events
Creates, updates, deletes, gets or lists an events resource.
Overview​
| Name | events |
| Type | Resource |
| Id | oci.audit.events |
Fields​
The following fields are returned by SELECT queries:
- list
All the attributes of an audit event. For more information, see [Viewing Audit Log Events](/iaas/Content/Audit/Tasks/viewinglogevents.htm).<br />
| Name | Datatype | Description |
|---|---|---|
cloudEventsVersion | string | The version of the CloudEvents specification. The structure of the envelope follows the [CloudEvents](https:​//github.com/cloudevents/spec) industry standard format hosted by the [Cloud Native Computing Foundation ( CNCF)](https:​//www.cncf.io/). Audit uses version 0.1 specification of the CloudEvents event envelope. Example: 0.1 |
contentType | string | The content type of the data contained in data. Example: application/json |
data | object | The payload of the event. Information within data comes from the resource emitting the event. (x-example: {<br /> "eventGroupingId": null,<br /> "eventName": "GetInstance",<br /> "compartmentId": "ocid1.tenancy.oc1..<var><unique_ID></var>",<br /> "compartmentName": "compartmentA",<br /> "resourceName": "my_instance",<br /> "resourceId": "ocid1.instance.oc1.phx.<var><unique_ID></var>",<br /> "availabilityDomain": "<availability_domain>",<br /> "freeformTags": null,<br /> "definedTags": null,<br /> "identity": {<br /> "principalName": "ExampleName",<br /> "principalId": "ocid1.user.oc1..<var><unique_ID></var>",<br /> "authType": "natv",<br /> "callerName": null,<br /> "callerId": null,<br /> "tenantId": "ocid1.tenancy.oc1..<var><unique_ID></var>",<br /> "ipAddress": "172.24.80.88",<br /> "credentials": null,<br /> "userAgent": "Jersey/2.23 (HttpUrlConnection 1.8.0_212)",<br /> "consoleSessionId": null<br /> },<br /> "request": {<br /> "id": "<var><unique_ID></var>",<br /> "path": "/20160918/instances/ocid1.instance.oc1.phx.<var><unique_ID></var>",<br /> "action": "GET",<br /> "parameters": {},<br /> "headers": {<br /> "opc-principal": [<br /> "{"tenantId":"ocid1.tenancy.oc1..<var><unique_ID></var>","subjectId":"ocid1.user.oc1..<var><unique_ID></var>","claims":[{"key":"pstype","value":"natv","issuer":"authService.oracle.com"},{"key":"h_host","value":"iaas.r2.oracleiaas.com","issuer":"h"},{"key":"h_opc-request-id","value":"<var><unique_ID></var>","issuer":"h"},{"key":"ptype","value":"user","issuer":"authService.oracle.com"},{"key":"h_date","value":"Wed, 18 Sep 2019 00:10:58 UTC","issuer":"h"},{"key":"h_accept","value":"application/json","issuer":"h"},{"key":"authorization","value":"Signature headers=\"date (request-target) host accept opc-request-id\",keyId=\"ocid1.tenancy.oc1..<var><unique_ID></var>/ocid1.user.oc1..<var><unique_ID></var>/8c:b4:5f:18:e7:ec:db:08:b8:fa:d2:2a:7d:11:76:ac\",algorithm=\"rsa-pss-sha256\",signature=\"<var><unique_ID></var>\",version=\"1\"","issuer":"h"},{"key":"h_(request-target)","value":"get /20160918/instances/ocid1.instance.oc1.phx.<var><unique_ID></var>","issuer":"h"}]}"<br /> ],<br /> "Accept": [<br /> "application/json"<br /> ],<br /> "X-Oracle-Auth-Client-CN": [<br /> "splat-proxy-se-02302.node.ad2.r2"<br /> ],<br /> "X-Forwarded-Host": [<br /> "compute-api.svc.ad1.r2"<br /> ],<br /> "Connection": [<br /> "close"<br /> ],<br /> "User-Agent": [<br /> "Jersey/2.23 (HttpUrlConnection 1.8.0_212)"<br /> ],<br /> "X-Forwarded-For": [<br /> "172.24.80.88"<br /> ],<br /> "X-Real-IP": [<br /> "172.24.80.88"<br /> ],<br /> "oci-original-url": [<br /> "https:​//iaas.r2.oracleiaas.com/20160918/instances/ocid1.instance.oc1.phx.