BlueConic Audit Events API

The Audit Event API allows users to connect BlueConic to a SIEM system. We recommend using this API to periodically receive security-related activities based on a rolling window. The API has a 30-day retention period. The API logs the following audit events: | Object | Events | |:---------------------------|:-----------------------------------------------------------------------------------------------| | BlueConic hostname | Create, Update, Delete | | BlueConic Support Access | Update (for each change) | | Channel | Create, Update, Delete | | Clean up rule | Create, Update, Delete | | Connection | Create, Update, Delete, Manual run, Scheduled run | | Dashboard | Create, Update, Delete | | Dialogue | Create, Update, Delete | | Domain Group | Create, Update, Delete | | Gen AI Setting | Update (for each change) | | Group | Read, Update, Delete | | Group type | Create, Update, Delete | | Ip range | Create, Update, Delete | | Language | Create, Update, Delete | | Lifecycle | Create, Update, Delete | | Merge rule | Create, Update, Delete | | Models | Create, Update, Delete | | Notebook | Create, Update, Delete, Manual run, Scheduled run, Editor run | | OAuth application | Create, Update, Delete | | OAuth token | Create, Update, Delete | | Objective | Create, Update, Delete | | Plugin | Create, Update, Delete | | Privacy setting | Update (for each change) | | Profile | Read, Update, Delete | | Profile property | Create, Update, Delete | | Role | Create, Update, Delete | | Segment | Create, Update, Delete | | Single Sign On Setting | Update (for each change) | | Inactvity Setting | Update (for each change) | | Supported Legislation Zone | Create, Delete, Update | | Timeline Event Rollup | Create, Update, Delete | | Timeline Event Type | Create, Update, Delete | | Tracker | Create, Update, Delete | | User | Login, Login failed, Logout, Create, Update, Delete, Password reset requested, Password change | Only Profile and Group viewed, updated, or deleted by a user from the Profile and Groups tab are logged. The following events are not considered as human actions, and therefore not covered in the Platform Audit Event API: - Connections that import or export profiles. - Profile and group creation (Profiles can only be created by a visitor or an import connection). **Event data** The following event data is available: | Field | Description | Example values | | :--- | :--- |:-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| |date|Datetime in UTC when the event occurred. The date is in the https://www.ietf.org/rfc/rfc3339.txt format.| 2025-04-15T11:24:01.183Z | |username|(BlueConic) Identifier (email address) of the user who did the action.Value is empty for failed login attempts.| test@blueconic.com | |objectType|Object of the action.| BLUECONIC_HOSTNAMEBLUECONIC_SUPPORT_ACCESS_SETTINGCHANNELCLEAN_UP_RULECONNECTIONDASHBOARDDIALOGUEDOMAIN_GROUPGEN_AI_SETTINGGROUPGROUP_TYPEIP_RANGELANGUAGELIFECYCLELISTENERMERGE_RULENOTEBOOKOBJECTIVEPLUGINPRIVACY_SETTINGPROFILEPROFILE_PROPERTYROLESEGMENTSINGLE_SIGN_ON_SETTINGSUPPORTED_LEGISLATION_ZONETRACKERUSER | |objectId|Email address in case of a user. In the case of LOGIN_FAILED and a user tried to login with an invalid format email address, it could be that the user filled the password in the email address field. In that case the objectId is emptyGrouptype_GroupID in case of a group For PRIVACY_SETTING and SINGLE_SIGN_ON_SETTING, the objectId is the name(s) of the changed setting. E.g. Status, Identity_Provider_Issuer_URL_Entity_ID. For BLUECONIC_SUPPORT_ACCESS_SETTING the objectID contains the new settings. `"objects" : [ {"name" : "No Access", "id" : "none" } ]` or `"objects" : [ {"name" : "User name here", "id" : "user1@blueconic.com" },{"name" : "User name 2 here", "id" : "user2@blueconic.com" }], (contains the new list)` or`"objects" : [ {"name" : "All BlueConic support employees", "id" : "all" } ],`UUID or identifier in case of other object types.| 1b1e50a5-c46a-4309-a95c-d4e19985fbbbtest@blueconic.comtest_objectivetest_profile_property | |objectName|Human readable name of the object.For Profiles, the name is determined by the first value that is not empty:fullnameemailBlueConic ID (UUID)For Users, the name is determined by the first value that is not empty:fullnameemailIn the case of LOGIN_FAILED and a user tried to login with an invalid format email address, it could be that the user filled the password in the email address field. In that case, the objectName is empty.For groups, the name is the group id.For PRIVACY_SETTING and SINGLE_SIGN_ON_SETTING, the objectName is the name(s) of the changed setting. E.g. Status, Identity_Provider_Issuer_URL_Entity_ID.For BLUECONIC_SUPPORT_ACCESS_SETTING the objectName contains the new settings.`"objects" : [ {"name" : "No Access", "id" : "none" } ]` or `"objects" : [ {"name" : "User name here", "id" : "user1@blueconic.com" },{"name" : "User name 2 here", "id" : "user2@blueconic.com" }],` (contains the new list) or`"objects" : [ {"name" : "All BlueConic support employees", "id" : "all" } ],`| SFTP connectiontest@blueconic.omKeyword Interest Ranking | |operation| Action performed on the object. | CREATEUPDATEDELETEEDITOR_RUNREADLOGINLOGIN_FAILEDLOGOUTMANUAL_RUNPASSWORD_RESET_REQUESTEDPASSWORD_CHANGESCHEDULED_RUN |ipAddress| The source IP address from which the event was triggered. | 192.168.1.100 | |application| The application that performed the audit event operation. | blueconic |

Operations 1

GET /auditEvents Get audit events #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/blueconic-audit-events-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

blueconic-audit-events-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: BlueConic REST API v2 Audit Events API
  description: Welcome to the BlueConic REST API v2.
