{"type":"api","title":"List Event Logs","meta":{"id":"/apps/pubhub/media/Meraki-Dashboard-API-v1-Documentation/14ef7049b5106a90d0c4b9d056dd0529931d50a2/906c5292-7ca5-3d85-bb6d-da1ee73c8be6","info":{"title":"Meraki Dashboard API","description":"A RESTful API to programmatically manage and monitor Cisco Meraki networks at scale.\n\n\u003e Date: 09 September, 2026\n\u003e\n\u003e [Recent Updates](https://meraki.io/whats-new/)\n\n---\n\n[API Documentation](https://meraki.io/api)\n\n[Community Support](https://meraki.io/community)\n\n[Meraki Homepage](https://www.meraki.com)\n","contact":{"name":"Meraki Developer Community","url":"https://meraki.io/community"},"version":"1.74.0-beta.1"},"security":[{"meraki_api_key":[]},{"bearerAuth":[]},{"oauth2":[]}],"tags":[{"name":"organizations"},{"name":"networks"},{"name":"devices"},{"name":"insight"},{"name":"wireless"},{"name":"camera"},{"name":"appliance"},{"name":"switch"},{"name":"cellularGateway"},{"name":"sm"},{"name":"sensor"},{"name":"administered"},{"name":"campusGateway"},{"name":"users"},{"name":"wirelessController"},{"name":"spaces"},{"name":"support"},{"name":"assistant"},{"name":"accelerometer"},{"name":"accessControlLists"},{"name":"accessGroups"},{"name":"accessPolicies"},{"name":"account"},{"name":"accounts"},{"name":"aclHitCount"},{"name":"acls"},{"name":"actionBatches"},{"name":"activities"},{"name":"adaptivePolicy"},{"name":"adaptivePolicyGroups"},{"name":"addressFamilies"},{"name":"addresses"},{"name":"administrators"},{"name":"admins"},{"name":"afc"},{"name":"airMarshal"},{"name":"alertTypes"},{"name":"alerts"},{"name":"allowlist"},{"name":"alternateManagementInterface"},{"name":"analytics"},{"name":"api"},{"name":"apiRequests"},{"name":"apnsCert"},{"name":"apple"},{"name":"appliances"},{"name":"application"},{"name":"applicationCategories"},{"name":"applicationUsage"},{"name":"applications"},{"name":"areas"},{"name":"arpInspection"},{"name":"arpTable"},{"name":"artifacts"},{"name":"assets"},{"name":"assignments"},{"name":"association"},{"name":"attributes"},{"name":"auth"},{"name":"authZones"},{"name":"authentication"},{"name":"authenticationToken"},{"name":"authorities"},{"name":"authorization"},{"name":"authorizations"},{"name":"autoLocate"},{"name":"autoRf"},{"name":"automate"},{"name":"automations"},{"name":"autonomousSystems"},{"name":"availabilities"},{"name":"azure"},{"name":"bands"},{"name":"bandwidthUsageHistory"},{"name":"bgp"},{"name":"bgpSessionStatus"},{"name":"billing"},{"name":"blink"},{"name":"bluetooth"},{"name":"bluetoothClients"},{"name":"bonjourForwarding"},{"name":"boots"},{"name":"boundaries"},{"name":"brandingPolicies"},{"name":"buildings"},{"name":"bulk"},{"name":"bulkAdd"},{"name":"bulkCreate"},{"name":"bulkDelete"},{"name":"bulkEdit"},{"name":"bulkEnrollment"},{"name":"bulkRemove"},{"name":"bulkUpdate"},{"name":"bulkUpload"},{"name":"byAdmin"},{"name":"byApplication"},{"name":"byAutonomousSystem"},{"name":"byBand"},{"name":"byBoundary"},{"name":"byClient"},{"name":"byClientOs"},{"name":"byClientType"},{"name":"byCluster"},{"name":"byDevice"},{"name":"byEnergyUsage"},{"name":"byFilterList"},{"name":"byGroup"},{"name":"byInterval"},{"name":"byMetric"},{"name":"byModel"},{"name":"byNetwork"},{"name":"byNewDevice"},{"name":"byOperation"},{"name":"byPeerGroup"},{"name":"byPipeline"},{"name":"byPort"},{"name":"byPrefixList"},{"name":"byProfile"},{"name":"byRouter"},{"name":"byServer"},{"name":"byServerType"},{"name":"bySite"},{"name":"bySourceIp"},{"name":"bySsid"},{"name":"byStack"},{"name":"byStatus"},{"name":"bySwitch"},{"name":"bySwitchProfile"},{"name":"byType"},{"name":"byUsage"},{"name":"byUtilization"},{"name":"byVlan"},{"name":"byVrf"},{"name":"bypassActivationLockAttempts"},{"name":"cableTest"},{"name":"callbacks"},{"name":"capabilities"},{"name":"captures"},{"name":"categories"},{"name":"cellular"},{"name":"cellularFirewallRules"},{"name":"cellularUsageHistory"},{"name":"certificateAuthority"},{"name":"certificates"},{"name":"certs"},{"name":"changeHistory"},{"name":"changelogs"},{"name":"channelAvailability"},{"name":"channelUtilization"},{"name":"channelUtilizationHistory"},{"name":"channels"},{"name":"chat"},{"name":"checkup"},{"name":"claim"},{"name":"claimKey"},{"name":"clientCountHistory"},{"name":"clientExclusion"},{"name":"clients"},{"name":"cloud"},{"name":"cloudEnrollment"},{"name":"clusters"},{"name":"commands"},{"name":"communicationPlans"},{"name":"completions"},{"name":"compliance"},{"name":"compute"},{"name":"config"},{"name":"configTemplates"},{"name":"configurationChanges"},{"name":"configurations"},{"name":"configure"},{"name":"configuredDevices"},{"name":"connectedCountHistory"},{"name":"connectionStats"},{"name":"connections"},{"name":"connectivity"},{"name":"connectivityEvents"},{"name":"connectivityMonitoringDestinations"},{"name":"connectors"},{"name":"contentFiltering"},{"name":"contents"},{"name":"controller"},{"name":"correlated"},{"name":"coterm"},{"name":"coverage"},{"name":"cpu"},{"name":"credentials"},{"name":"crls"},{"name":"current"},{"name":"customAnalytics"},{"name":"customPerformanceClasses"},{"name":"cycle"},{"name":"data"},{"name":"dataRate"},{"name":"dataRateHistory"},{"name":"defaultContent"},{"name":"delegated"},{"name":"deltas"},{"name":"deploy"},{"name":"deployable"},{"name":"deployed"},{"name":"deployments"},{"name":"descriptors"},{"name":"desktopLogs"},{"name":"details"},{"name":"detections"},{"name":"deviceCommandLogs"},{"name":"deviceProfiles"},{"name":"deviceTypeGroupPolicies"},{"name":"dhcp"},{"name":"dhcpLeases"},{"name":"dhcpServerPolicy"},{"name":"dictionaries"},{"name":"disconnect"},{"name":"discover"},{"name":"discovered"},{"name":"discovery"},{"name":"disenrollments"},{"name":"dns"},{"name":"domains"},{"name":"doorLocks"},{"name":"download"},{"name":"downloadUrl"},{"name":"dscpTaggingOptions"},{"name":"dscpToCosMappings"},{"name":"eapOverride"},{"name":"earlyAccess"},{"name":"electronicShelfLabel"},{"name":"eligible"},{"name":"enrollments"},{"name":"entitlements"},{"name":"entries"},{"name":"eox"},{"name":"errors"},{"name":"esims"},{"name":"ethernet"},{"name":"eventLogs"},{"name":"eventTypes"},{"name":"events"},{"name":"exclusions"},{"name":"experience"},{"name":"extensions"},{"name":"facets"},{"name":"failedConnections"},{"name":"failover"},{"name":"failures"},{"name":"featureTiers"},{"name":"features"},{"name":"feedback"},{"name":"fetchTableQuery"},{"name":"fields"},{"name":"filterLists"},{"name":"filters"},{"name":"firewall"},{"name":"firewalledServices"},{"name":"firmware"},{"name":"firmwareUpgrades"},{"name":"floorPlans"},{"name":"gateways"},{"name":"gcp"},{"name":"geolocations"},{"name":"global"},{"name":"group"},{"name":"groupPolicies"},{"name":"groups"},{"name":"health"},{"name":"healthByTime"},{"name":"healthScores"},{"name":"histogram"},{"name":"historical"},{"name":"history"},{"name":"hosts"},{"name":"hotspot20"},{"name":"httpServers"},{"name":"httpsi"},{"name":"hubs"},{"name":"iam"},{"name":"identities"},{"name":"identity"},{"name":"identityPsks"},{"name":"idps"},{"name":"impacted"},{"name":"impactedDevice"},{"name":"import"},{"name":"inboundCellularFirewallRules"},{"name":"inboundFirewallRules"},{"name":"insights"},{"name":"integrate"},{"name":"integration"},{"name":"integrations"},{"name":"interconnects"},{"name":"interfaces"},{"name":"internetPolicies"},{"name":"intrusion"},{"name":"inventory"},{"name":"ipAssignment"},{"name":"ipsec"},{"name":"ipv6"},{"name":"isolation"},{"name":"jobs"},{"name":"json"},{"name":"keys"},{"name":"l2"},{"name":"l3"},{"name":"l3FirewallRules"},{"name":"l7FirewallRules"},{"name":"lan"},{"name":"lanLink"},{"name":"lanStp"},{"name":"latency"},{"name":"latencyHistory"},{"name":"latencyStats"},{"name":"latest"},{"name":"leds"},{"name":"license"},{"name":"licenses"},{"name":"licensing"},{"name":"lines"},{"name":"linkAggregations"},{"name":"linkLayer"},{"name":"links"},{"name":"listenRanges"},{"name":"live"},{"name":"liveTools"},{"name":"lldpCdp"},{"name":"load"},{"name":"local"},{"name":"localOverrides"},{"name":"location"},{"name":"locationScanning"},{"name":"loginSecurity"},{"name":"logins"},{"