Audit Events API

We are pleased to announce the Audit Events API, which allows you to retrieve a paginated log of administrative and system actions taken within your Sophos Central account.

Using this API you can query audit events by date range, actor, originating IP address, and resource owner. Results are returned in pages using cursor-based pagination, making it straightforward to walk through large volumes of event history.

Check out the Audit Events API Guide for end-to-end examples and a full description of query parameters and response fields.