  termsOfService: https://www.blueconic.com/blueconic-terms-and-conditions
  contact:
    name: Contact us
    url: https://support.blueconic.com/hc/en-us/requests/new
  license:
    name: BlueConic
    url: https://github.com/blueconic/openapi/blob/main/LICENSE.MD
  version: '100.0'
servers:
- url: https://{blueconicHostname}/rest/v2
  description: The BlueConic server
  variables:
    blueconicHostname:
      description: BlueConic server hostname, e.g. 'tenant.blueconic.net'
      default: tenantname
tags:
- name: Audit Events
  description: The Audit Event API allows users to connect BlueConic to a SIEM system.
paths:
  /auditEvents:
    get:
      tags:
      - Audit Events
      summary: Get audit events
      description: Retrieves the audit events.
      operationId: getAuditEvents
      parameters:
      - name: fromDate
        in: query
        description: Only return entries that are created later than this date. The fromDate is in the ISO 8601 format (e.g. '2025-01-22T11:21:33.872Z').
        schema:
          type: string
        example: 2025-01-22 11:21:33.872000+00:00
      - name: count
        in: query
        description: Page size for the result.<br />Maximum limit is 1000
        schema:
          type: integer
          format: int32
          default: 100
      responses:
        '200':
          description: Returns the audit events.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditEventsBean'
              examples:
                Example response:
                  description: Example response
                  value: "{\n  \"auditEvents\": [\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2025-04-15T11:21:33.872Z\",\n      \"userName\": \"test@blueconic.com\",\n      \"objects\": [\n        {\n          \"id\": \"68a02413-98d0-4a2b-b65c-4617a3c26fd0\",\n          \"name\": \"Campaign Tracker Listener ds\"\n        }\n      ],\n      \"objectType\": \"LISTENER\",\n      \"operation\": \"UPDATE\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2025-04-15T11:21:33.672Z\",\n      \"userName\": \"test@blueconic.com\",\n      \"objectType\": \"PROFILEPROPERTY\",\n      \"objects\": [\n        {\n          \"id\": \"responded_to_campaigns\",\n          \"name\": \"responded_to_campaigns\"\n        }\n      ],\n      \"operation\": \"CREATE\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2023-04-15T12:51:32.702Z\",\n      \"userName\": \"test@blueconic.com\",\n      \"objectType\": \"USER\",\n      \"objects\": [\n        {\n          \"id\": \"test@blueconic.com\",\n          \"name\": \"test@blueconic.com\"\n        }\n      ],\n      \"operation\": \"LOGIN\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2023-04-15T12:51:32.702Z\",\n      \"objectType\": \"USER\",\n      \"objects\": [\n        {\n          \"id\": \"wrongpassword@blueconic.com\",\n          \"name\": \"wrongpassword@blueconic.com\"\n        }\n      ],\n      \"operation\": \"LOGIN_FAILED\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2023-04-15T12:51:32.702Z\",\n      \"objectType\": \"USER\",\n      \"objects\": [\n        {\n          \"id\": \"\",\n          \"name\": \"\"\n        }\n      ],\n      \"operation\": \"LOGIN_FAILED\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2023-04-15T12:51:32.702Z\",\n      \"objectType\": \"USER\",\n      \"objects\": [\n        {\n          \"id\": \"nonexistinguserName@blueconic.com\",\n          \"name\": \"nonexistinguserName@blueconic.com\"\n        }\n      ],\n      \"operation\": \"LOGIN_FAILED\",\n      \"ipAddress\": \"192.168.1.100\"\n    },\n    {\n      \"application\": \"blueconic\",\n      \"date\": \"2023-04-15T12:51:32.702Z\",\n      \"userName\": \"test@blueconic.com\",\n      \"objectType\": \"PROFILE\",\n      \"objects\": [\n        {\n          \"id\": \"4dc2a97e-707e-4049-a03a-badcce564f3c\",\n          \"name\": \"4dc2a97e-707e-4049-a03a-badcce564f3c\"\n        },\n        {\n          \"id\": \"test@blueconic.com\",\n          \"name\": \"33f53658-3dc8-4946-b239-ecb65dea9827\"\n        }\n      ],\n      \"operation\": \"READ\",\n      \"ipAddress\": \"192.168.1.100\"\n    }\n  ]\n}"
        '400':
          description: One or more required parameters are missing or invalid.