name":"logs"},{"name":"lookups"},{"name":"lossAndLatencyHistory"},{"name":"lowPower"},{"name":"macTable"},{"name":"malware"},{"name":"managementInterface"},{"name":"manufacturers"},{"name":"masks"},{"name":"mcf"},{"name":"mdns"},{"name":"me"},{"name":"memory"},{"name":"merakiAuth"},{"name":"merakiAuthUsers"},{"name":"meshStatuses"},{"name":"messages"},{"name":"metrics"},{"name":"migrations"},{"name":"mirror"},{"name":"mirrors"},{"name":"mode"},{"name":"models"},{"name":"monitor"},{"name":"monitoredMediaServers"},{"name":"mostImpactedClientNetworks"},{"name":"mostImpactedNetworks"},{"name":"mostImpactedXMs"},{"name":"moves"},{"name":"mqtt"},{"name":"mqttBrokers"},{"name":"mtu"},{"name":"multicast"},{"name":"multicastForwarding"},{"name":"multicastRouting"},{"name":"nac"},{"name":"nat"},{"name":"neighbors"},{"name":"netflow"},{"name":"networkAdapters"},{"name":"networkHealth"},{"name":"networkServices"},{"name":"new"},{"name":"nodes"},{"name":"objectDetectionModels"},{"name":"offboard"},{"name":"onboard"},{"name":"onboarding"},{"name":"onboardingHistory"},{"name":"oneToManyNatRules"},{"name":"oneToOneNatRules"},{"name":"openRoaming"},{"name":"openapiSpec"},{"name":"opportunistic"},{"name":"opportunisticPcap"},{"name":"optIns"},{"name":"optimization"},{"name":"order"},{"name":"orders"},{"name":"ospf"},{"name":"ospfNeighbors"},{"name":"override"},{"name":"overrides"},{"name":"overview"},{"name":"overviews"},{"name":"owe"},{"name":"package"},{"name":"packetCapture"},{"name":"packetCaptures"},{"name":"packetLoss"},{"name":"packets"},{"name":"payloadTemplates"},{"name":"peers"},{"name":"performance"},{"name":"performanceHistory"},{"name":"permissions"},{"name":"pii"},{"name":"piiKeys"},{"name":"ping"},{"name":"pingDevice"},{"name":"pipelines"},{"name":"placement"},{"name":"planning"},{"name":"poe"},{"name":"policies"},{"name":"policy"},{"name":"policyObjects"},{"name":"portForwardingRules"},{"name":"portSchedules"},{"name":"ports"},{"name":"position"},{"name":"positions"},{"name":"power"},{"name":"powerLimits"},{"name":"powerModules"},{"name":"prefixLists"},{"name":"prefixes"},{"name":"priorities"},{"name":"privateApplicationGroups"},{"name":"privateApplications"},{"name":"privateResourceGroups"},{"name":"privateResources"},{"name":"productAnnouncements"},{"name":"productIntegrations"},{"name":"profiles"},{"name":"provisioning"},{"name":"publicApplications"},{"name":"push"},{"name":"qosRules"},{"name":"qualityAndRetention"},{"name":"qualityRetentionProfiles"},{"name":"queues"},{"name":"raGuardPolicy"},{"name":"radio"},{"name":"radius"},{"name":"radsec"},{"name":"ratePlans"},{"name":"rca"},{"name":"readings"},{"name":"reboot"},{"name":"receivers"},{"name":"recent"},{"name":"recommendations"},{"name":"records"},{"name":"redundancy"},{"name":"regions"},{"name":"regulatoryDomain"},{"name":"relationships"},{"name":"remoteAccess"},{"name":"remoteAccessLog"},{"name":"remoteAccessLogsExports"},{"name":"removedResources"},{"name":"rendezvousPoints"},{"name":"requests"},{"name":"requirements"},{"name":"responseCodes"},{"name":"rest"},{"name":"restrictions"},{"name":"revocationLists"},{"name":"rfHealth"},{"name":"rfProfiles"},{"name":"roaming"},{"name":"roles"},{"name":"rollbacks"},{"name":"routeTableAssociations"},{"name":"routeTables"},{"name":"routers"},{"name":"routing"},{"name":"routingTable"},{"name":"rrm"},{"name":"rssi"},{"name":"ruleGroups"},{"name":"rules"},{"name":"rulesets"},{"name":"salesRepresentatives"},{"name":"saml"},{"name":"samlRoles"},{"name":"sase"},{"name":"scanning"},{"name":"schedules"},{"name":"scores"},{"name":"sdwan"},{"name":"sdwanmanager"},{"name":"search"},{"name":"secureClient"},{"name":"secureConnect"},{"name":"security"},{"name":"securityCenters"},{"name":"seen"},{"name":"sense"},{"name":"sentry"},{"name":"serverHealth"},{"name":"servers"},{"name":"serviceProviders"},{"name":"sessions"},{"name":"settings"},{"name":"signalQuality"},{"name":"signalQualityHistory"},{"name":"sims"},{"name":"singleLan"},{"name":"siteToSite"},{"name":"siteToSiteVpn"},{"name":"sites"},{"name":"slas"