---
title: "Search the organization's Trails, newest first"
description: "Without `from`, the last 7 days. Unknown parameters are 400. A search that reads too much is 400 lookup_too_broad: narrow the window or add filters."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

Path: Trails API › events

`GET /v1/organizations/{orgId}/events`

Without `from`, the last 7 days. Unknown parameters are 400. A search that reads too much is 400 lookup_too_broad: narrow the window or add filters.

## Authentication

Requires one of the following:

- `apiKey`, http, header `Authorization`
- `oauth`, http, header `Authorization`
- `sessionCookie`, apiKey, in cookie

## Path parameters

- `LookupEvents.path.orgId` (string, required) — The organization.
  - format `uuid`

## Query parameters

- `LookupEvents.query.from` (string, optional) — Inclusive, RFC 3339. Default: 7 days ago.
  - format `date-time`
- `LookupEvents.query.to` (string, optional) — Exclusive, RFC 3339.
  - format `date-time`
- `LookupEvents.query.eventSource` (string, optional) — widgets.ezghcloud.com
- `LookupEvents.query.eventName` (string, optional) — CreateWidget
- `LookupEvents.query.eventType` (string, optional) — ApiCall, ServiceEvent or SignIn.
- `LookupEvents.query.principalId` (string, optional)
- `LookupEvents.query.accessKeyId` (string, optional)
- `LookupEvents.query.resourceName` (string, optional) — Events that touched this resource.
- `LookupEvents.query.errorCode` (string, optional)
- `LookupEvents.query.readOnly` (boolean, optional)
- `LookupEvents.query.hasError` (boolean, optional)
- `LookupEvents.query.projectId` (string, optional)
  - format `uuid`
- `LookupEvents.query.limit` (integer, optional) — Default 20.
  - format `int32`; min 1; max 100
- `LookupEvents.query.cursor` (string, optional) — The previous page's nextCursor, for the same filters.

## Code samples

### cURL

```curl
curl --request GET \
  --url https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events \
  --header 'Authorization: Bearer <token>'
```

### TypeScript

```typescript
const url = 'https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

fetch(url, options)
  .then(res => res.json())
  .then(json => console.log(json))
  .catch(err => console.error(err));
```

### Python

```python
import requests

url = "https://audit.ezghcloud.com/v1/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/events"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.text)
```

## Responses

### 200

A page of events.

#### Example

```json
{
  "events": [
    {
      "additionalEventData": {},
      "errorCode": "string",
      "errorMessage": "string",
      "eventCategory": "string",
      "eventId": "d6703cc8-9e79-415d-ac03-a4dc7f6ab43c",
      "eventName": "string",
      "eventSource": "string",
      "eventTime": "2019-08-24T14:15:22Z",
      "eventType": "string",
      "eventVersion": "string",
      "organizationId": "7bc05553-4b68-44e8-b7bc-37be63c6d9e9",
      "projectId": "string",
      "readOnly": true,
      "region": "string",
      "requestId": "string",
      "requestParameters": {},
      "resources": [
        {
          "resourceName": "string",
          "type": "string"
        }
      ],
      "responseElements": {},
      "sourceIpAddress": "string",
      "userAgent": "string",
      "userIdentity": {
        "accessKeyId": "string",
        "invokedBy": "string",
        "isRoot": true,
        "principalId": "string",
        "sessionContext": {
          "clientId": "string",
          "credential": "string",
          "mfaAuthenticated": true,
          "sessionIssuedAt": "string",
          "ssoProviderId": "string"
        },
        "type": "string",
        "userName": "string"
      }
    }
  ],
  "nextCursor": "string"
}
```

