> For the complete documentation index, see [llms.txt](https://docs.ox.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ox.security/api-documentation/api-reference/api--audit/types/objects/audit-log.md).

# auditLog

Represents a detailed audit log entry capturing system events and user actions.

### Examples

```graphql
type AuditLog {
  id: String!
  date: DateTime!
  logType: LogType!
  logName: LogName!
  userId: String!
  userEmail: String!
  name: String
  appId: String
  appName: String
  registry: String
  dockerfile: String
  connector: String
  credentialsType: String
  credentialName: String
  resourceCount: Float
  resources: [String!]
  branches: [MultipliedBranchWithReason!]
  repoName: String
  reposCount: Float
  hostUrl: String
  monitorAllResources: Boolean
  scanId: String
  enabledConnectors: [String!]
  loginType: String
  domain: String
  memberEmail: String
  disclaimerType: String
  memberRoles: [String!]
  memberScopes: String
  appNames: [String]
  isDastOnlyScan: Boolean
  dastTargetIds: [String!]
  dastTargetNames: [String!]
  scanStartDate: DateTime
  scanFinishDate: DateTime
  scanStatus: String
  scanFailureReason: String
  businessPriority: Float
  owners: [String!]
  ownersWithRoles: [Owner!]
  roles: [String!]
  generatedForOrg: Boolean
  downloadFormat: String
  generatedFrom: String
  comment: String
  commentId: String
  excluded: Boolean
  removed: Boolean
  issueName: String
  issueId: String
  profileId: String
  profileName: String
  activeProfile: Boolean
  settingsType: String
  disabled: Boolean
  configured: Float
  textArr: [String!]
  policies: [LogPolicy!]
  slackUser: String
  channel: String
  key: String
  ticketId: String
  ticketingVendor: String
  targetStatus: String
  currentStatus: String
  availableTransitions: [String!]
  failureReason: String
  failureKind: String
  hopsUsed: Float
  statusesTraversed: [String!]
  messagingVendor: String
  recipients: [String!]
  user: String
  link: String
  categoryName: String
  categoryId: Float
  expiredAt: DateTime
  prId: String
  prURL: String
  sourceControlType: String
  aggItems: String
  excludedIssues: [ExcludedIssue!]
  issues: [JiraIssueDetailType!]
  fixTitle: String
  severity: String
  oldSeverity: String
  newOwnerName: String
  newOwnerEmail: String
  oldOwnerName: String
  oldOwnerEmail: String
  tagsAdded: [String!]
  tagsRemoved: [String!]
  workflowType: String
  workflowName: String
  nodeName: String
  nodeType: String
  workflowId: String
  description: String
  enabled: Boolean
  monitorAllNewlyCreatedRepositories: Float
  monitoredApps: [String!]
  secretName: String
  filterName: String
  viewName: String
  pageName: String
  apiKeyName: String
  apiKeyType: String
  createdBy: String
  apiKeyCreatedAt: DateTime
  apiKeyExpiredAt: DateTime
  orgUnitName: String
  orgUnitId: ID
  tags: [String!]
  pipelineSettingsV2: PipelineSettingsV2
  children: [ID!]
  updateSlaSettings: String
  irrelevantComment: String
  sla: Float
  emailType: String
  emailSubject: String
  triageStatus: String
  actionType: String
  changes: [String!]
  fileName: String
  universalParserName: String
  fileType: String
  title: String
  domainType: String
  targetUrl: String
  env: String
  authMethod: String
  previousValues: PreviousTargetValues
  branch: String
  customRoleLogData: customRoleLogData
  tableRowsChanges: TableRowsChangeSet
  notificationSettings: [NotificationSettingItem!]