},{"name":"smDevicesForKey"},{"name":"smOwnersForKey"},{"name":"snmp"},{"name":"software"},{"name":"softwares"},{"name":"spanningTree"},{"name":"speedTest"},{"name":"speedTestResults"},{"name":"splash"},{"name":"splashAuthorizationStatus"},{"name":"splashLoginAttempts"},{"name":"split"},{"name":"ssids"},{"name":"stacks"},{"name":"staged"},{"name":"stages"},{"name":"states"},{"name":"static"},{"name":"staticRoutes"},{"name":"statics"},{"name":"stats"},{"name":"status"},{"name":"statuses"},{"name":"stickyEvents"},{"name":"stormControl"},{"name":"stp"},{"name":"subnetPool"},{"name":"subnets"},{"name":"subscription"},{"name":"subscriptions"},{"name":"successfulConnections"},{"name":"successfulConnects"},{"name":"summaries"},{"name":"summary"},{"name":"summaryPanel"},{"name":"supported"},{"name":"swap"},{"name":"swaps"},{"name":"switchPortStatus"},{"name":"switches"},{"name":"sync"},{"name":"syncJobs"},{"name":"syslog"},{"name":"syslogServers"},{"name":"system"},{"name":"tags"},{"name":"targetGroups"},{"name":"targets"},{"name":"tasks"},{"name":"taxonomy"},{"name":"telemetry"},{"name":"testConnectivity"},{"name":"tests"},{"name":"themes"},{"name":"thirdPartyVPNPeers"},{"name":"thousandEyes"},{"name":"threads"},{"name":"throughputTest"},{"name":"timeToConnect"},{"name":"token"},{"name":"tokens"},{"name":"top"},{"name":"topics"},{"name":"topology"},{"name":"towers"},{"name":"traceRoute"},{"name":"traffic"},{"name":"trafficAnalysis"},{"name":"trafficHistory"},{"name":"trafficShaping"},{"name":"transceivers"},{"name":"traps"},{"name":"trustedAccessConfigs"},{"name":"trustedServers"},{"name":"tunnelCreation"},{"name":"tunnelStatus"},{"name":"tunnelable"},{"name":"tunneling"},{"name":"types"},{"name":"umbrella"},{"name":"unassigned"},{"name":"update"},{"name":"updates"},{"name":"upgrades"},{"name":"uplink"},{"name":"uplinkBandwidth"},{"name":"uplinkSelection"},{"name":"uplinks"},{"name":"uplinksLossAndLatency"},{"name":"usage"},{"name":"usageHistories"},{"name":"usageHistory"},{"name":"userAccessDevices"},{"name":"utilization"},{"name":"v4"},{"name":"values"},{"name":"versions"},{"name":"video"},{"name":"videoLink"},{"name":"videoWalls"},{"name":"vlanAssignments"},{"name":"vlanProfiles"},{"name":"vlans"},{"name":"vmx"},{"name":"vpcOnboardingBatches"},{"name":"vpcs"},{"name":"vpn"},{"name":"vpnExclusions"},{"name":"vpnFirewallRules"},{"name":"vpnPeers"},{"name":"vppAccounts"},{"name":"vrfs"},{"name":"vrrp"},{"name":"vrrpTable"},{"name":"wakeOnLan"},{"name":"warmSpare"},{"name":"warnings"},{"name":"webApps"},{"name":"webhookTests"},{"name":"webhooks"},{"name":"wired"},{"name":"wirelessControllers"},{"name":"wirelessProfiles"},{"name":"wlanLists"},{"name":"workflows"},{"name":"xdr"},{"name":"zigbee"},{"name":"zones"},{"name":"ztrIntents"}],"x-parser-conf":{"overview":{"markdownPath":"docs/overview-early-access.md"},"theme":"meraki","serverConfig":true,"httpBearer":{"bearerToken":"75dd5334bef4d2bc96f26138c163c0a3fa0b5ca6"},"labelConfig":{"endpoint":{"field":"operationId","format":"startCase"}},"groupBy":{"$remoteModule":"config/group_platform.js"},"filterBy":{"$remoteModule":"config/filter_only_beta.js"},"sortBy":{"$remoteModule":"config/sort_by.js"},"exampleAsDefault":true,"expand":0,"variables":{"organizationId":"1215707","networkId":"N_784752235069315754","serial":"QBSB-VQ3J-XZ54"}},"openapi":"3.0.1","servers":[{"url":"https://api.meraki.com/{basePath}","variables":{"basePath":{"default":"api/v1"}}}],"securitySchemes":{"meraki_api_key":{"type":"apiKey","name":"X-Cisco-Meraki-API-Key","in":"header"},"bearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"API Key"},"oauth2":{"type":"oauth2","description":"This API uses OAuth 2 with the authorization code grant flow. [More info](https://developer.cisco.com/meraki/api-v1/authorization/)","flows":{"authorizationCode":{"authorizationUrl":"https://as.meraki.com/oauth/authorize","tokenUrl":"https://as.meraki.com/oauth/token","scopes":{"camera:config:read":"Cameras (MV)","camera:config:write":"Cameras (MV)","camera:telemetry:read":"Cameras (MV)","camera:telemetry:write":"Cameras (MV)","dashboard:general:config:read":"Entire dashboard, excluding identity and access management","dashboard:general:config:write":"Entire dashboard, excluding identity and access management","dashboard:general:telemetry:read":"Entire dashboard, excluding identity and access management","dashboard:general:telemetry:write":"Entire dashboard, excluding identity and access management","dashboard:iam:config:read":"Dashboard related to identity and access management, including early access features","dashboard:iam:config:write":"Dashboard related to identity and access management, including early access features","dashboard:iam:telemetry:read":"Dashboard related to identity and access management, including early access features","dashboard:iam:telemetry:write":"Dashboard related to identity and access management, including early access features","dashboard:licensing:config:read":"Licensing","dashboard:licensing:config:write":"Licensing","dashboard:licensing:telemetry:read":"Licensing","dashboard:licensing:telemetry:write":"Licensing","iot:gateway:general:config:read":"IoT Gateway Control using NIPC","iot:gateway:general:config:write":"IoT Gateway Control using NIPC","iot:gateway:general:telemetry:read":"IoT Gateway telemetry using NIPC","iot:gateway:general:telemetry:write":"IoT Gateway telemetry using NIPC","iot:gateway:onboarding:config:read":"IoT Gateway Onboarding using SCIM","iot:gateway:onboarding:config:write":"IoT Gateway Onboarding using SCIM","policy:config:read":"Provides granular authorization over all global policy resources including policy objects, adaptive policy, and Organization Group Policy","policy:config:write":"Provides granular authorization over all global policy resources including policy objects, adaptive policy, and Organization Group Policy","policy:telemetry:read":"Provides granular authorization over all global policy resources including policy objects, adaptive policy, and Organization Group Policy","policy:telemetry:write":"Provides granular authorization over all global policy resources including policy objects, adaptive policy, and Organization Group Policy","sdwan:config:read":"Secure SD-WAN (MX including MXIGZ)","sdwan:config:write":"Secure SD-WAN (MX including MXIGZ)","sdwan:telemetry:read":"Secure SD-WAN (MX including MXIGZ)","sdwan:telemetry:write":"Secure SD-WAN (MX including MXIGZ)","sensor:config:read":"Sensors (MT)","sensor:config:write":"Sensors (MT)","sensor:telemetry:read":"Sensors (MT)","sensor:telemetry:write":"Sensors (MT)","sm:config:read":"Endpoint Management (SM)","sm:config:write":"Endpoint Management (SM)","sm:telemetry:read":"Endpoint Management (SM)","sm:telemetry:write":"Endpoint Management (SM)","switch:config:read":"Switches (MS)","switch:config:write":"Switches (MS)","switch:telemetry:read":"Switches (MS)","switch:telemetry:write":"Switches (MS)","wireless:config:read":"Wireless (MR)","wireless:config:write":"Wireless (MR)","wireless:telemetry:read":"Wireless (MR)","wireless:telemetry:write":"Wireless (MR)"}}}}}},"spec":{"description":"Returns organization event logs ordered by event time and event ID,\nnewest first. Repeated values are ORed within one filter dimension and\ndifferent dimensions are combined with AND. The list applies no default\ntime window. Pagination defaults to 100 events and allows at most 500;\npass the opaque `nextCursor` unchanged as `startingAfter`.","operationId":"listEventLogs","parameters":[{"name":"organizationId","in":"path","description":"Organization ID","schema":{"type":"string"},"required":true},{"name":"since","in":"query","description":"Inclusive RFC 3339 lower bound on when events occurred. The list has no\ndefault when omitted. For histogram and facets, supplying only `until`\nsets `since` to 24 hours before `until`; omitting both uses the previous\n24 hours. Histogram and facets require the effective `since` to be\nearlier than `until`; the list applies supplied bounds independently.","schema":{"type":"string","format":"date-time"}},{"name":"until","in":"query","description":"Inclusive RFC 3339 upper bound on when events occurred. The list has no\ndefault when omitted. For histogram and facets, supplying only `since`\nsets `until` to the current time; omitting both uses the previous 24\nhours. Histogram and facets require the effective `until` to be later\nthan `since`; the list applies supplied bounds independently.","schema":{"type":"string","format":"date-time"}},{"name":"triggerType","in":"query","description":"Restricts results by initiation type. Repeat the parameter to OR values.