Skip to main content
Audit logs are available under Infisical’s Pro, Advanced, and Enterprise plans, with retention that varies by plan.If you’re self-hosting Infisical, contact [email protected] to purchase an Enterprise license.
Infisical records every action performed in your organization as a structured event, so security and compliance teams can investigate incidents, prove access boundaries to auditors, and answer questions about who did what.
Audit logs

View audit logs

Anyone with the Read permission on Audit Logs has access to view audit logs. For more information, check out Role-based access controls.

For an organization

To view all events in an organization across every product:
1
From your organization’s home page, go to Audit Logs.
2
Narrow down the results with filters.

For a product

To view all events scoped to a single product:
1
Open the product from the organization sidebar.
2
For Secrets Management, Certificate Manager, KMS, and Secret Scanning, select the project you want to audit.
For Privileged Access Manager and Agent Vault, skip this step.
3
Select Audit Logs in the product’s sidebar.
4
Narrow down the results with filters.

Log structure

Each log contains the following fields:
string
The log entry’s UUID.
string
The source IP address of the request.
string
The raw User-Agent header of the client.
string
The client category: web, cli, k8-operator, terraform, InfisicalPythonSDK, InfisicalNodeSDK, or other.
string
When Infisical will delete the log entry, based on your plan’s retention.
string
When the action occurred, in ISO 8601 format.
string
Always equals createdAt. Audit log entries are append-only.
string
The organization the action occurred in.
string
The project the action affected. Empty for organization-level events.
string
The name of the project at the time of the action. Empty for organization-level events.
object
The action that occurred.
object
Who performed the action.

Example payload

Filtering audit logs

You can filter audit logs to find events more easily. When you set more than one filter, an event needs to match all of them to appear in the results.
Every filter is an exact match, so wildcards like * aren’t supported.

By date

Use the date range buttons at the top of the audit logs page. The page defaults to the last hour on load. Presets include 1 day, 1 week, 1 month, and 3 months, and the custom picker takes any range up to 3 months.

Advanced filters

Select Search audit logs from the audit logs menu and choose the filter you want to add:
Actor ID filtering is only supported for actor types that carry an ID: user, identity, service, kmipClient, kmipServer, gateway, relay, agentVaultProxy, acmeProfile, acmeAccount, estAccount, and scepAccount.platform, scimClient, and unknownUser don’t have an ID field and can only be filtered by type.

Special characters

Every filter compares the raw string value as-is, so filter values that contain $, ., /, @, or any other special character work without escaping. For example, to filter for a secret key named $DB/PROD.URL:
In the above example, \$ is only there to stop the shell from expanding $DB as a variable. The filter itself takes $DB/PROD.URL as-is.

Filtering by event metadata

The API accepts an eventMetadata query parameter that matches key/value pairs inside event.metadata. Pass it as key1=value1,key2=value2. Every pair has to match on the same event. Use it for queries the built-in filters can’t express, like every login for a specific identity, or every secret sync run for a specific destination:
Values that contain a literal , can’t be filtered this way, because , separates the pairs. Values with = work: only the first = in each pair is treated as the separator, so the rest of the string passes through.

Common filters

Here are a few common patterns for filtering audit logs, grouped by product.

Secrets Manager

Find every read of DATABASE_URL in the prod environment.
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
  • event: get-secret
  • project: the project holding the secret
  • environment: prod
  • secret_key: DATABASE_URL
Find every time someone loaded the secrets in the /db folder — for example, by opening it in the web UI, running infisical secrets, or having an app fetch it at startup. Each event records the folder, the actor, and how many secrets came back.
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
  • event: get-secrets
  • project: the project holding the folder
  • environment: prod
  • secret_path: /db
Find every creation, update, and deletion of secrets in a project’s prod environment over the last 7 days.
1
Go to Organization > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add these filters:
  • event: create-secret, update-secret, delete-secret, create-secrets, update-secrets, delete-secrets
  • project: the project you want to audit
  • environment: prod
Include the batch event types (create-secrets, update-secrets, delete-secrets) so that bulk changes from the CLI or SDKs aren’t missed. The environment filter only applies when a project is set.
Find who removed a specific secret key. Include the batch event so single and bulk deletes are both matched.
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
  • event: delete-secret, delete-secrets
  • project: the project holding the secret
  • secret_key: the key that was deleted
Read the actor column on each result to see who ran the delete. The secret_key filter only applies when a project is set.

