Skip to content

Search the audit trail

Every governed action produces an audit event: who, what, the policy decision and version, the credential mode, the upstream transport, latency/status, and a safe error category. Audit is metadata‑only by design — it never stores raw tool arguments or secret material — which is what makes it safe to search, export, and ship to a SIEM.

Search the audit trail
gatewayctl search-audit --environment prod --decision deny --format json

Every gatewayctl verb accepts --format text|json.

To investigate one request end‑to‑end, fetch its bundle by request_id — the chain of events the gateway recorded for that call.

Read the audit bundle for one request
  1. From a search result, open the event and choose View request bundle.

Type set in Geist, Source Serif 4, and Departure Mono.