---
title: "Get one event"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

Path: Trails API › events

`GET /v1/organizations/{orgId}/events/{eventId}`

## Authentication

Requires one of the following:

- `apiKey`, http, header `Authorization`
- `oauth`, http, header `Authorization`
- `sessionCookie`, apiKey, in cookie

## Path parameters

- `GetEvent.path.orgId` (string, required) — The organization.
  - format `uuid`
- `GetEvent.path.eventId` (string, required) — The event's eventId.
  - format `uuid`

## Code samples

### cURL

```curl
curl --request GET \
  --url https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events/497f6eca-6276-4993-bfeb-53cbbbba6f08 \
  --header 'Authorization: Bearer <token>'
```

### TypeScript

```typescript
const url = 'https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events/497f6eca-6276-4993-bfeb-53cbbbba6f08';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

fetch(url, options)
  .then(res => res.json())
  .then(json => console.log(json))
  .catch(err => console.error(err));
```

### Python

```python
import requests

url = "https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events/497f6eca-6276-4993-bfeb-53cbbbba6f08"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.text)
```

## Responses

### 200

The event.

#### Example

```json
{
  "additionalEventData": {},
  "errorCode": "string",
  "errorMessage": "string",
  "eventCategory": "string",
  "eventId": "d6703cc8-9e79-415d-ac03-a4dc7f6ab43c",
  "eventName": "string",
  "eventSource": "string",
  "eventTime": "2019-08-24T14:15:22Z",
  "eventType": "string",
  "eventVersion": "string",
  "organizationId": "7bc05553-4b68-44e8-b7bc-37be63c6d9e9",
  "projectId": "string",
  "readOnly": true,
  "region": "string",
  "requestId": "string",
  "requestParameters": {},
  "resources": [
    {
      "resourceName": "string",
      "type": "string"
    }
  ],
  "responseElements": {},
  "sourceIpAddress": "string",
  "userAgent": "string",
  "userIdentity": {
    "accessKeyId": "string",
    "invokedBy": "string",
    "isRoot": true,
    "principalId": "string",
    "sessionContext": {
      "clientId": "string",
      "credential": "string",
      "mfaAuthenticated": true,
      "sessionIssuedAt": "string",
      "ssoProviderId": "string"
    },
    "type": "string",
    "userName": "string"
  }
}
```

- `GetEvent.response.200.eventCategory` (string, required)
- `GetEvent.response.200.eventId` (string, required)
  - format `uuid`
- `GetEvent.response.200.eventName` (string, required) — The operation: CreateWidget, LookupEvents.
- `GetEvent.response.200.eventSource` (string, required) — `<namespace>.ezghcloud.com`.
- `GetEvent.response.200.eventTime` (string, required)
  - format `date-time`
- `GetEvent.response.200.eventType` (string, required) — ApiCall, ServiceEvent or SignIn.
- `GetEvent.response.200.eventVersion` (string, required) — "1.0".
- `GetEvent.response.200.organizationId` (string, required)
  - format `uuid`
- `GetEvent.response.200.readOnly` (boolean, required)
- `GetEvent.response.200.region` (string, required)
- `GetEvent.response.200.resources` (array<object>, required)
  - `GetEvent.response.200.resources.resourceName` (string, required)
  - `GetEvent.response.200.resources.type` (string, required) — Organization, Project, Widget…
- `GetEvent.response.200.userIdentity` (object, required) — Who made the call.
  - `GetEvent.response.200.userIdentity.isRoot` (boolean, required)
  - `GetEvent.response.200.userIdentity.accessKeyId` (string | null, optional)
  - `GetEvent.response.200.userIdentity.invokedBy` (string | null, optional) — A service event's cause: the public namespace that made the change.
  - `GetEvent.response.200.userIdentity.principalId` (string | null, optional)
  - `GetEvent.response.200.userIdentity.sessionContext` (one of, optional)
    - one of: [SessionContext](/trails-api/schemas/SessionContext/), `null`
  - `GetEvent.response.200.userIdentity.type` (string | null, optional) — User, Bot, Root or EzghService.
  - `GetEvent.response.200.userIdentity.userName` (string | null, optional)
- `GetEvent.response.200.additionalEventData` (object | null, optional)
- `GetEvent.response.200.errorCode` (string | null, optional)
- `GetEvent.response.200.errorMessage` (string | null, optional)
- `GetEvent.response.200.projectId` (string | null, optional)
- `GetEvent.response.200.requestId` (string | null, optional)
- `GetEvent.response.200.requestParameters` (object | null, optional) — Path and query parameters and the body's top-level fields, secrets hidden.
- `GetEvent.response.200.responseElements` (object | null, optional) — A successful write's identifiers.
- `GetEvent.response.200.sourceIpAddress` (string | null, optional)
- `GetEvent.response.200.userAgent` (string | null, optional)

