Learn · Lesson 6 of 7 · 4 min
Watch the audit log
Find out who changed a rule, approved a node or created a key. Start with one change you recognize.
Follow the rule you just created.
Open Audit Logs. Use search, date range, action and resource filters to narrow the list.

dev-to-stagingci-runner-keybuild-01Who, what, and when—in one place.
- Actor
- Alex Morgan
- Time
- Today · 16:02
- Resource
- dev-to-staging
- Actor IP
- 192.0.2.10
The entry also includes the submitted request body, so you can inspect the change.
Audit logs cover administrative actions. They do not contain connection or traffic logs.
Bring the log into your own workflow.
Create an API key under Keys. Replace the placeholders with your API key and organization ID.
curl https://api.baseguard.net/v1/audit-log \
-H "Authorization: Bearer <api-key>" \
-H "x-bg-organization-id: <org-id>" \
-H "Content-Type: application/json"All three headers are required. Available history depends on your plan.
A few useful details
Actors. A change can be attributed to a user, API key or node auth key.
Recorded actions. Network rules; DNS nameservers, records and search domains; API keys and node auth keys; node changes and approvals; user invitations and roles; organization settings.
Entry contents. Action, actor, actor IP, resource, submitted request body and timestamp.
One lesson left: how your machines connect behind the scenes.