Manage Mondoo

View Audit Logs

View, filter, and export organization and space audit logs in Mondoo, or pull them through the GraphQL API.

Mondoo records administrative events in audit logs you can view and export in the Mondoo App or pull through the GraphQL API. There are two scopes:

  • An organization log tracks changes across the organization, like organization settings updates, membership changes and invitations, spaces that are created or deleted, organization-level integrations, and API tokens.
  • A space log tracks changes within a space, like policies that are added, removed, or changed, registration tokens, service accounts, agents, and integrations.

Each entry shows the Subject (the user or service account that made the change), the Action (a short description, the API operation, and the affected resource), and the Time.

View a space audit log

  1. Navigate to the space.

  2. In the side navigation, select Settings, then select Audit Log.

    The Audit Log page of a Mondoo space, listing entries with Subject, Action, and Time columns

View an organization audit log

  1. Navigate to the organization.

  2. In the side navigation, select Settings, then select Audit Log.

Filter the audit log

To narrow down the list, use the Filter audit log box above the table:

  • Select Action to show only entries for one API operation, such as mondoo.captain.Captain.DeleteSpace.
  • Select Identity to show only entries made by one user or service account.
  • Type any other text to search the entries.

To remove a filter, delete its chip from the box. To sort by time, select the Time column header.

Export the audit log

To download a copy of the audit log for the space or organization you're viewing:

  1. In the top right of the Audit Log page, select Export. (If you don't see the button, you don't have permission to export audit logs for this scope.)

    The Export audit log dialog, with Format and Time range options

  2. Under Format, choose CSV or JSONL (OCSF). The JSONL format writes one OCSF event per line, the same format the continuous export uses.

  3. Under Time range, choose Last 7 days, Last 30 days, Last 90 days, All time, or Custom range. For a custom range, pick the start and end dates.

  4. Select Export. Mondoo prepares the file and your browser downloads it when it's ready.

You can only export entries that are still within your audit log retention period. Mondoo doesn't apply retention to files you download, so store and delete them according to your own data policy.

The steps above cover everyday audit-log review in the Mondoo App. The rest of this page is for pulling audit logs programmatically. Skip it if you only need the in-app view.

Retrieve audit logs through the API

Organization audit logs are available through Mondoo's GraphQL API. You need:

  • An API token with at least read access to the organization.

  • The organization ID. To find it, go to the organization's Settings > General page and copy the Organization ID. The same page also shows the Organization MRN, which is the resourceMrn value the query below needs.

    The General settings page of a Mondoo organization, showing the Organization ID and Organization MRN

Query

Save this query to query.gql. Replace <ORG_ID> with your organization ID.

query AuditLogForwardPagination(
  $first: Int
  $after: String
  $orderBy: AuditLogOrder = { direction: DESC, field: TIMESTAMP }
  $resourceMrn: String!
) {
  auditlog(first: $first, after: $after, orderBy: $orderBy, resourceMrn: $resourceMrn) {
    totalCount
    edges {
      cursor
      node {
        identity {
          name
          mrn
        }
        resource
        action
        timestamp
        msg
      }
    }
    pageInfo {
      startCursor
      endCursor
      hasNextPage
    }
  }
}

Variables

Save this variables payload to variables.json, again replacing <ORG_ID>:

{
  "first": 25,
  "resourceMrn": "//captain.api.mondoo.app/organizations/<ORG_ID>"
}

Call the API

EU region

Replace https://api.mondoo.com/query with https://eu.api.mondoo.com/query if your organization is in the EU region.

export TOKEN='YOUR_API_TOKEN'

curl -X POST \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  --data-binary @<(jq -nc --arg q "$(cat query.gql)" --argjson v "$(cat variables.json)" \
    '{query: $q, variables: $v}') \
  https://api.mondoo.com/query | jq

A successful response looks like:

{
  "data": {
    "auditlog": {
      "totalCount": 36,
      "edges": [
        {
          "cursor": "172213",
          "node": {
            "identity": {
              "name": "Jane Doe",
              "mrn": "//captain.api.mondoo.app/users/26OR1GOGsqmfjXOOO8joxgJDdtM"
            },
            "resource": "//agents.api.mondoo.app/organizations/mondoo-organization-1/serviceaccounts/2e3NzLkD73yQe7MTJZLw3",
            "action": "mondoo.agents.AgentManager.CreateServiceAccount",
            "timestamp": "2024-03-22T17:46:03Z",
            "msg": "created service account"
          }
        }
      ]
    }
  }
}

Filter by timestamp

Add a timestampFilter variable to limit results to events before or after a given time. Update the query to accept the variable:

query AuditLogForwardPagination(
  $first: Int
  $after: String
  $orderBy: AuditLogOrder = { direction: DESC, field: TIMESTAMP }
  $resourceMrn: String!
  $timestampFilter: TimestampFilter
) {
  auditlog(
    first: $first
    after: $after
    orderBy: $orderBy
    resourceMrn: $resourceMrn
    timestampFilter: $timestampFilter
  ) {
    # ...same body as above
  }
}

And include the filter in your variables:

{
  "first": 25,
  "resourceMrn": "//captain.api.mondoo.app/organizations/<ORG_ID>",
  "timestampFilter": {
    "timestamp": "2024-05-06T13:48:33+03:00",
    "operator": "LT"
  }
}

LT returns events before the timestamp; use GT for events after.

The auditlog query also accepts identityFilter (for example, { "name": "Jane Doe" }), actionFilter (an API operation such as mondoo.captain.Captain.DeleteSpace), and queryTerms (a list of search strings). These are the same filters the Mondoo App uses.

Continuously export audit logs

To continuously export audit logs to Google Cloud Storage in OCSF format for long-term retention, SIEM ingestion, or compliance evidence, see Continuously Export Audit Logs.

Get help

Can't find what you need? Join the Mondoo community Slack channel to chat with the Mondoo team and other users.

On this page