by an audit-log entry.

One of the following:
const EventGetResponseEntryKindAuditLogEntryKindUnspecified EventGetResponseEntryKind = "AUDIT_LOG_ENTRY_KIND_UNSPECIFIED"
const EventGetResponseEntryKindAuditLogEntryKindAgentSecurityExecBlocked EventGetResponseEntryKind = "AUDIT_LOG_ENTRY_KIND_AGENT_SECURITY_EXEC_BLOCKED"
const EventGetResponseEntryKindAuditLogEntryKindAgentSecurityExecAudited EventGetResponseEntryKind = "AUDIT_LOG_ENTRY_KIND_AGENT_SECURITY_EXEC_AUDITED"
SubjectID stringOptional
SubjectType ResourceTypeOptional
One of the following:
const ResourceTypeUnspecified ResourceType = "RESOURCE_TYPE_UNSPECIFIED"
const ResourceTypeEnvironment ResourceType = "RESOURCE_TYPE_ENVIRONMENT"
const ResourceTypeRunner ResourceType = "RESOURCE_TYPE_RUNNER"
const ResourceTypeProject ResourceType = "RESOURCE_TYPE_PROJECT"
const ResourceTypeTask ResourceType = "RESOURCE_TYPE_TASK"
const ResourceTypeTaskExecution ResourceType = "RESOURCE_TYPE_TASK_EXECUTION"
const ResourceTypeService ResourceType = "RESOURCE_TYPE_SERVICE"
const ResourceTypeOrganization ResourceType = "RESOURCE_TYPE_ORGANIZATION"
const ResourceTypeUser ResourceType = "RESOURCE_TYPE_USER"
const ResourceTypeEnvironmentClass ResourceType = "RESOURCE_TYPE_ENVIRONMENT_CLASS"
const ResourceTypeRunnerScmIntegration ResourceType = "RESOURCE_TYPE_RUNNER_SCM_INTEGRATION"
const ResourceTypeHostAuthenticationToken ResourceType = "RESOURCE_TYPE_HOST_AUTHENTICATION_TOKEN"
const ResourceTypeGroup ResourceType = "RESOURCE_TYPE_GROUP"
const ResourceTypePersonalAccessToken ResourceType = "RESOURCE_TYPE_PERSONAL_ACCESS_TOKEN"
const ResourceTypeUserPreference ResourceType = "RESOURCE_TYPE_USER_PREFERENCE"
const ResourceTypeServiceAccount ResourceType = "RESOURCE_TYPE_SERVICE_ACCOUNT"
const ResourceTypeSecret ResourceType = "RESOURCE_TYPE_SECRET"
const ResourceTypeSSOConfig ResourceType = "RESOURCE_TYPE_SSO_CONFIG"
const ResourceTypeDomainVerification ResourceType = "RESOURCE_TYPE_DOMAIN_VERIFICATION"
const ResourceTypeAgentExecution ResourceType = "RESOURCE_TYPE_AGENT_EXECUTION"
const ResourceTypeRunnerLlmIntegration ResourceType = "RESOURCE_TYPE_RUNNER_LLM_INTEGRATION"
const ResourceTypeAgent ResourceType = "RESOURCE_TYPE_AGENT"
const ResourceTypeEnvironmentSession ResourceType = "RESOURCE_TYPE_ENVIRONMENT_SESSION"
const ResourceTypeUserSecret ResourceType = "RESOURCE_TYPE_USER_SECRET"
const ResourceTypeOrganizationPolicy ResourceType = "RESOURCE_TYPE_ORGANIZATION_POLICY"
const ResourceTypeOrganizationSecret ResourceType = "RESOURCE_TYPE_ORGANIZATION_SECRET"
const ResourceTypeProjectEnvironmentClass ResourceType = "RESOURCE_TYPE_PROJECT_ENVIRONMENT_CLASS"
const ResourceTypeBilling ResourceType = "RESOURCE_TYPE_BILLING"
const ResourceTypePrompt ResourceType = "RESOURCE_TYPE_PROMPT"
const ResourceTypeCoupon ResourceType = "RESOURCE_TYPE_COUPON"
const ResourceTypeCouponRedemption ResourceType = "RESOURCE_TYPE_COUPON_REDEMPTION"
const ResourceTypeAccount ResourceType = "RESOURCE_TYPE_ACCOUNT"
const ResourceTypeIntegration ResourceType = "RESOURCE_TYPE_INTEGRATION"
const ResourceTypeWorkflow ResourceType = "RESOURCE_TYPE_WORKFLOW"
const ResourceTypeWorkflowExecution ResourceType = "RESOURCE_TYPE_WORKFLOW_EXECUTION"
const ResourceTypeWorkflowExecutionAction ResourceType = "RESOURCE_TYPE_WORKFLOW_EXECUTION_ACTION"
const ResourceTypeSnapshot ResourceType = "RESOURCE_TYPE_SNAPSHOT"
const ResourceTypePrebuild ResourceType = "RESOURCE_TYPE_PREBUILD"
const ResourceTypeOrganizationLlmIntegration ResourceType = "RESOURCE_TYPE_ORGANIZATION_LLM_INTEGRATION"
const ResourceTypeCustomDomain ResourceType = "RESOURCE_TYPE_CUSTOM_DOMAIN"
const ResourceTypeRoleAssignmentChanged ResourceType = "RESOURCE_TYPE_ROLE_ASSIGNMENT_CHANGED"
const ResourceTypeGroupMembershipChanged ResourceType = "RESOURCE_TYPE_GROUP_MEMBERSHIP_CHANGED"
const ResourceTypeWebhook ResourceType = "RESOURCE_TYPE_WEBHOOK"
const ResourceTypeScimConfiguration ResourceType = "RESOURCE_TYPE_SCIM_CONFIGURATION"
const ResourceTypeServiceAccountSecret ResourceType = "RESOURCE_TYPE_SERVICE_ACCOUNT_SECRET"
const ResourceTypeAnnouncementBanner ResourceType = "RESOURCE_TYPE_ANNOUNCEMENT_BANNER"
const ResourceTypeServiceAccountToken ResourceType = "RESOURCE_TYPE_SERVICE_ACCOUNT_TOKEN"
const ResourceTypeRoleAssignment ResourceType = "RESOURCE_TYPE_ROLE_ASSIGNMENT"
const ResourceTypeWarmPool ResourceType = "RESOURCE_TYPE_WARM_POOL"
const ResourceTypeNotification ResourceType = "RESOURCE_TYPE_NOTIFICATION"
const ResourceTypeSecurityPolicy ResourceType = "RESOURCE_TYPE_SECURITY_POLICY"
const ResourceTypeBaseSnapshot ResourceType = "RESOURCE_TYPE_BASE_SNAPSHOT"
const ResourceTypeBaseSnapshotConfig ResourceType = "RESOURCE_TYPE_BASE_SNAPSHOT_CONFIG"
Details AuditLogEntryDetailsOptional

