lhc audit-logs
Read the audit log — who changed what, and when. Requires admin role on all subcommands.
An empty result means no entry was written, which is not the same as nothing having happened. Reads (viewing a chart, running a query) and sign-ins are not recorded. See Audit Logging for what the log covers.
Commands
audit-logs list
lhc audit-logs list [--limit N] [--offset N]
| Flag | Default | Description |
|---|---|---|
--limit | 50 | Maximum number of entries |
--offset | 0 | Pagination offset |
Entries are returned newest first. The endpoint caps its page size at 200; larger windows are
fetched in chunks, so --limit 5000 works and never surfaces a pagination error.
audit-logs entity <type> <id>
lhc audit-logs entity <type> <id> [--query <text>] [--limit N] [--offset N]
The history of a single object — the same view the entity's Audit Log tab shows.
| Argument | Description |
|---|---|
<type> | MODEL, DATASOURCE, JOB_DEFINITION, CHART, DASHBOARD, USER, GROUP (case-insensitive) |
<id> | The object's id. For charts and dashboards this is the Lakehousecat id, not the Superset id |
| Flag | Default | Description |
|---|---|---|
--query | — | Filter by user, action, entity name or changed field; applies server-side across all pages |
An unknown <type> is rejected by the CLI. The API would answer it with an empty list, which is
indistinguishable from a genuinely empty history.
lhc audit-logs entity USER 3e7c3d4f-16ff-4914-8250-bbe693ab7224 --output json
lhc audit-logs entity CHART 42 --query shared
audit-logs search
lhc audit-logs search [--user <id>] [--action <action>] [--entity-type <type>] \
[--start <unix>] [--end <unix>] [--limit N] [--offset N]
All filters are optional and AND-combined.
| Flag | Description |
|---|---|
--user | Only entries caused by this user id |
--action | CREATE, UPDATE, DELETE, STATUS_CHANGE, APPROVE, REVOKE_APPROVAL, SHARE, UNSHARE |
--entity-type | One of the entity types listed above |
--start / --end | Timestamp bounds in Unix seconds |
lhc audit-logs search --action DELETE --output json
lhc audit-logs search --entity-type USER --start 1756000000
Entry fields
| Field | Meaning |
|---|---|
user_id | Who acted. For a share this is the person granting access, not receiving it |
action | The kind of change |
entity_type / entity_id | The object acted upon |
entity_name | Its name at the time of the entry, so a deleted object stays identifiable |
diff | Changed fields as {"field": {"old": …, "new": …}}, or null |
meta | Context — for SHARE / UNSHARE, the recipient |
Large fields such as a chart definition or a datasource connection are recorded as
{"changed_keys": [...]} rather than as values. Those fields can carry credentials, so the log
records that a key changed, never what it changed to.
Status codes
| Status | Meaning |
|---|---|
401 | Key invalid or revoked |
403 | Caller is not an administrator |
422 | A filter value the API rejects — check that --start / --end are Unix seconds |