- `LookupEvents.response.200.events` (array<object>, required)
  - `LookupEvents.response.200.events.eventCategory` (string, required)
  - `LookupEvents.response.200.events.eventId` (string, required)
    - format `uuid`
  - `LookupEvents.response.200.events.eventName` (string, required) — The operation: CreateWidget, LookupEvents.
  - `LookupEvents.response.200.events.eventSource` (string, required) — `<namespace>.ezghcloud.com`.
  - `LookupEvents.response.200.events.eventTime` (string, required)
    - format `date-time`
  - `LookupEvents.response.200.events.eventType` (string, required) — ApiCall, ServiceEvent or SignIn.
  - `LookupEvents.response.200.events.eventVersion` (string, required) — "1.0".
  - `LookupEvents.response.200.events.organizationId` (string, required)
    - format `uuid`
  - `LookupEvents.response.200.events.readOnly` (boolean, required)
  - `LookupEvents.response.200.events.region` (string, required)
  - `LookupEvents.response.200.events.resources` (array<object>, required)
    - `LookupEvents.response.200.events.resources.resourceName` (string, required)
    - `LookupEvents.response.200.events.resources.type` (string, required) — Organization, Project, Widget…
  - `LookupEvents.response.200.events.userIdentity` (object, required) — Who made the call.
    - `LookupEvents.response.200.events.userIdentity.isRoot` (boolean, required)
    - `LookupEvents.response.200.events.userIdentity.accessKeyId` (string | null, optional)
    - `LookupEvents.response.200.events.userIdentity.invokedBy` (string | null, optional) — A service event's cause: the public namespace that made the change.
    - `LookupEvents.response.200.events.userIdentity.principalId` (string | null, optional)
    - `LookupEvents.response.200.events.userIdentity.sessionContext` (one of, optional)
      - one of: [SessionContext](/trails-api/schemas/SessionContext/), `null`
    - `LookupEvents.response.200.events.userIdentity.type` (string | null, optional) — User, Bot, Root or EzghService.
    - `LookupEvents.response.200.events.userIdentity.userName` (string | null, optional)
  - `LookupEvents.response.200.events.additionalEventData` (object | null, optional)
  - `LookupEvents.response.200.events.errorCode` (string | null, optional)
  - `LookupEvents.response.200.events.errorMessage` (string | null, optional)
  - `LookupEvents.response.200.events.projectId` (string | null, optional)
  - `LookupEvents.response.200.events.requestId` (string | null, optional)
  - `LookupEvents.response.200.events.requestParameters` (object | null, optional) — Path and query parameters and the body's top-level fields, secrets hidden.
  - `LookupEvents.response.200.events.responseElements` (object | null, optional) — A successful write's identifiers.
  - `LookupEvents.response.200.events.sourceIpAddress` (string | null, optional)
  - `LookupEvents.response.200.events.userAgent` (string | null, optional)
- `LookupEvents.response.200.nextCursor` (string | null, optional)

### 400

invalid_request, invalid_cursor, invalid_query (with line and column), or lookup_too_broad.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.400.error` (object, required)
  - `LookupEvents.response.400.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.400.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.400.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.400.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.400.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.400.error.quota.id` (string, required)
    - `LookupEvents.response.400.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.400.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.400.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.400.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.400.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.400.error.quota.region` (string, optional)
    - `LookupEvents.response.400.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.400.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.400.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.400.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.400.error.reason` (string, optional) — query_failed: the query's own error code.

### 401

unauthenticated: no credential, or one that doesn't check out.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.401.error` (object, required)
  - `LookupEvents.response.401.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.401.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.401.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.401.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.401.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.401.error.quota.id` (string, required)
    - `LookupEvents.response.401.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.401.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.401.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.401.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.401.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.401.error.quota.region` (string, optional)
    - `LookupEvents.response.401.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.401.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.401.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.401.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.401.error.reason` (string, optional) — query_failed: the query's own error code.

### 403

access_denied: the caller's policies don't allow the action; forbidden_origin: a cookie-authenticated write from an origin that isn't allowed.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.403.error` (object, required)
  - `LookupEvents.response.403.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.403.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.403.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.403.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.403.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.403.error.quota.id` (string, required)
    - `LookupEvents.response.403.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.403.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.403.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.403.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.403.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.403.error.quota.region` (string, optional)
    - `LookupEvents.response.403.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.403.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.403.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.403.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.403.error.reason` (string, optional) — query_failed: the query's own error code.