details contains typed evidence captured with the audit entry. It is absent when the entry has no supported, valid details.

VetoExec AuditLogEntryDetailsVetoExec

veto_exec contains Veto Exec event details without process.cmdline.

Process Process

process contains metadata about the process that triggered the event.

Name stringOptional

name is the process name (comm). 2x kernel TASK_COMM_LEN=16

maxLength32
Pgid int64Optional

pgid is the process group ID.

formatint32
Pid int64Optional

pid is the userspace process ID (kernel thread group ID, tgid).

formatint32
Ppid int64Optional

ppid is the parent process ID.

formatint32
Sid int64Optional

sid is the session ID.

formatint32
StartedAt TimeOptional

started_at is when the process started.

formatdate-time
Tid int64Optional

tid is the userspace thread ID (kernel pid).

formatint32
Timestamp Time

timestamp is when the event occurred in the environment.

formatdate-time
Action KernelControlsActionOptional

action is the enforcement action taken (block or audit).

One of the following:
const KernelControlsActionUnspecified KernelControlsAction = "KERNEL_CONTROLS_ACTION_UNSPECIFIED"
const KernelControlsActionBlock KernelControlsAction = "KERNEL_CONTROLS_ACTION_BLOCK"
const KernelControlsActionAudit KernelControlsAction = "KERNEL_CONTROLS_ACTION_AUDIT"
EnvironmentID stringOptional

environment_id is the environment where the event occurred.

formatuuid
Executable stringOptional

executable is the digest of the binary content (e.g., “sha256:a1b2c3d4…”). 256 allows for longer hash algorithms or prefixed identifiers. May be empty when the event source cannot compute the hash.

maxLength256
Filename stringOptional

filename is the kernel-resolved path of the binary. Kernel PATH_MAX = 4096 (include/uapi/linux/limits.h). May be empty if the event source could not resolve it.

maxLength4096

GetAuditLog

package main

import (
  "context"
  "fmt"

  "github.com/gitpod-io/gitpod-sdk-go"
  "github.com/gitpod-io/gitpod-sdk-go/option"
)

func main() {
  client := gitpod.NewClient(
    option.WithBearerToken("My Bearer Token"),
  )
  event, err := client.Events.Get(context.TODO(), gitpod.EventGetParams{
    AuditLogEntryID: gitpod.F("d2c94c27-3b76-4a42-b88c-95a85e392c68"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", event.Entry)
}
{
  "entry": {
    "id": "id",
    "action": "action",
    "actorId": "actorId",
    "actorPrincipal": "PRINCIPAL_UNSPECIFIED",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "kind": "AUDIT_LOG_ENTRY_KIND_UNSPECIFIED",
    "subjectId": "subjectId",
    "subjectType": "RESOURCE_TYPE_UNSPECIFIED"
  },
  "details": {
    "vetoExec": {
      "process": {
        "cmdline": "cmdline",
        "name": "name",
        "pgid": 0,
        "pid": 0,
        "ppid": 0,
        "sid": 0,
        "startedAt": "2019-12-27T18:11:19.117Z",
        "tid": 0
      },
      "timestamp": "2019-12-27T18:11:19.117Z",
      "action": "KERNEL_CONTROLS_ACTION_UNSPECIFIED",
      "environmentId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "executable": "executable",
      "filename": "filename"
    }
  }
}
Returns Examples
{
  "entry": {
    "id": "id",
    "action": "action",
    "actorId": "actorId",
    "actorPrincipal": "PRINCIPAL_UNSPECIFIED",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "kind": "AUDIT_LOG_ENTRY_KIND_UNSPECIFIED",
    "subjectId": "subjectId",
    "subjectType": "RESOURCE_TYPE_UNSPECIFIED"
  },
  "details": {
    "vetoExec": {
      "process": {
        "cmdline": "cmdline",
        "name": "name",
        "pgid": 0,
        "pid": 0,
        "ppid": 0,
        "sid": 0,
        "startedAt": "2019-12-27T18:11:19.117Z",
        "tid": 0
      },
      "timestamp": "2019-12-27T18:11:19.117Z",
      "action": "KERNEL_CONTROLS_ACTION_UNSPECIFIED",
      "environmentId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "executable": "executable",
      "filename": "filename"
    }
  }
}