  incidentCaseId: String
  incidentName: String
  incidentSource: String
  incidentStatusFrom: String
  incidentStatusTo: String
}
```

### Fields

| Field                                                                                                                                       | Description                                                                                                                                                       | Supported fields                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| id `String!`                                                                                                                                | Unique identifier of the audit log entry                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| date `DateTime!`                                                                                                                            | Timestamp when the event occurred. Records are automatically expired after 365 days                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| logType [`LogType!`](/api-documentation/api-reference/api--audit/types/enums/log-type.md)                                                   | Category of the event (e.g., Authentication, Login, Scan)                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| logName [`LogName!`](/api-documentation/api-reference/api--audit/types/enums/log-name.md)                                                   | Specific action or event name within the category                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| userId `String!`                                                                                                                            | Unique identifier of the user who performed the action                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| userEmail `String!`                                                                                                                         | Email address of the user who performed the action                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| name `String`                                                                                                                               | Name of the container or organization involved in the event                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| appId `String`                                                                                                                              | Unique identifier of the application associated with the container                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| appName `String`                                                                                                                            | Name of the application associated with the container                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| registry `String`                                                                                                                           | Container registry information                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dockerfile `String`                                                                                                                         | Path or content of the Dockerfile used                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| connector `String`                                                                                                                          | Name or identifier of the external service connector                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| credentialsType `String`                                                                                                                    | Type of credentials used for authentication                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| credentialName `String`                                                                                                                     | Name of the credential used for the connector                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| resourceCount `Float`                                                                                                                       | Number of resources affected or monitored                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| resources `[String!]`                                                                                                                       | List of resource identifiers being monitored                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| branches [`[MultipliedBranchWithReason!]`](/api-documentation/api-reference/api--audit/types/objects/multiplied-branch-with-reason.md)      | List of branches selected for scanning with their selection reasons                                                                                               | <p>branch <code>String!</code><br>reason <code>String!</code></p>                                                                                                                                                                                                                                                                                                                                                                                       |
| repoName `String`                                                                                                                           | Name of the repository being scanned                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| reposCount `Float`                                                                                                                          | Total number of repositories affected                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| hostUrl `String`                                                                                                                            | URL of the external service or repository host                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| monitorAllResources `Boolean`                                                                                                               | Whether all available resources are being monitored                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| scanId `String`                                                                                                                             | Unique identifier of the security scan                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| enabledConnectors `[String!]`                                                                                                               | List of connectors enabled for the scan                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| loginType `String`                                                                                                                          | Authentication method used for login                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| domain `String`                                                                                                                             | Domain associated with the authentication or login event                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| memberEmail `String`                                                                                                                        | Email address of the member involved in the event                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| disclaimerType `String`                                                                                                                     | Type of disclaimer that was accepted                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| memberRoles `[String!]`                                                                                                                     | Roles assigned to the member                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| memberScopes `String`                                                                                                                       | Permission scopes granted to the member                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| appNames `[String]`                                                                                                                         | Names of applications involved in the event                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| isDastOnlyScan `Boolean`                                                                                                                    | Indicates whether the scan was an Agentic Pentester scan                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dastTargetIds `[String!]`                                                                                                                   | IDs of Agentic Pentester targets included in the scan. Empty when the scan covers all targets.                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dastTargetNames `[String!]`                                                                                                                 | Human-readable names of Agentic Pentester targets included in the scan. Empty when the scan covers all targets.                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| scanStartDate `DateTime`                                                                                                                    | Timestamp when the scan started (ScanFinished entries)                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| scanFinishDate `DateTime`                                                                                                                   | Timestamp when the scan finished (ScanFinished entries)                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| scanStatus `String`                                                                                                                         | Final scan status: Succeeded, Failed, or Timed Out (ScanFinished entries)                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| scanFailureReason `String`                                                                                                                  | Customer-facing failure reason on failed ScanFinished entries                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| businessPriority `Float`                                                                                                                    | Business priority level assigned to the application                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| owners `[String!]`                                                                                                                          | List of application owner identifiers                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ownersWithRoles [`[Owner!]`](/api-documentation/api-reference/api--audit/types/objects/owner.md)                                            | Detailed information about application owners including their roles                                                                                               | <p>owner <code>String</code><br>email <code>String</code><br>roles <code>\[String!]</code></p>                                                                                                                                                                                                                                                                                                                                                          |