<var><unique_ID></var>"<br /> ],<br /> "opc-request-id": [<br /> "<var><unique_ID></var>"<br /> ],<br /> "Date": [<br /> "Wed, 18 Sep 2019 00:10:58 UTC"<br /> ]<br /> }<br /> },<br /> "response": {<br /> "status": "200",<br /> "responseTime": "2019-09-18T00:10:59.278Z",<br /> "headers": {<br /> "ETag": [<br /> "<var><unique_ID></var>"<br /> ],<br /> "Connection": [<br /> "close"<br /> ],<br /> "Content-Length": [<br /> "1828"<br /> ],<br /> "opc-request-id": [<br /> "<var><unique_ID></var>"<br /> ],<br /> "Date": [<br /> "Wed, 18 Sep 2019 00:10:59 GMT"<br /> ],<br /> "Content-Type": [<br /> "application/json"<br /> ]<br /> },<br /> "payload": {<br /> "resourceName": "my_instance",<br /> "id": "ocid1.instance.oc1.phx.<var><unique_ID></var>"<br /> },<br /> "message": null<br /> },<br /> "stateChange": {<br /> "previous": null,<br /> "current": null<br /> },<br /> "additionalDetails": {<br /> "imageId": "ocid1.image.oc1.phx.<var><unique_ID></var>",<br /> "shape": "VM.Standard1.1",<br /> "type": "CustomerVmi"<br /> }<br />}<br />) |
eventId | string | The GUID of the event. |
eventTime | string (date-time) | The time the event occurred, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-09-18T00:10:59.252Z |
eventType | string | The type of event that happened. The service that produces the event can also add, remove, or change the meaning of a field. A service implementing these type changes would publish a new version of an eventType and revise the eventTypeVersion field. Example: com.oraclecloud.ComputeApi.GetInstance |
eventTypeVersion | string | The version of the event type. This version applies to the payload of the event, not the envelope. Use cloudEventsVersion to determine the version of the envelope. Example: 2.0 |
source | string | The source of the event. Example: ComputeApi |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | compartmentId, startTime, endTime, region | page, opc-request-id | Returns all the audit events processed for the specified compartment within the specified<br />time range.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The [OCID](/Content/General/Concepts/identifiers.htm) of the compartment. |
endTime | string (date-time) | Returns events that were processed before this end date and time, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. For example, a start value of 2017-01-01T00:00:00Z and an end value of 2017-01-02T00:00:00Z will retrieve a list of all events processed on January 1, 2017. Similarly, a start value of 2017-01-01T00:00:00Z and an end value of 2017-02-01T00:00:00Z will result in a list of all events processed between January 1, 2017 and January 31, 2017. You can specify a value with granularity to the minute. Seconds (and milliseconds, if included) must be set to 0. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
startTime | string (date-time) | Returns events that were processed at or after this start date and time, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. For example, a start value of 2017-01-15T11:30:00Z will retrieve a list of all events processed since 30 minutes after the 11th hour of January 15, 2017, in Coordinated Universal Time (UTC). You can specify a value with granularity to the minute. Seconds (and milliseconds, if included) must be set to 0. |
opc-request-id | string | Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
SELECT examples​
- list
Returns all the audit events processed for the specified compartment within the specified<br />time range.<br />
SELECT
cloudEventsVersion,
contentType,
data,
eventId,
eventTime,
eventType,
eventTypeVersion,
source
FROM oci.audit.events
WHERE compartmentId = '{{ compartmentId }}' -- required
AND startTime = '{{ startTime }}' -- required
AND endTime = '{{ endTime }}' -- required
AND region = '{{ region }}' -- required
AND page = '{{ page }}'
AND opc-request-id = '{{ opc-request-id }}'
;