Audit logs are available under Infisical’s Pro, Advanced, and Enterprise plans, with retention that varies by plan.If you’re self-hosting Infisical, contact [email protected] to purchase an Enterprise license.

View audit logs
Anyone with the Read permission on Audit Logs has access to view audit logs. For more information, check out Role-based access controls.For an organization
To view all events in an organization across every product:- Infisical UI
- API
1
From your organization’s home page, go to Audit Logs.
2
Narrow down the results with filters.
For a product
To view all events scoped to a single product:- Infisical UI
- API
1
Open the product from the organization sidebar.
2
For Secrets Management, Certificate Manager, KMS, and Secret Scanning, select the project you want to audit.
For Privileged Access Manager and Agent Vault, skip this step.
3
Select Audit Logs in the product’s sidebar.
4
Narrow down the results with filters.
Log structure
Each log contains the following fields:string
The log entry’s UUID.
string
The source IP address of the request.
string
The raw
User-Agent header of the client.string
The client category:
web, cli, k8-operator, terraform, InfisicalPythonSDK, InfisicalNodeSDK, or other.string
When Infisical will delete the log entry, based on your plan’s retention.
string
When the action occurred, in ISO 8601 format.
string
Always equals
createdAt. Audit log entries are append-only.string
The organization the action occurred in.
string
The project the action affected. Empty for organization-level events.
string
The name of the project at the time of the action. Empty for organization-level events.
object
The action that occurred.
object
Who performed the action.
Example payload
Filtering audit logs
You can filter audit logs to find events more easily. When you set more than one filter, an event needs to match all of them to appear in the results.Every filter is an exact match, so wildcards like
* aren’t supported.By date
- Infisical UI
- API
Use the date range buttons at the top of the audit logs page. The page defaults to the last hour on load. Presets include 1 day, 1 week, 1 month, and 3 months, and the custom picker takes any range up to 3 months.
Advanced filters
- Infisical UI
- API
Select Search audit logs from the audit logs menu and choose the filter you want to add:
Actor ID filtering is only supported for actor types that carry an ID:
user, identity, service, kmipClient, kmipServer, gateway, relay, agentVaultProxy, acmeProfile, acmeAccount, estAccount, and scepAccount.platform, scimClient, and unknownUser don’t have an ID field and can only be filtered by type.Special characters
Every filter compares the raw string value as-is, so filter values that contain$, ., /, @, or any other special character work without escaping.
For example, to filter for a secret key named $DB/PROD.URL:
\$ is only there to stop the shell from expanding $DB as a variable. The filter itself takes $DB/PROD.URL as-is.
Filtering by event metadata
The API accepts aneventMetadata query parameter that matches key/value pairs inside event.metadata. Pass it as key1=value1,key2=value2. Every pair has to match on the same event.
Use it for queries the built-in filters can’t express, like every login for a specific identity, or every secret sync run for a specific destination:
Values that contain a literal
, can’t be filtered this way, because , separates the pairs. Values with = work: only the first = in each pair is treated as the separator, so the rest of the string passes through.Common filters
Here are a few common patterns for filtering audit logs, grouped by product.Secrets Manager
Who read a specific secret
Who read a specific secret
Find every read of
DATABASE_URL in the prod environment.- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
event:get-secretproject: the project holding the secretenvironment:prodsecret_key:DATABASE_URL
Who opened a folder
Who opened a folder
Find every time someone loaded the secrets in the
/db folder — for example, by opening it in the web UI, running infisical secrets, or having an app fetch it at startup. Each event records the folder, the actor, and how many secrets came back.- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
event:get-secretsproject: the project holding the folderenvironment:prodsecret_path:/db
All writes to production
All writes to production
Find every creation, update, and deletion of secrets in a project’s Include the batch event types (
prod environment over the last 7 days.- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add these filters:
event:create-secret,update-secret,delete-secret,create-secrets,update-secrets,delete-secretsproject: the project you want to auditenvironment:prod
create-secrets, update-secrets, delete-secrets) so that bulk changes from the CLI or SDKs aren’t missed. The environment filter only applies when a project is set.Who deleted a secret
Who deleted a secret
Find who removed a specific secret key. Include the batch event so single and bulk deletes are both matched.Read the actor column on each result to see who ran the delete. The
- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
event:delete-secret,delete-secretsproject: the project holding the secretsecret_key: the key that was deleted
secret_key filter only applies when a project is set.Certificate Manager
Recent certificate issuance
Recent certificate issuance
Find every certificate issued from a project in the last 7 days.The returned
Externally-issued certificates (from a linked external CA) don’t emit an issuance audit event when Infisical attaches the certificate. The
order-certificate-from-profile event captures the request at submit time (typically with event.metadata.status = pending), and Infisical doesn’t update the audit row later. To confirm which orders resulted in issued certificates, check the certificate list in Certificate Manager.- Infisical UI
- API
1
Go to Certificate Manager, select the project, and open Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
event:issue-cert,issue-pki-subscriber-cert,issue-certificate-from-profile
event.metadata varies by issuance path:issue-certrecords the certificate authority (CA), its distinguished name (DN), and serial number- Subscriber and profile events record the subscriber or profile ID and common name, with the serial number added once the certificate is issued
Who revoked a certificate
Who revoked a certificate
Find every revocation in a project.Read the actor column on each result to see who ran the revocation.