| roles `[String!]`                                                                                                                           | List of roles associated with the event                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| generatedForOrg `Boolean`                                                                                                                   | Indicates if the file was generated for the entire organization                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| downloadFormat `String`                                                                                                                     | Format of the downloaded file (e.g., JSON, CSV)                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| generatedFrom `String`                                                                                                                      | Source or context from which the file was generated                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| comment `String`                                                                                                                            | User-provided comment or explanation for the action                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| commentId `String`                                                                                                                          | Unique identifier of a specific comment on an issue                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| excluded `Boolean`                                                                                                                          | Indicates if an issue was marked as a false positive                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| removed `Boolean`                                                                                                                           | Indicates if a resolved issue was marked as incorrectly resolved                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| issueName `String`                                                                                                                          | Name or title of the security issue                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| issueId `String`                                                                                                                            | Unique identifier of the security issue                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| profileId `String`                                                                                                                          | Identifier of the security policy profile                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| profileName `String`                                                                                                                        | Name of the security policy profile                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| activeProfile `Boolean`                                                                                                                     | Indicates if this is the active security policy profile                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| settingsType `String`                                                                                                                       | Type of system settings being modified                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| disabled `Boolean`                                                                                                                          | Indicates if the feature or setting is disabled                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| configured `Float`                                                                                                                          | Configuration value or count                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| textArr `[String!]`                                                                                                                         | Array of text values in string format                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| policies [`[LogPolicy!]`](/api-documentation/api-reference/api--audit/types/objects/log-policy.md)                                          | List of security policies affected by the event                                                                                                                   | <p>policyId <code>String</code><br>policyName <code>String</code><br>categoryName <code>String</code><br>enabled <code>Boolean</code><br>severity <code>String</code><br>oldIssues <code>String</code><br>newIssues <code>String</code><br>args <code>String</code></p>                                                                                                                                                                                 |
| slackUser `String`                                                                                                                          | Slack username associated with the event                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| channel `String`                                                                                                                            | Slack channel where the notification was sent                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| key `String`                                                                                                                                | Unique key or identifier in the external system                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ticketId `String`                                                                                                                           | Ticket identifier in the external ticketing system                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ticketingVendor `String`                                                                                                                    | Name of the ticketing system vendor (e.g., Jira, ServiceNow)                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| targetStatus `String`                                                                                                                       | Status the ticket was being moved to                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| currentStatus `String`                                                                                                                      | Status the ticket was in when the transition failed                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| availableTransitions `[String!]`                                                                                                            | Transitions the ticketing system offered from the current status                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| failureReason `String`                                                                                                                      | Reason the ticketing system gave for rejecting the transition                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| failureKind `String`                                                                                                                        | Machine-readable transition failure category                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| hopsUsed `Float`                                                                                                                            | Number of intermediate status hops performed before failing                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| statusesTraversed `[String!]`                                                                                                               | Statuses the ticket was actually moved through before the failure                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| messagingVendor `String`                                                                                                                    | Name of the messaging system vendor                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| recipients `[String!]