Skip to content

Event format

The fields of a Trails event, what each one holds, and an example.

Updated View as Markdown

Each Trails event is a JSON object in the same shape wherever you read it: the console’s Event record, GetEvent, LookupEvents and ezgh trails events get -o json.

Example

A bot creates an OCR processor with an API key:

{
  "eventVersion": "1.0",
  "eventId": "0199a3d0-3c4d-7e5f-a061-7c8d9e0f1a2b",
  "eventTime": "2026-09-28T09:58:02.114Z",
  "eventType": "ApiCall",
  "eventCategory": "Management",
  "eventSource": "ocr.ezghcloud.com",
  "eventName": "CreateProcessor",
  "readOnly": false,
  "region": "us-west-1",
  "organizationId": "0199a3c2-5b1e-7d40-9f3a-2c8e6b1d4f70",
  "projectId": "0199a3c2-6c2f-7e51-8a4b-3d9f7c2e5a81",
  "userIdentity": {
    "type": "Bot",
    "principalId": "0199a3c4-0d1e-7f20-8a3b-4c5d6e7f8091",
    "userName": "deployer",
    "isRoot": false,
    "accessKeyId": "0199a3c4-1e2f-7a31-9b4c-5d6e7f809102",
    "sessionContext": {
      "credential": "apiKey",
      "sessionIssuedAt": null,
      "ssoProviderId": null,
      "mfaAuthenticated": false,
      "clientId": null
    },
    "invokedBy": null
  },
  "sourceIpAddress": "203.0.113.9",
  "userAgent": "curl/8.7.1",
  "requestParameters": {
    "orgId": "0199a3c2-5b1e-7d40-9f3a-2c8e6b1d4f70",
    "projectId": "0199a3c2-6c2f-7e51-8a4b-3d9f7c2e5a81",
    "name": "Receipts",
    "model": "unlimited-ocr",
    "modelVersion": "latest",
    "languages": ["en"],
    "outputFormat": "text",
    "options": { "detail": "high" }
  },
  "responseElements": {
    "id": "0199a3d0-2b3c-7d4e-9f50-6b7c8d9e0f1a",
    "slug": "prc_4k2m9x0a7qpe",
    "name": "Receipts",
    "resourceName": "ezgh:us-west-1:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:prc_4k2m9x0a7qpe"
  },
  "additionalEventData": null,
  "errorCode": null,
  "errorMessage": null,
  "resources": [
    { "resourceName": "ezgh::org_k3f9a0x2m7qp", "type": "Organization" },
    { "resourceName": "ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2", "type": "Project" },
    { "resourceName": "ezgh:us-west-1:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:prc_4k2m9x0a7qpe", "type": "Processor" }
  ],
  "requestId": "0199a3d0-3b4c-7d5e-8f60-7a8b9c0d1e2f"
}

A refused call has the same shape. These fields differ: responseElements is null, and errorCode and errorMessage hold the error the caller received.

{
  "responseElements": null,
  "errorCode": "access_denied",
  "errorMessage": "This API key isn't allowed to ocr.processors.create"
}

Fields

Every field is always present. Fields without a value are null.

Field Type Description
eventVersion string The event format’s version: 1.0.
eventId string The event’s ID, a UUID.
eventTime string When the request arrived, in UTC with milliseconds: 2026-09-28T09:58:02.114Z.
eventType string ApiCall for an API call, SignIn for sign-in and sign-out, ServiceEvent for a change the platform made on its own.
eventCategory string Management.
eventSource string The API namespace the call was made to, such as iam.ezghcloud.com. See event sources.
eventName string The operation, such as CreateApiKey or ProcessDocument.
readOnly boolean true when the request only read (GET or HEAD).
region string The region that recorded the event: us-west-1.
organizationId string The organization the event belongs to.
projectId string or null The project the call was about, or null for organization-level calls.
userIdentity object Who acted. See userIdentity.
sourceIpAddress string or null The caller’s IP address, up to 64 characters. null for service events.
userAgent string or null The caller’s User-Agent, cut to 512 characters.
requestParameters object or null The request’s path parameters, query parameters and top-level body fields, with secrets hidden. null when the request had none.
responseElements object or null For a successful write, the identifiers of what it created or changed: id, slug, name, resourceName, prefix and expiresAt, at the top level of the response or one object down, plus fields an operation adds. null for reads and failures. Never contains a token or secret.
additionalEventData object or null Extra data an operation records, else null.
errorCode string or null The error code the caller received, such as access_denied, up to 64 characters. null on success.
errorMessage string or null The error message the caller received, up to 1,024 characters. null on success.
resources array The resources the call touched, up to 50. Each is { "resourceName", "type" }, where type is the resource type, such as Organization, Project, Bot or Processor.
requestId string or null The request’s ID, from its X-Request-Id header.

A whole event is at most 64 KiB.

userIdentity

Field Type Description
type string Root (the organization’s root user), User, Bot, EzghService (the platform, for a service event) or Unknown.
principalId string or null The user’s or bot’s ID.
userName string or null The user’s email address or the bot’s name when the event happened.
isRoot boolean Whether the caller is the organization’s root user.
accessKeyId string or null The ID of the API key used, or null if no API key was used.
sessionContext object or null How the caller authenticated. null for service events.
sessionContext.credential string session (signed in to the console), apiKey (an API key) or oauth (an OAuth access token, such as the ezgh CLI’s).
sessionContext.sessionIssuedAt string or null When the session or sign-in began, when known.
sessionContext.ssoProviderId string or null The SSO identity provider used to sign in, if any.
sessionContext.mfaAuthenticated boolean Whether the session used multi-factor authentication.
sessionContext.clientId string or null For oauth, the OAuth client, such as ezgh-cli. null otherwise.
invokedBy string or null For a service event, the API namespace that caused the change, such as billing.ezghcloud.com.

Hidden values

In requestParameters, the value of any field whose name contains token, secret, password, authorization, cookie, apikey, privatekey or credential (in any case, at any depth) is replaced with HIDDEN_DUE_TO_SECURITY_REASONS. Operations also hide fields of their own, such as an OCR processor’s description and tags. Values nested more than 6 levels deep become "[truncated]", and arrays keep their first 100 items. Headers are never recorded.

For ProcessDocument, requestParameters holds only the document’s metadata: pageCount (the number of pages selected), bytes (the document’s size), mimeType (its detected type) and pages (the page numbers selected).

Resource names

resourceName identifies a resource across EZGH Cloud. After ezgh: comes the region (empty for resources that aren’t regional), then the slugs of the organization, project and resource:

Resource Format
Organization ezgh::org_…
Project ezgh::org_…:prj_…
Organization-level resource, such as a bot ezgh::org_…:bot_…
Regional resource in a project, such as an OCR processor ezgh:us-west-1:org_…:prj_…:prc_…

Filter by a resource name to see every event that touched it. See Look up events.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close