### 400

invalid_request, invalid_cursor, invalid_query (with line and column), or lookup_too_broad.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.400.error` (object, required)
  - `GetEvent.response.400.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.400.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.400.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.400.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.400.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.400.error.quota.id` (string, required)
    - `GetEvent.response.400.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.400.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.400.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.400.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.400.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.400.error.quota.region` (string, optional)
    - `GetEvent.response.400.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.400.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.400.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.400.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.400.error.reason` (string, optional) — query_failed: the query's own error code.

### 401

unauthenticated: no credential, or one that doesn't check out.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.401.error` (object, required)
  - `GetEvent.response.401.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.401.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.401.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.401.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.401.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.401.error.quota.id` (string, required)
    - `GetEvent.response.401.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.401.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.401.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.401.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.401.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.401.error.quota.region` (string, optional)
    - `GetEvent.response.401.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.401.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.401.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.401.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.401.error.reason` (string, optional) — query_failed: the query's own error code.

### 403

access_denied: the caller's policies don't allow the action; forbidden_origin: a cookie-authenticated write from an origin that isn't allowed.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.403.error` (object, required)
  - `GetEvent.response.403.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.403.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.403.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.403.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.403.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.403.error.quota.id` (string, required)
    - `GetEvent.response.403.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.403.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.403.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.403.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.403.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.403.error.quota.region` (string, optional)
    - `GetEvent.response.403.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.403.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.403.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.403.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.403.error.reason` (string, optional) — query_failed: the query's own error code.

### 404

not_found: unknown, malformed, or in an organization the caller isn't in.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.404.error` (object, required)
  - `GetEvent.response.404.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.404.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.404.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.404.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.404.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.404.error.quota.id` (string, required)
    - `GetEvent.response.404.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.404.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.404.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.404.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.404.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.404.error.quota.region` (string, optional)
    - `GetEvent.response.404.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.404.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.404.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.404.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.404.error.reason` (string, optional) — query_failed: the query's own error code.

### 429

too_many_requests or too_many_queries, with Retry-After; or quota_exceeded (with quota), never with Retry-After.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.429.error` (object, required)
  - `GetEvent.response.429.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.429.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.429.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.429.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.429.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.429.error.quota.id` (string, required)
    - `GetEvent.response.429.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.429.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.429.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.429.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.429.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.429.error.quota.region` (string, optional)
    - `GetEvent.response.429.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.429.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.429.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.429.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.429.error.reason` (string, optional) — query_failed: the query's own error code.

### 500

internal_error: a bug; the details are in the logs, under the request ID.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.500.error` (object, required)
  - `GetEvent.response.500.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.500.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.500.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.500.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.500.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.500.error.quota.id` (string, required)
    - `GetEvent.response.500.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.500.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.500.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.500.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.500.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.500.error.quota.region` (string, optional)
    - `GetEvent.response.500.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.500.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.500.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.500.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.500.error.reason` (string, optional) — query_failed: the query's own error code.

### 503

unavailable: a dependency the request needs is down. Retry after Retry-After.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `GetEvent.response.503.error` (object, required)
  - `GetEvent.response.503.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `GetEvent.response.503.error.message` (string, required)
    - maxLength 1024
  - `GetEvent.response.503.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.503.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `GetEvent.response.503.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `GetEvent.response.503.error.quota.id` (string, required)
    - `GetEvent.response.503.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `GetEvent.response.503.error.quota.limit` (integer, required)
      - min 0
    - `GetEvent.response.503.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `GetEvent.response.503.error.quota.inFlight` (integer, optional)
      - min 0
    - `GetEvent.response.503.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `GetEvent.response.503.error.quota.region` (string, optional)
    - `GetEvent.response.503.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `GetEvent.response.503.error.quota.scopeResourceName` (string, optional)
    - `GetEvent.response.503.error.quota.used` (integer, optional)
      - min 0
    - `GetEvent.response.503.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `GetEvent.response.503.error.reason` (string, optional) — query_failed: the query's own error code.


Source: https://docs.ezghcloud.com/trails-api/events/GetEvent/index.md