\n\n- `user_action` — Initiated through a user or API action.\n- `system_action` — Initiated by background system processing.\n\nUnknown values return HTTP 400.","schema":{"type":"array","items":{"type":"string"}}},{"name":"outcome","in":"query","description":"Restricts results by event classification. Repeat the parameter to OR values.\n\n- `information` — Informational event.\n- `warning` — Event with a noteworthy condition.\n- `error` — Failed or error event.\n\nThese values classify the event, not an HTTP response. Unknown values\nreturn HTTP 400.","schema":{"type":"array","items":{"type":"string"}}},{"name":"entityType","in":"query","description":"Restricts results by primary event subject. Repeat the parameter to OR values.\n\n- `integration` — Cloud integration subject.\n- `account` — Discovered cloud-account subject.\n- `subnet` — Discovered subnet or VLAN subject.\n- `vpc` — Request alias for a public-cloud `network` subject.\n- `site` — Request alias for a Meraki `network` subject.\n- `network` — Deprecated legacy subject spanning VPCs and Sites.\n\nThe `vpc` and `site` aliases constrain provider family only when this\nfilter contains family aliases exclusively. Mixing either alias with\n`integration`, `account`, or `subnet` drops that constraint\nand can broaden matching `network` events. Unknown values return HTTP 400.","schema":{"type":"array","items":{"type":"string"}}},{"name":"entityId","in":"query","description":"Restricts results to exact primary-subject identifiers across all entity\ntypes. Repeat the parameter to OR identifiers.","schema":{"type":"array","items":{"type":"string"}}},{"name":"cloudProvider","in":"query","description":"Restricts results by provider attribution. Repeat the parameter to OR values.\n\n- `aws` — Amazon Web Services.\n- `azure` — Microsoft Azure.\n- `gcp` — Google Cloud.\n- `meraki` — Meraki Site resources or Meraki-attributed events.\n\nUnknown values return HTTP 400.","schema":{"type":"array","items":{"type":"string"}}},{"name":"event","in":"query","description":"Restricts results to exact, case-sensitive event-source-supplied\nheadlines. Repeat the parameter to OR headlines. The headline is not a\nclosed vocabulary, and an empty value matches no rows exposed through\nevent facets.","schema":{"type":"array","items":{"type":"string"}}},{"name":"integrationId","in":"query","description":"Restricts results to exact MCN cloud-integration UUIDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"accountId","in":"query","description":"Restricts results to exact MCN cloud-account UUIDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"vpcId","in":"query","description":"Restricts results to exact MCN VPC UUIDs; repeat to OR values. When VPC\nIDs are supplied without Site or deprecated Network IDs, only AWS,\nAzure, and GCP network events match.","schema":{"type":"array","items":{"type":"string"}}},{"name":"siteId","in":"query","description":"Restricts results to exact MCN Site UUIDs; repeat to OR values. When Site\nIDs are supplied without VPC or deprecated Network IDs, only Meraki\nnetwork events match.","schema":{"type":"array","items":{"type":"string"}}},{"name":"subnetId","in":"query","description":"Restricts results to exact MCN subnet UUIDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"regionId","in":"query","description":"Restricts results to exact MCN region UUIDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"regionName","in":"query","description":"Restricts results to exact, case-sensitive provider region names; repeat\nto OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"userId","in":"query","description":"Restricts results to exact opaque identity-provider subject IDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"userEmail","in":"query","description":"Restricts results to exact, case-sensitive actor email snapshots; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"groupId","in":"query","description":"Restricts results to exact event-source-supplied logical-action correlation\nIDs; repeat to OR values.","schema":{"type":"array","items":{"type":"string"}}},{"name":"search","in":"query","description":"Case-insensitive free-text search across event details. The input is\nsplit on characters other than ASCII letters, digits, or underscores,\nand every resulting token must match. Empty or separator-only input\napplies no search constraint.","schema":{"type":"string"}},{"name":"perPage","in":"query","description":"Requested maximum number of matching resources to return. The default and maximum, and whether this parameter is applied, are defined by the operation. A response can contain fewer resources than requested.","schema":{"type":"integer"}},{"name":"startingAfter","in":"query","description":"Forward page boundary accepted by an operation. Its source, format, and interpretation are defined by that operation; do not reuse it across operations unless their documentation permits it. Cursor validation and interaction with other pagination parameters are operation-specific.","schema":{"type":"string"}}],"responses":{"200":{"description":"Successful operation","content":{"application/json":{"schema":{"type":"object","properties":{"items":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","description":"UUID that uniquely identifies this event-log entry."},"eventTime":{"type":"string","format":"date-time","description":"RFC 3339 timestamp reported by the event source for when the event occurred."},"receivedAt":{"type":"string","format":"date-time","description":"RFC 3339 timestamp when MCN recorded the event."},"traceId":{"type":"string","description":"Optional W3C Trace Context trace identifier supplied by the event source.\nOmitted when no trace correlation is available."},"triggerType":{"type":"string","description":"Identifies what initiated the event.\n\n- `user_action` — Initiated through a user or API action.\n- `system_action` — Initiated by background system processing.\n\nResponses contain only these values; the schema remains an\nunconstrained string for compatibility."},"outcome":{"type":"string","description":"Classifies the event result, independently of any HTTP response.\n\n- `information` — Informational event.\n- `warning` — Event with a noteworthy condition.\n- `error` — Failed or error event.\n\nResponses contain only these values; the schema remains an\nunconstrained string for compatibility."},"entityType":{"type":"string","description":"Identifies the primary subject represented by `entityId`.\n\n- `integration` — Cloud integration subject.\n- `account` — Discovered cloud-account subject.\n- `network` — Legacy response subject representing either a VPC or Site.\n- `subnet` — Discovered subnet or VLAN subject.\n\nResponses retain `network`; use `resourceType` to distinguish VPCs\nfrom Sites. Responses contain only these values; the schema remains an\nunconstrained string for compatibility."},"resourceType":{"type":"string","description":"Preferred resource family for `entityType=network`.\n\n- `vpc` — Public-cloud network backed by AWS, Azure, or GCP.\n- `site` — Meraki-backed network.\n\nOmitted for other entity types or when provider family cannot be\nresolved; `entityType` remains `network` for compatibility."},"entityId":{"type":"string","description":"Identifier of the event's primary subject, represented as a string across entity types."},"entityName":{"type":"string","description":"Display name of the primary subject captured when the event was recorded."},"cloudProvider":{"type":"string","description":"Provider attributed to the event.\n\n- `aws` — Amazon Web Services.