Audit Logs
API7 Control Plane provides a complete audit trail of all administrative actions. These audit logs are essential for security monitoring, troubleshooting, and meeting regulatory compliance requirements.
Capabilities
- Comprehensive Tracking: Record all changes to routes, services, plugins, and security policies.
- Detailed Context: Capture the operator, event time, resource, request, response, and source of the action.
- Long-Term Retention: Configure the retention period for audit data to meet your compliance needs.
- Export: Export filtered audit logs as JSON or CSV for external analysis and archival.
Audit Log Contents
Each audit log entry includes:
| Field | Description |
|---|---|
| Timestamp | When the operation occurred. |
| Operator | Details of the user who performed the action. |
| Event type | The named action, such as UpdateContactPoint. Use GET /api/audit_logs/event_types to retrieve the supported values. |
| Resource | The ID and available details of the resource associated with the action. |
| Request and response | The HTTP request method, URI, body, and user agent, plus the response status code and body. The entry records the request and response, not a before-and-after object diff. |
| Token name | The token used when the operation was authenticated through the Admin API. |
| Source IP | The IP address from which the request originated. |
| Source | Whether the operation came through the Dashboard or Admin API. ADC operations use the Admin API and are audited with other API operations. |
| Gateway group | The ID of the gateway group associated with the operation, when applicable. |
Review Audit Logs in the Dashboard
To view the audit trail, log in to the API7 Dashboard and navigate to Organization > Audit. You can filter the logs by date range, operator, event type, resource, or gateway group.
Retention
By default, audit logs are retained for 60 days. The Control Plane runs a background cleanup job that deletes audit entries older than the configured retention period. To change the retention period, set audit.retention_days in your Control Plane configuration:
audit:
retention_days: 180
Set a longer retention period if your compliance framework requires extended audit history, or a shorter one to reduce database storage consumption.
Export Audit Logs
From Organization > Audit, apply the required filters and export the result as JSON or CSV. You can then archive the file or import it into an external analysis system.
Compliance and Accountability
By maintaining a clear, immutable record of all administrative changes, API7 Gateway helps you demonstrate accountability and pass security audits. Audit logs ensure that every configuration change can be traced back to a specific individual and time.
Next Steps
- Configure RBAC to limit who can make administrative changes.
- Review the API7 Trust Center for certifications and security reports.