Certificate Manager

Find every certificate issued from a project in the last 7 days.
Externally-issued certificates (from a linked external CA) don’t emit an issuance audit event when Infisical attaches the certificate. The order-certificate-from-profile event captures the request at submit time (typically with event.metadata.status = pending), and Infisical doesn’t update the audit row later. To confirm which orders resulted in issued certificates, check the certificate list in Certificate Manager.
1
Go to Certificate Manager, select the project, and open Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
  • event: issue-cert, issue-pki-subscriber-cert, issue-certificate-from-profile
The returned event.metadata varies by issuance path:
  • issue-cert records the certificate authority (CA), its distinguished name (DN), and serial number
  • Subscriber and profile events record the subscriber or profile ID and common name, with the serial number added once the certificate is issued
Find every revocation in a project.
1
Go to Certificate Manager, select the project, and open Audit Logs.
2
Select Search audit logs and add:
  • event: revoke-cert
Read the actor column on each result to see who ran the revocation.

KMS

Find every encryption, decryption, signature, and verification against KMS keys in a project.
1
Go to KMS, select the project, and open Audit Logs.
2
Select Search audit logs and add:
  • event: cmek-encrypt, cmek-decrypt, cmek-sign, cmek-verify
To narrow the results to a specific key, read event.metadata.keyId on each row.
Find every KMS key created, updated, or deleted in a project.
1
Go to KMS, select the project, and open Audit Logs.
2
Select Search audit logs and add:
  • event: create-cmek, update-cmek, delete-cmek

Secret Scanning

Find every completed scan run in the last 7 days (both scheduled and on-demand). Each row represents one run, and event.metadata records the data source, the scan type, and the status. Successful runs also include numberOfSecretsDetected.
1
Go to Secret Scanning, select the project, and open Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
  • event: secret-scanning-data-source-scan
To also see the request rows for on-demand scans (which fire before the run completes), add secret-scanning-data-source-trigger-scan to the event filter. On-demand scans then appear twice: once as a trigger and once as a completed run.
View every finding an operator marked as remediated, dismissed, or otherwise updated.
1
Go to Secret Scanning, select the project, and open Audit Logs.
2
Select Search audit logs and add:
  • event: secret-scanning-finding-update

Privileged Access Manager

Find every session start, end, or termination in the last 7 days.
1
Go to PAM > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
  • event: pam-session-start, pam-session-end, pam-session-terminate
View all access to a PAM account using its account ID.
1
Go to PAM > Audit Logs.
2
Select Search audit logs and add:
  • event: pam-account-access, pam-account-credentials-view
Each result’s event.metadata.accountId names the account and actor names the accessor.

Agent Vault

Find every Agent Vault session minted or revoked over the last 7 days.
1
Go to Agent Vault > Audit Logs.
2
Set the date range to the last 7 days.
3
Select Search audit logs and add:
  • event: agent-vault-session-mint, agent-vault-session-revoke
Find every proxy registration, enrollment, and revocation.
1
Go to Agent Vault > Audit Logs.
2
Select Search audit logs and add:
  • event: agent-vault-proxy-register, agent-vault-proxy-enroll, agent-vault-proxy-revoke, agent-vault-proxy-delete

Identities and authentication

Investigate every action a machine identity took.
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
  • actor: identity
  • actor_id: the identity’s ID
Find failed login attempts by a machine identity, across every auth method.
1
Go to Organization > Audit Logs.
2
Select Search audit logs and add these filters:
  • event: login-identity-universal-auth-failed, login-identity-kubernetes-auth-failed, login-identity-oidc-auth-failed, login-identity-gcp-auth-failed, login-identity-aws-auth-failed, login-identity-jwt-auth-failed
  • actor: identity
  • actor_id: the identity’s ID
Extend the event list to include any other *-failed variants your organization uses (SPIFFE, LDAP, AliCloud, and so on).

Event types

Infisical emits hundreds of event types. Here are some of the most common ones you’ll encounter.
For the full event catalog and every field the API accepts, see the audit log export API reference.

Next steps

Stream audit logs

Forward audit logs to a SIEM, storage bucket, or observability stack.

ClickHouse storage backend

Keep queries fast when a self-hosted audit log table grows to hundreds of millions of rows.