- Infisical UI
- API
1
Go to Certificate Manager, select the project, and open Audit Logs.
2
Select Search audit logs and add:
event:revoke-cert
KMS
Recent key use
Recent key use
Find every encryption, decryption, signature, and verification against KMS keys in a project.To narrow the results to a specific key, read
- Infisical UI
- API
1
Go to KMS, select the project, and open Audit Logs.
2
Select Search audit logs and add:
event:cmek-encrypt,cmek-decrypt,cmek-sign,cmek-verify
event.metadata.keyId on each row.Key lifecycle changes
Key lifecycle changes
Find every KMS key created, updated, or deleted in a project.
- Infisical UI
- API
1
Go to KMS, select the project, and open Audit Logs.
2
Select Search audit logs and add:
event:create-cmek,update-cmek,delete-cmek
Secret Scanning
Recent scan runs
Recent scan runs
Find every completed scan run in the last 7 days (both scheduled and on-demand). Each row represents one run, and To also see the request rows for on-demand scans (which fire before the run completes), add
event.metadata records the data source, the scan type, and the status. Successful runs also include numberOfSecretsDetected.- Infisical UI
- API
1
Go to Secret Scanning, select the project, and open Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
event:secret-scanning-data-source-scan
secret-scanning-data-source-trigger-scan to the event filter. On-demand scans then appear twice: once as a trigger and once as a completed run.Finding updates
Finding updates
View every finding an operator marked as remediated, dismissed, or otherwise updated.
- Infisical UI
- API
1
Go to Secret Scanning, select the project, and open Audit Logs.
2
Select Search audit logs and add:
event:secret-scanning-finding-update
Privileged Access Manager
All privileged sessions this week
All privileged sessions this week
Find every session start, end, or termination in the last 7 days.
- Infisical UI
- API
1
Go to PAM > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
event:pam-session-start,pam-session-end,pam-session-terminate
Who accessed a specific PAM account
Who accessed a specific PAM account
View all access to a PAM account using its account ID.Each result’s
- Infisical UI
- API
1
Go to PAM > Audit Logs.
2
Select Search audit logs and add:
event:pam-account-access,pam-account-credentials-view
event.metadata.accountId names the account and actor names the accessor.Agent Vault
Sessions issued this week
Sessions issued this week
Find every Agent Vault session minted or revoked over the last 7 days.
- Infisical UI
- API
1
Go to Agent Vault > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
event:agent-vault-session-mint,agent-vault-session-revoke
Proxy lifecycle events
Proxy lifecycle events
Find every proxy registration, enrollment, and revocation.
- Infisical UI
- API
1
Go to Agent Vault > Audit Logs.
2
Select Search audit logs and add:
event:agent-vault-proxy-register,agent-vault-proxy-enroll,agent-vault-proxy-revoke,agent-vault-proxy-delete
Identities and authentication
Everything a specific identity did
Everything a specific identity did
Investigate every action a machine identity took.
- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
actor:identityactor_id: the identity’s ID
Failed login attempts for an identity
Failed login attempts for an identity
Find failed login attempts by a machine identity, across every auth method.Extend the
- Infisical UI
- API
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
event:login-identity-universal-auth-failed,login-identity-kubernetes-auth-failed,login-identity-oidc-auth-failed,login-identity-gcp-auth-failed,login-identity-aws-auth-failed,login-identity-jwt-auth-failedactor:identityactor_id: the identity’s ID
event list to include any other *-failed variants your organization uses (SPIFFE, LDAP, AliCloud, and so on).Event types
Infisical emits hundreds of event types. Here are some of the most common ones you’ll encounter.Secrets
Secrets
Identities and authentication
Identities and authentication
Projects and access
Projects and access
Integrations and secret sync
Integrations and secret sync
Approvals
Approvals
Audit logs
Audit logs
Next steps
Stream audit logs
Forward audit logs to a SIEM, storage bucket, or observability stack.
ClickHouse storage backend
Keep queries fast when a self-hosted audit log table grows to hundreds of millions of rows.