> ## Documentation Index
> Fetch the complete documentation index at: https://docs.advinservers.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List a server's audit log

> ### Overview

Lists server activity, newest first. `per_page` defaults to 25 and accepts 1 to 100. Sort by `created_at` or `updated_at`, with `-` for descending order. Filter by `filter[action]`, `filter[user_id]` or `filter[user.email]`. By default, `user` contains only an email address. Add `?include=user` for full account details. The included `user` is null when you cannot view that account.

### Permissions

Requires the `server.read` (View servers) permission for the selected team. Resources outside that team return 404.



## OpenAPI

````yaml https://console.advinservers.com/docs/openapi.json get /servers/{server}/audit-log
openapi: 3.1.0
info:
  title: API reference
  version: 1.0.0
  description: >-
    Use this API to manage your team's servers, networks, backups, and other
    resources.


    ## Authentication


    Create an API key under **API Keys** and send it as a bearer token with
    every request:


    ```

    Authorization: Bearer {YOUR_API_KEY}

    Accept: application/json

    ```


    Copy the key when you create it. It cannot be shown again. Revoking a key
    takes effect immediately.


    ## Permissions


    Give each key only the permissions it needs. Every endpoint lists the
    required permission.


    Permissions cover servers and other resources in the key's team.


    ## Team scope


    A key can access resources in the team selected when it was created. This
    includes servers,

    snapshots, backups, firewall groups, images, SSH keys, scripts, networks and
    addresses.

    Resources in other teams return `404 Not Found`. Create a separate key for
    each team.


    The key determines the team for every request. Legacy keys that had no team
    are assigned

    to the account's first owned team.


    ## Actions that need the panel


    API keys cannot do the following, even with every permission. Sign in to the
    panel in a

    browser to do them:


    - Create, edit or revoke API keys

    - Edit the IP groups that restrict API keys

    - End signed-in sessions

    - Change two-factor authentication

    - Change the account's email address

    - Accept or decline team invitations

    - Switch or leave a team


    This keeps a leaked key from widening its own access or locking you out of
    your account.


    ## Source IP restrictions


    A key can be restricted to one or more IP groups. Requests from other
    addresses are rejected.


    ## Requests and responses


    Each endpoint lists its path, query, header, and body parameters. Examples
    use fictional data.


    Single records use JSON objects. Collections use JSON arrays unless the
    endpoint supports pagination. Timestamps use ISO 8601 in UTC.


    Error responses include `message`. Validation errors also include an
    `errors` object for each field. Each endpoint lists its status codes.


    ## Audit log


    Every API request, including reads, is recorded in the account audit log
    with the key that made it.
servers:
  - url: https://console.advinservers.com/api/v1/client
security:
  - http: []
tags:
  - name: Account
    description: Billing contact details and account setup progress.
  - name: Account activity
    description: Actions performed in the current team by people and API keys.
  - name: Servers
    description: >-
      Order and list servers, read their state and resource use, open a console,
      and control power.
  - name: Server settings
    description: >-
      Rename a server, rebuild it, and change its hardware, media, resolvers and
      credentials.
  - name: Backups
    description: Scheduled server copies stored separately from the server.
  - name: Snapshots
    description: >-
      Take, restore and move server snapshots. Snapshots are kept in snapshot
      storage that the team buys by the GiB.
  - name: Firewall groups
    description: Reusable sets of firewall rules, and the servers they apply to.
  - name: IP groups
    description: Reusable source address lists for firewall rules.
  - name: Server firewall
    description: >-
      Read default traffic policies and rules managed outside your firewall
      groups.
  - name: IP addresses
    description: Manage floating IPs and server address assignments.
  - name: Private networks
    description: Connect servers over a private network in the same location.
  - name: Reverse DNS
    description: Set the hostnames returned by IP address lookups.
  - name: DDoS protection
    description: Configure attack filtering for server addresses.
  - name: Bandwidth
    description: Buy extra bandwidth and share it between servers or location pools.
  - name: SSH keys
    description: Public keys the account can install on a server when it is built.
  - name: Setup scripts
    description: Scripts the account can run on a server when it is built.
  - name: ISO images
    description: ISO images you have downloaded, and the servers they are mounted on.
  - name: Server upgrades
    description: Change an existing server's plan.
  - name: Checkout
    description: Choose a payment method and pay for a purchase.
  - name: Invoices
    description: View and pay account invoices.
  - name: Billing
    description: Manage service renewals, payment methods and account credit.
  - name: Transfers
    description: Move resources between teams or transfer ownership.
  - name: Teams
    description: Manage the team assigned to your API key.
  - name: Team members
    description: Invite people and manage their team access.
  - name: Team roles
    description: Define the permissions granted to team members.
  - name: Team activity
    description: View actions performed in a team.
  - name: Support tickets
    description: >-
      Open, read, reply to and close support tickets. Tickets belong to the
      account holder and are not shared with team members.
paths:
  /servers/{server}/audit-log:
    get:
      tags:
        - Servers
      summary: List a server's audit log
      description: >-
        ### Overview


        Lists server activity, newest first. `per_page` defaults to 25 and
        accepts 1 to 100. Sort by `created_at` or `updated_at`, with `-` for
        descending order. Filter by `filter[action]`, `filter[user_id]` or
        `filter[user.email]`. By default, `user` contains only an email address.
        Add `?include=user` for full account details. The included `user` is
        null when you cannot view that account.


        ### Permissions


        Requires the `server.read` (View servers) permission for the selected
        team. Resources outside that team return 404.
      operationId: server.auditLogList
      parameters:
        - name: server
          in: path
          required: true
          description: The server UUID
          schema:
            type: string
            examples:
              - ecc6f4f1
          example: ecc6f4f1
        - name: per_page
          in: query
          description: The maximum number of records to return on one page.
          schema:
            type:
              - integer
              - 'null'