        '401':
          description: Authentication failed (unauthorized).
      security:
      - oauth2:
        - read:audit-events
components:
  schemas:
    AuditEntryBean:
      type: object
      properties:
        application:
          type: string
        date:
          type: string
          format: date-time
          description: Datetime in UTC when the event occurred. The date is in the https://www.ietf.org/rfc/rfc3339.txt format, example = "2025-01-22T11:21:33.872Z".
        ipAddress:
          type: string
        objectType:
          type: string
          enum:
          - DIALOGUE
          - LISTENER
          - CONNECTION
          - VARIANT
          - SEGMENT
          - PROFILE_PROPERTY
          - GROUP_PROPERTY
          - TRACKER
          - DASHBOARD
          - LIFECYCLE
          - PLUGIN
          - USER
          - ROLE
          - CHANNEL
          - BLUECONIC_HOSTNAME
          - LANGUAGE
          - CONTENTSTORE
          - STATISTICS
          - FAVORITE
          - TEMPLATE
          - NOTEBOOK
          - PRIORITY
          - GROUP_TYPE
          - CLEANUP_RULE
          - MERGE_RULE
          - COMPOSITION_RULE
          - OBJECTIVE
          - TIMELINE_EVENT_TYPE
          - PROFILE
          - IP_RANGE
          - GROUP
          - SUPPORTED_LEGISLATION_ZONE
          - DOMAIN_GROUP
          - DOMAIN
          - PRIVACY_SETTING
          - SINGLE_SIGN_ON_SETTING
          - BLUECONIC_SUPPORT_ACCESS_SETTING
          - OAUTH_APPLICATION
          - OAUTH_TOKEN
          - TIMELINE_EVENT_ROLLUP
          - INACTIVITY_SETTING
          - AI_CANVAS
          - MODEL
          - GEN_AI_SETTING
        objects:
          type: array
          items:
            $ref: '#/components/schemas/AuditEntryObjectBean'
        operation:
          type: string
          enum:
          - CREATE
          - UPDATE
          - DELETE
          - READ
          - LOGIN
          - LOGOUT
          - LOGIN_FAILED
          - PROFILE_MERGE_TRIGGERED_BY_USER
          - PASSWORD_RESET_REQUESTED
          - PASSWORD_CHANGE
          - MANUAL_RUN
          - SCHEDULED_RUN
          - EDITOR_RUN
        username:
          type: string
      required:
      - date
      - objectType
      - operation
    AuditEventsBean:
      type: object
      properties:
        auditEvents:
          type: array
          items:
            $ref: '#/components/schemas/AuditEntryBean'
    AuditEntryObjectBean:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
  securitySchemes:
    oauth2:
      type: oauth2
      description: 'Authenticates a registered OAuth 2.0 client. The Authorization code flow and Client credentials flow are supported. Make sure to select the correct flow based on which flow the registered client supports. The client id and client secret can be found in BlueConic by opening the registered client under *Settings* > *Access management* > *Applications*.<br/>**NOTE:** When using the Authorization code flow, the redirect URL of the registered client in BlueConic must be set to `https://rest.apidoc.blueconic.com/oauth-receiver.html` and ''Send Proof Key for Code Exchange'' must be enabled.<br/><br/>To use a Bearer token for authentication, follow these steps: <br/>1. Acquire the token through authentication.<br/>2. Include the token in the request''s Authorization header as Bearer \<token\>.<br/>3. Send the request to access protected resources.<br/>4. Handle token expiration by refreshing or obtaining a new token.'
      flows:
        clientCredentials:
          tokenUrl: /rest/v2/oauth/token
        authorizationCode:
          authorizationUrl: /rest/v2/oauth/authorize
          tokenUrl: /rest/v2/oauth/token
          refreshUrl: /rest/v2/oauth/token