UpdatesExplore the release notes

Learn · Lesson 6 of 7 · 4 min

Watch the audit log

Find out who changed a rule, approved a node or created a key. Start with one change you recognize.

01 / FIND A CHANGE

Follow the rule you just created.

Open Audit Logs. Use search, date range, action and resource filters to narrow the list.

Audit LogsExample
16:02
Rule createddev-to-staging
15:48
Node auth key createdci-runner-key
15:31
Node approvedbuild-01
02 / READ THE ENTRY

Who, what, and when—in one place.

Rule createdExample
Actor
Alex Morgan
Time
Today · 16:02
Resource
dev-to-staging
Actor IP
192.0.2.10

The entry also includes the submitted request body, so you can inspect the change.

Audit logs cover administrative actions. They do not contain connection or traffic logs.

03 / RETRIEVE VIA API

Bring the log into your own workflow.

Create an API key under Keys. Replace the placeholders with your API key and organization ID.

curl https://api.baseguard.net/v1/audit-log \
  -H "Authorization: Bearer <api-key>" \
  -H "x-bg-organization-id: <org-id>" \
  -H "Content-Type: application/json"

All three headers are required. Available history depends on your plan.

A few useful details

Actors. A change can be attributed to a user, API key or node auth key.

Recorded actions. Network rules; DNS nameservers, records and search domains; API keys and node auth keys; node changes and approvals; user invitations and roles; organization settings.

Entry contents. Action, actor, actor IP, resource, submitted request body and timestamp.

You can trace a change back to its source.

One lesson left: how your machines connect behind the scenes.