> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/for-developers/rest-api/core/activity-log/list-activity-log-events.md).

# List activity log events

Supports filtering by time range, module, event type and username, plus a free-text search over event descriptions.

```json
{"openapi":"3.1.0","info":{"title":"defguard Core API","version":"2.0.3"},"tags":[{"name":"activity log","description":"Activity log events and activity log streams."}],"security":[{"cookie":[]},{"api_token":[]}],"components":{"securitySchemes":{"cookie":{"type":"apiKey","in":"cookie","name":"defguard_session"},"api_token":{"type":"http","scheme":"bearer"}},"schemas":{"PaginatedApiResponse_ApiActivityLogEvent":{"type":"object","description":"Envelope returned by paginated endpoints.","required":["data","pagination"],"properties":{"data":{"type":"array","items":{"type":"object","description":"Activity log event as returned by the API.","required":["id","timestamp","user_id","username","event","module","device"],"properties":{"description":{"type":["string","null"]},"device":{"type":"string"},"event":{"type":"string"},"id":{"$ref":"#/components/schemas/i64"},"ip":{"type":["string","null"]},"location":{"type":["string","null"]},"module":{"$ref":"#/components/schemas/ActivityLogModule"},"timestamp":{"type":"string","format":"date-time"},"user_id":{"$ref":"#/components/schemas/i64"},"username":{"type":"string"}}},"description":"Items of the requested page."},"pagination":{"$ref":"#/components/schemas/PaginationMeta"}}},"i64":{"type":"integer","format":"int64"},"ActivityLogModule":{"type":"string","enum":["defguard","client","vpn","enrollment"]},"PaginationMeta":{"type":"object","description":"Pagination metadata included in the response.","required":["current_page","page_size","total_items","total_pages"],"properties":{"current_page":{"type":"integer","format":"int32","description":"Number of the returned page, starting from 1.","minimum":0},"next_page":{"type":["integer","null"],"format":"int32","description":"Number of the next page, or `null` on the last page.","minimum":0},"page_size":{"type":"integer","format":"int32","description":"Requested page size.","minimum":0},"total_items":{"type":"integer","format":"int32","description":"Total number of items matching the query.","minimum":0},"total_pages":{"type":"integer","format":"int32","description":"Total number of pages for the requested page size.","minimum":0}}},"ApiErrorResponse":{"type":"object","description":"Body returned with error responses.","required":["msg"],"properties":{"code":{"type":["string","null"],"description":"Machine-readable error code, returned for selected errors."},"msg":{"type":"string","description":"Human-readable error message."}}}}},"paths":{"/api/v1/activity_log":{"get":{"tags":["activity log"],"summary":"List activity log events","description":"Supports filtering by time range, module, event type and username, plus a free-text search\nover event descriptions.","operationId":"get_activity_log_events","parameters":[{"name":"page","in":"query","description":"Page number. Defaults to 1.","required":false,"schema":{"type":"integer","format":"int32","minimum":0}},{"name":"per_page","in":"query","description":"Number of items per page, from 1 to 100. Defaults to 50.","required":false,"schema":{"type":"integer","format":"int32","minimum":0}},{"name":"from","in":"query","description":"Start of the reported period as an RFC 3339 timestamp.","required":false,"schema":{"type":"string"}},{"name":"until","in":"query","description":"End of the reported period as an RFC 3339 timestamp.","required":false,"schema":{"type":"string"}},{"name":"username","in":"query","description":"Filter by username. Admins only.","required":false,"schema":{"type":"string"}},{"name":"event","in":"query","description":"Filter by event type.","required":false,"schema":{"type":"string"}},{"name":"module","in":"query","description":"Filter by module.","required":false,"schema":{"type":"string"}},{"name":"search","in":"query","description":"Free-text search across username, location, module, event type, device, and description.","required":false,"schema":{"type":"string"}},{"name":"sort_by","in":"query","description":"Sort key: `timestamp`, `username`, `location`, `ip`, `event`, `module`, or `device`. Defaults to `timestamp`.","required":false,"schema":{"type":"string"}},{"name":"sort_order","in":"query","description":"Sort direction: `asc` or `desc`. Defaults to `desc`.","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"Paginated list of activity log events.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PaginatedApiResponse_ApiActivityLogEvent"}}}},"401":{"description":"Session is missing or invalid.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}},"500":{"description":"Unable to list activity log events.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}}}}}}}
```