            examples:
              - 25
            minimum: 1
            maximum: 100
          example: 25
        - name: include
          in: query
          description: >-
            Related records to include, with multiple values separated by
            commas.
          schema:
            type: string
            examples:
              - user
          example: user
        - name: filter[user_id]
          in: query
          description: Filter records by user id.
          schema:
            type: string
            examples:
              - User id
          example: User id
        - name: filter[server_id]
          in: query
          description: Filter records by server id.
          schema:
            type: string
            examples:
              - Server id
          example: Server id
        - name: filter[action]
          in: query
          description: Filter records by action.
          schema:
            type: string
            examples:
              - resize_disk
          example: resize_disk
        - name: filter[user.email]
          in: query
          description: Filter records by user.email.
          schema:
            type: string
            examples:
              - gordon.freeman@blackmesa.example.com
          example: gordon.freeman@blackmesa.example.com
        - name: sort
          in: query
          description: The field to sort by, prefixed with `-` for descending order.
          schema:
            type: array
            default:
              - '-created_at'
            examples:
              - - created_at
            items:
              type: string
              enum:
                - created_at
                - '-created_at'
                - updated_at
                - '-updated_at'
          example:
            - created_at
          explode: false
      responses:
        '200':
          description: >-
            One page of results, with the rows under `data` and the paging
            figures beside them.
          content:
            application/json:
              schema:
                type: object
                examples:
                  - current_page: 1
                    data:
                      - id: 58214
                        server_id: 4821
                        user_id: 1873
                        action: power_action
                        description: 'Server power action: restart'
                        metadata:
                          action: restart
                          resource:
                            type: server
                            id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                            name: lambda-core
                        ip_address: 192.0.2.44
                        created_at: '2026-09-14T15:58:21.000000Z'
                        updated_at: '2026-09-14T15:58:21.000000Z'
                        user:
                          email: gordon.freeman@blackmesa.example.com
                    first_page_url: >-
                      https://vps.advinservers.com/api/v1/client/servers/ecc6f4f1/audit-log?page=1
                    from: 1
                    last_page: 1
                    last_page_url: >-
                      https://vps.advinservers.com/api/v1/client/servers/ecc6f4f1/audit-log?page=1
                    links:
                      - url: null
                        label: '&laquo; Previous'
                        page: null
                        active: false
                      - url: >-
                          https://vps.advinservers.com/api/v1/client/servers/ecc6f4f1/audit-log?page=1
                        label: '1'
                        page: 1
                        active: true
                      - url: null
                        label: Next &raquo;
                        page: null
                        active: false
                    next_page_url: null
                    path: >-
                      https://vps.advinservers.com/api/v1/client/servers/ecc6f4f1/audit-log
                    per_page: 50
                    prev_page_url: null
                    to: 1
                    total: 1
                properties:
                  current_page:
                    type: integer
                    description: Which page this is, counting from 1.
                    examples:
                      - 1
                  data:
                    type: array
                    description: The rows on this page.
                    examples:
                      - - id: 58214
                          server_id: 4821
                          user_id: 1873
                          action: power_action
                          description: 'Server power action: restart'
                          metadata:
                            action: restart
                            resource:
                              type: server
                              id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                              name: lambda-core
                          ip_address: 192.0.2.44
                          created_at: '2026-09-14T15:58:21.000000Z'
                          updated_at: '2026-09-14T15:58:21.000000Z'
                          user:
                            email: gordon.freeman@blackmesa.example.com
                    items:
                      $ref: '#/components/schemas/ServerAuditLogData'
                  first_page_url:
                    type: string
                    description: A link to the first page.
                  from:
                    type:
                      - integer
                      - 'null'
                    description: >-
                      The position of the first row on this page in the whole
                      result, or null when the page is empty.
                  last_page:
                    type: integer
                    description: How many pages there are.
                  last_page_url:
                    type: string
                    description: A link to the last page.
                  links:
                    type: array
                    description: Pagination links in display order.
                    items:
                      type: object
                      properties:
                        url:
                          type:
                            - string
                            - 'null'
                        label:
                          type: string
                        active:
                          type: boolean
                        page:
                          type:
                            - integer
                            - 'null'
                      required:
                        - url
                        - label
                        - active
                  next_page_url:
                    type:
                      - string
                      - 'null'
                    description: A link to the next page, or null on the last one.
                  path:
                    type: string
                    description: The base URL used for pagination.
                  per_page:
                    type: integer