### 404

not_found: unknown, malformed, or in an organization the caller isn't in.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.404.error` (object, required)
  - `LookupEvents.response.404.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.404.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.404.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.404.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.404.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.404.error.quota.id` (string, required)
    - `LookupEvents.response.404.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.404.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.404.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.404.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.404.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.404.error.quota.region` (string, optional)
    - `LookupEvents.response.404.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.404.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.404.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.404.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.404.error.reason` (string, optional) — query_failed: the query's own error code.

### 429

too_many_requests or too_many_queries, with Retry-After; or quota_exceeded (with quota), never with Retry-After.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.429.error` (object, required)
  - `LookupEvents.response.429.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.429.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.429.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.429.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.429.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.429.error.quota.id` (string, required)
    - `LookupEvents.response.429.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.429.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.429.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.429.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.429.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.429.error.quota.region` (string, optional)
    - `LookupEvents.response.429.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.429.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.429.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.429.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.429.error.reason` (string, optional) — query_failed: the query's own error code.

### 500

internal_error: a bug; the details are in the logs, under the request ID.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.500.error` (object, required)
  - `LookupEvents.response.500.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.500.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.500.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.500.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.500.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.500.error.quota.id` (string, required)
    - `LookupEvents.response.500.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.500.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.500.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.500.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.500.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.500.error.quota.region` (string, optional)
    - `LookupEvents.response.500.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.500.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.500.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.500.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.500.error.reason` (string, optional) — query_failed: the query's own error code.

### 503

unavailable: a dependency the request needs is down. Retry after Retry-After.

#### Example

```json
{
  "error": {
    "code": "string",
    "column": 0,
    "line": 0,
    "message": "string",
    "quota": {
      "id": "string",
      "inFlight": 0,
      "kind": "allocation",
      "limit": 0,
      "periodStart": "2019-08-24T14:15:22Z",
      "region": "string",
      "resetsAt": "2019-08-24T14:15:22Z",
      "scope": "organization",
      "scopeResourceName": "string",
      "used": 0,
      "window": "string"
    },
    "reason": "string"
  }
}
```

- `LookupEvents.response.503.error` (object, required)
  - `LookupEvents.response.503.error.code` (string, required)
    - maxLength 64; pattern `^[a-z][a-z0-9_]*$`
  - `LookupEvents.response.503.error.message` (string, required)
    - maxLength 1024
  - `LookupEvents.response.503.error.column` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.503.error.line` (integer, optional) — invalid_query: where the SQL went wrong.
  - `LookupEvents.response.503.error.quota` (object, optional) — quota_exceeded: the quota that refused the request. Trails Query's are audit.queries.queriesPerHour and audit.queries.bytesReadPerHour, rate quotas with a PT1H window. Never with Retry-After.
    - `LookupEvents.response.503.error.quota.id` (string, required)
    - `LookupEvents.response.503.error.quota.kind` (unknown, required)
      - one of `"allocation"`, `"rate"`, `"usage"`, `"concurrency"`
    - `LookupEvents.response.503.error.quota.limit` (integer, required)
      - min 0
    - `LookupEvents.response.503.error.quota.scope` (unknown, required)
      - one of `"organization"`, `"project"`, `"resource"`
    - `LookupEvents.response.503.error.quota.inFlight` (integer, optional)
      - min 0
    - `LookupEvents.response.503.error.quota.periodStart` (string, optional)
      - format `date-time`
    - `LookupEvents.response.503.error.quota.region` (string, optional)
    - `LookupEvents.response.503.error.quota.resetsAt` (string, optional)
      - format `date-time`
    - `LookupEvents.response.503.error.quota.scopeResourceName` (string, optional)
    - `LookupEvents.response.503.error.quota.used` (integer, optional)
      - min 0
    - `LookupEvents.response.503.error.quota.window` (string, optional) — rate only: an ISO 8601 duration, PT1S to PT1H.
  - `LookupEvents.response.503.error.reason` (string, optional) — query_failed: the query's own error code.


Source: https://docs.ezghcloud.com/trails-api/events/LookupEvents/index.md
