Search
Search returns audit events filtered by finding, actor, type, or app. Authorized as VIEWER — the same role required to read the finding itself.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Body
The FindingAuditServiceSearchRequest message.
The actorPrincipalId field.
Partial match via full-text search over the denormalized actor email / display name column.
Empty skips the filter; non-empty must be a 27-char alphanumeric id.
Filter by one or more event types. Empty means any.
FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED, FINDING_AUDIT_EVENT_TYPE_CREATED, FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED, FINDING_AUDIT_EVENT_TYPE_SNOOZED, FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED, FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED, FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED, FINDING_AUDIT_EVENT_TYPE_SUPPRESSED, FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED, FINDING_AUDIT_EVENT_TYPE_RESOLVED, FINDING_AUDIT_EVENT_TYPE_REOPENED, FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED, FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN, FINDING_AUDIT_EVENT_TYPE_COMMENT, FINDING_AUDIT_EVENT_TYPE_TASK_CREATED, FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED, FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED, FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED Filter to a single finding. The detail-page timeline uses this. Empty skips the filter; non-empty must be a 27-char alphanumeric id.
The pageSize field.
The pageToken field.