`                                                                                                                      | Recipients (channels or users) the notification was delivered to                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| user `String`                                                                                                                               | Username in the external system                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| link `String`                                                                                                                               | URL or link to the external resource                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| categoryName `String`                                                                                                                       | Category name of the security issue or code fix                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| categoryId `Float`                                                                                                                          | Numeric identifier of the issue category                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| expiredAt `DateTime`                                                                                                                        | Expiration date of the exclusion                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| prId `String`                                                                                                                               | Pull request identifier                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| prURL `String`                                                                                                                              | URL of the pull request                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| sourceControlType `String`                                                                                                                  | Type of source control system (e.g., GitHub, GitLab)                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| aggItems `String`                                                                                                                           | Aggregated items in string format                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| excludedIssues [`[ExcludedIssue!]`](/api-documentation/api-reference/api--audit/types/objects/excluded-issue.md)                            | List of issues excluded from security scanning                                                                                                                    | <p>appNames <code>\[String!]</code><br>issueId <code>String!</code><br>issueName <code>String!</code><br>categoryName <code>String!</code><br>comment <code>String</code><br>expiredAt <code>String</code></p>                                                                                                                                                                                                                                          |
| issues [`[JiraIssueDetailType!]`](/api-documentation/api-reference/api--audit/types/objects/jira-issue-detail-type.md)                      | List of issues for multi-issue Jira tickets                                                                                                                       | <p>issueId <code>String!</code><br>issueName <code>String</code></p>                                                                                                                                                                                                                                                                                                                                                                                    |
| fixTitle `String`                                                                                                                           | Title of the applied fix                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| severity `String`                                                                                                                           | Current severity level of the issue                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| oldSeverity `String`                                                                                                                        | Previous severity level of the issue                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| newOwnerName `String`                                                                                                                       | Name of the new issue owner                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| newOwnerEmail `String`                                                                                                                      | Email of the new issue owner                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| oldOwnerName `String`                                                                                                                       | Name of the previous issue owner                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| oldOwnerEmail `String`                                                                                                                      | Email of the previous issue owner                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| tagsAdded `[String!]`                                                                                                                       | Tags added to the application                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| tagsRemoved `[String!]`                                                                                                                     | Tags removed from the application                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| workflowType `String`                                                                                                                       | Type of the policy workflow                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| workflowName `String`                                                                                                                       | Name of the workflow the event relates to: the policy workflow for policy-workflow logs, or the ticketing system workflow governing the ticket for ticketing logs |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| nodeName `String`                                                                                                                           | Name of the workflow node                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| nodeType `String`                                                                                                                           | Type of the workflow node                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| workflowId `String`                                                                                                                         | Unique identifier of the workflow                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| description `String`                                                                                                                        | Description of the workflow                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| enabled `Boolean`                                                                                                                           | Indicates if the workflow is enabled                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| monitorAllNewlyCreatedRepositories `Float`                                                                                                  | Number of newly created repositories to monitor                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| monitoredApps `[String!]`                                                                                                                   | List of applications being monitored by the workflow                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| secretName `String`                                                                                                                         | Name of the secret                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| filterName `String`                                                                                                                         | Name of the saved filter                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| viewName `String`                                                                                                                           | Name of the saved view                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pageName `String`                                                                                                                           | Page where the filter is applied                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| apiKeyName `String`                                                                                                                         | Name of the API key                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| apiKeyType `String`                                                                                                                         | Type of the API key                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| createdBy `String`                                                                                                                          | User who created the API key                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| apiKeyCreatedAt `DateTime`                                                                                                                  | Creation date of the API key                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| apiKeyExpiredAt `DateTime`                                                                                                                  | Expiration date of the API key                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| orgUnitName `String`                                                                                                                        | Name of the organization unit                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| orgUnitId `ID`                                                                                                                              | Unique identifier of the organization unit                                                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| tags `[String!]`                                                                                                                            | Tags associated with the organization unit                                                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pipelineSettingsV2 [`PipelineSettingsV2`](/api-documentation/api-reference/api--audit/types/objects/pipeline-settings-v2.md)                | Enhanced CI/CD pipeline configuration settings                                                                                                                    | <p>isDefaultSettings <code>Boolean!</code><br>isGithubConnected <code>Boolean</code><br>isBitbucketConnected <code>Boolean</code><br>isGitlabConnected <code>Boolean</code><br>apps <code>JSONObject</code><br>settings <code>JSONObject</code><br>branchSettings <code>JSONObject</code></p>                                                                                                                                                           |