                    description: How many rows a page holds.
                    examples:
                      - 50
                  prev_page_url:
                    type:
                      - string
                      - 'null'
                    description: A link to the previous page, or null on the first one.
                  to:
                    type:
                      - integer
                      - 'null'
                    description: >-
                      The position of the last row on this page, or null when
                      the page is empty.
                  total:
                    type: integer
                    description: How many rows there are altogether.
                required:
                  - current_page
                  - data
                  - first_page_url
                  - from
                  - last_page
                  - last_page_url
                  - links
                  - next_page_url
                  - path
                  - per_page
                  - prev_page_url
                  - to
                  - total
        '401':
          description: >-
            The key was missing, malformed, revoked, or belongs to an account
            that no longer exists.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Unauthenticated.
                required:
                  - message
        '403':
          description: >-
            Access denied. Check the key's team, permissions and allowed IP
            addresses. Some actions, such as managing API keys, require a
            browser session. The response message explains the reason.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - >-
                        This API key is not allowed to do that in this team. It
                        needs the "snapshot.delete" permission.
                required:
                  - message
        '404':
          description: >-
            The resource was not found in the selected team. Resources in
            another account or team also return 404.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Not found.
                required:
                  - message
        '429':
          description: >-
            Too many requests. The `Retry-After` header says how many seconds to
            wait. Limits are per account, so several keys on one account share
            them.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Too Many Attempts.
                required:
                  - message
components:
  schemas:
    ServerAuditLogData:
      type: object
      description: One audit log entry for a server.
      examples:
        - id: 58214
          server_id: 4821
          user_id: 1873
          action: power_action
          description: 'Server power action: restart'
          metadata:
            action: restart
            resource:
              type: server
              id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
              name: lambda-core
          ip_address: 192.0.2.44
          created_at: '2026-09-14T15:58:21.000000Z'
          updated_at: '2026-09-14T15:58:21.000000Z'
          user:
            email: gordon.freeman@blackmesa.example.com
      properties:
        id:
          type: integer
          description: The id ID.
          examples:
            - 58214
        server_id:
          type:
            - integer
            - 'null'
          description: The server id ID.
          examples:
            - 4821
        user_id:
          type:
            - integer
            - 'null'
          description: The user id ID.
          examples:
            - 1873
        action:
          type: string
          description: The value of `action`.
          examples:
            - power_action
        description:
          type:
            - string
            - 'null'
          description: An optional description shown to customers.
          examples:
            - 'Server power action: restart'
        metadata:
          description: The value of `metadata`.
          examples:
            - action: restart
              resource:
                type: server
                id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                name: lambda-core
          anyOf:
            - anyOf:
                - anyOf:
                    - type: object
                      additionalProperties: {}
                    - type: array
                      items: {}
                      maxItems: 0
                - type: 'null'
            - type: 'null'
        ip_address:
          type: string
          description: The value of `ip_address`.
          examples:
            - 192.0.2.44
        created_at:
          type:
            - string
            - 'null'
          description: The date and time for created at, in UTC.
          examples:
            - '2026-09-14T15:58:21.000000Z'
        updated_at:
          type:
            - string
            - 'null'
          description: The date and time for updated at, in UTC.
          examples:
            - '2026-09-14T15:58:21.000000Z'
        user:
          description: The account the entry is filed under.
          examples:
            - email: gordon.freeman@blackmesa.example.com
          anyOf:
            - anyOf:
                - $ref: '#/components/schemas/ServerAuditLogUserData'
                - $ref: '#/components/schemas/AccountOwnerData'
            - type: 'null'
      required:
        - id
        - server_id
        - user_id
        - action
        - description
        - metadata
        - ip_address
        - created_at
        - updated_at
        - user
      title: ServerAuditLogData
    ServerAuditLogUserData:
      type: object
      description: The account associated with a server audit log entry.
      examples:
        - email: gordon.freeman@blackmesa.example.com
      properties:
        email:
          type:
            - string
            - 'null'
          description: The email address.
          examples:
            - gordon.freeman@blackmesa.example.com
      required:
        - email
      title: ServerAuditLogUserData
    AccountOwnerData:
      type: object
      description: Whose key or script this is, in the two words a listing has room for.
      examples:
        - name: Gordon Freeman
          email: gordon.freeman@blackmesa.example.com
      properties:
        name:
          type: string
          description: The name shown to customers.
          examples:
            - Gordon Freeman
        email:
          type: string
          description: The email address.
          examples:
            - gordon.freeman@blackmesa.example.com
      required:
        - name
        - email
      title: AccountOwnerData
  securitySchemes:
    http:
      type: http
      description: >-
        Your API key, sent as a bearer token. Create one in the control panel
        under API Keys, give it only the permissions the integration needs, and
        copy it when it is created. It cannot be shown again. Each key is
        restricted to one owned team. The key determines the team for every
        request.
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.