Skip to main content
Version: Next

lhc audit-logs

Read the audit log — who changed what, and when. Requires admin role on all subcommands.

An empty result means no entry was written, which is not the same as nothing having happened. Reads (viewing a chart, running a query) and sign-ins are not recorded. See Audit Logging for what the log covers.

Commands​

audit-logs list​

lhc audit-logs list [--limit N] [--offset N]
FlagDefaultDescription
--limit50Maximum number of entries
--offset0Pagination offset

Entries are returned newest first. The endpoint caps its page size at 200; larger windows are fetched in chunks, so --limit 5000 works and never surfaces a pagination error.


audit-logs entity <type> <id>​

lhc audit-logs entity <type> <id> [--query <text>] [--limit N] [--offset N]

The history of a single object — the same view the entity's Audit Log tab shows.

ArgumentDescription
<type>MODEL, DATASOURCE, JOB_DEFINITION, CHART, DASHBOARD, USER, GROUP (case-insensitive)
<id>The object's id. For charts and dashboards this is the Lakehousecat id, not the Superset id
FlagDefaultDescription
--query—Filter by user, action, entity name or changed field; applies server-side across all pages

An unknown <type> is rejected by the CLI. The API would answer it with an empty list, which is indistinguishable from a genuinely empty history.

lhc audit-logs entity USER 3e7c3d4f-16ff-4914-8250-bbe693ab7224 --output json
lhc audit-logs entity CHART 42 --query shared

lhc audit-logs search [--user <id>] [--action <action>] [--entity-type <type>] \
[--start <unix>] [--end <unix>] [--limit N] [--offset N]

All filters are optional and AND-combined.

FlagDescription
--userOnly entries caused by this user id
--actionCREATE, UPDATE, DELETE, STATUS_CHANGE, APPROVE, REVOKE_APPROVAL, SHARE, UNSHARE
--entity-typeOne of the entity types listed above
--start / --endTimestamp bounds in Unix seconds
lhc audit-logs search --action DELETE --output json
lhc audit-logs search --entity-type USER --start 1756000000

Entry fields​

FieldMeaning
user_idWho acted. For a share this is the person granting access, not receiving it
actionThe kind of change
entity_type / entity_idThe object acted upon
entity_nameIts name at the time of the entry, so a deleted object stays identifiable
diffChanged fields as {"field": {"old": …, "new": …}}, or null
metaContext — for SHARE / UNSHARE, the recipient

Large fields such as a chart definition or a datasource connection are recorded as {"changed_keys": [...]} rather than as values. Those fields can carry credentials, so the log records that a key changed, never what it changed to.

Status codes​

StatusMeaning
401Key invalid or revoked
403Caller is not an administrator
422A filter value the API rejects — check that --start / --end are Unix seconds