| children `[ID!]`                                                                                                                            | Child organization unit identifiers                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| updateSlaSettings `String`                                                                                                                  | Changes made to SLA settings                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| irrelevantComment `String`                                                                                                                  | Reason for marking an application as irrelevant                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| sla `Float`                                                                                                                                 | SLA time value in hours                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| emailType `String`                                                                                                                          | Type of email notification sent                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| emailSubject `String`                                                                                                                       | Subject line of the email notification                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| triageStatus `String`                                                                                                                       | Triage status of the issue                                                                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| actionType `String`                                                                                                                         | Action type of the audit logs export                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| changes `[String!]`                                                                                                                         | Changes made to the audit logs export                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| fileName `String`                                                                                                                           | Imported File Name                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| universalParserName `String`                                                                                                                | Universal Parser connector name                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| fileType `String`                                                                                                                           | Imported File Type                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| title `String`                                                                                                                              | Title or name of the Agentic Pentest scanning target                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| domainType `String`                                                                                                                         | Type or classification of the domain being scanned                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| targetUrl `String`                                                                                                                          | URL of the target being scanned by Agentic Pentest                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| env `String`                                                                                                                                | Environment classification of the target (e.g., production, staging, development)                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| authMethod `String`                                                                                                                         | Authentication method used to access the Agentic Pentest target                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| previousValues [`PreviousTargetValues`](/api-documentation/api-reference/api--audit/types/objects/previous-target-values.md)                | Previous values of the target configuration before modification (used in Edit operations)                                                                         | <p>title <code>String</code><br>domainType <code>String</code><br>targetUrl <code>String</code><br>env <code>String</code><br>authMethod <code>String</code></p>                                                                                                                                                                                                                                                                                        |
| branch `String`                                                                                                                             | Name of the branch being scanned                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| customRoleLogData [`customRoleLogData`](/api-documentation/api-reference/api--audit/types/objects/custom-role-log-data.md)                  | Custom Role details                                                                                                                                               | <p>name <code>String!</code><br>displayName <code>String!</code><br>assignablePermissions <a href="/api-documentation/api-reference/api--audit/types/objects/assignable-permission.md"><code>\[AssignablePermission!]</code></a><br>previousDisplayName <code>String</code><br>previousAssignablePermissions <a href="/api-documentation/api-reference/api--audit/types/objects/assignable-permission.md"><code>\[AssignablePermission!]</code></a></p> |
| tableRowsChanges [`TableRowsChangeSet`](/api-documentation/api-reference/api--audit/types/objects/table-rows-change-set.md)                 | Table rows changes                                                                                                                                                | <p>deleted <a href="/api-documentation/api-reference/api--audit/types/objects/table-row-change-item.md"><code>\[TableRowChangeItem!]</code></a><br>added <a href="/api-documentation/api-reference/api--audit/types/objects/table-row-change-item.md"><code>\[TableRowChangeItem!]</code></a></p>                                                                                                                                                       |
| notificationSettings [`[NotificationSettingItem!]`](/api-documentation/api-reference/api--audit/types/objects/notification-setting-item.md) | Notification settings configuration                                                                                                                               | <p>type <a href="/api-documentation/api-reference/api--audit/types/enums/notification-settings-type.md"><code>NotificationSettingsType!</code></a><br>enabled <code>Boolean!</code><br>channels <a href="/api-documentation/api-reference/api--audit/types/objects/notification-channel-setting.md"><code>NotificationChannelSetting</code></a></p>                                                                                                     |
| incidentCaseId `String`                                                                                                                     | Response Center incident case id (e.g. RC-1018)                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| incidentName `String`                                                                                                                       | Response Center incident name                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| incidentSource `String`                                                                                                                     | Response Center incident creation origin: manual, ox-declared or auto-rule                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| incidentStatusFrom `String`                                                                                                                 | Response Center incident status before the change                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| incidentStatusTo `String`                                                                                                                   | Response Center incident status after the change                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

### References

#### Queries using this object:

* [\<?> getLogs](/api-documentation/api-reference/api--audit/queries/get-logs.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ox.security/api-documentation/api-reference/api--audit/types/objects/audit-log.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