\n- `azure` — Microsoft Azure.\n- `gcp` — Google Cloud.\n- `meraki` — Meraki Site resource or Meraki-attributed event.\n\nOmitted for provider-independent events. Responses contain only these\nvalues; the schema remains an unconstrained string for compatibility."},"integrationId":{"type":"string","description":"MCN-assigned cloud-integration UUID; omitted when the event has no integration scope."},"integrationName":{"type":"string","description":"Cloud-integration display name captured when the event was recorded."},"accountId":{"type":"string","description":"MCN-assigned cloud-account UUID; omitted when the event has no account scope."},"accountName":{"type":"string","description":"Cloud-account display name captured when the event was recorded."},"networkName":{"type":"string","description":"Deprecated: Network display-name snapshot. Use `resourceType` with\n`vpcName` or `siteName`."},"vpcId":{"type":"string","description":"MCN-assigned VPC UUID; omitted for Site and non-network events."},"vpcName":{"type":"string","description":"VPC display-name snapshot; omitted for Site and non-network events."},"siteId":{"type":"string","description":"MCN-assigned Site UUID; omitted for VPC and non-network events."},"siteName":{"type":"string","description":"Site display-name snapshot; omitted for VPC and non-network events."},"subnetId":{"type":"string","description":"MCN-assigned subnet UUID; omitted when the event has no subnet scope."},"subnetName":{"type":"string","description":"Subnet display name captured when the event was recorded."},"regionId":{"type":"string","description":"MCN-assigned region UUID; omitted when the event has no cataloged region scope."},"regionName":{"type":"string","description":"Provider-region display name captured when the event was recorded."},"userId":{"type":"string","description":"Opaque identity-provider subject for the actor; omitted for system actions or unavailable identity."},"userName":{"type":"string","description":"Actor display name captured with the event; omitted when unavailable."},"userEmail":{"type":"string","description":"Actor email captured with the event; omitted when unavailable."},"groupId":{"type":"string","description":"Event-source-supplied identifier that correlates events from one logical action; omitted when unavailable."},"event":{"type":"string","description":"Event-source-supplied short event headline. This is not a closed\nvocabulary; an empty string means no headline was supplied."},"details":{"type":"string","description":"Event-source-supplied human-readable explanation of what occurred."},"payload":{"type":"string","description":"Optional event-source payload returned as an opaque string, commonly\ncontaining JSON. Its structure is source-specific and is not a\nstable API contract."}}},"description":"Event-log entries in descending `eventTime`, then descending event ID\norder. Empty when no events match or the pagination boundary is reached."},"nextCursor":{"type":"string","description":"Opaque time-and-event boundary for the next page. Pass it unchanged as\n`startingAfter`; omitted or empty when no additional events remain."}}},"example":{"items":[{"id":"8f1d3aab-91a7-4cf6-b2c1-2d3e4f5a6b7c","eventTime":"2026-05-04T18:32:11.123Z","receivedAt":"2026-05-04T18:32:12.001Z","traceId":"0123456789abcdef0123456789abcdef","triggerType":"system_action","outcome":"information","entityType":"network","resourceType":"vpc","entityId":"11111111-1111-1111-1111-111111111111","entityName":"prod-app-private-us-east-1a","cloudProvider":"aws","integrationId":"123e4567-e89b-12d3-a456-426614174000","integrationName":"AWS prod integration","accountId":"9c3c5b65-72f0-4d1e-a16e-756d4fb61a4e","accountName":"prod-account","networkName":"prod-vpc-east","vpcId":"dabbca4c-fd8b-46f5-8a09-d95a67632fce","vpcName":"prod-vpc-east","siteId":"e27eaf1a-a81e-4912-b912-c73fa315ef11","siteName":"branch-17","subnetId":"a9d9a58e-4cde-4e20-aad2-62e0f2d7f6c3","subnetName":"prod-private-a","regionId":"7e9d0d3d-6d6a-4f95-8ef3-dfbf9f2f8a3a","regionName":"us-east-1","userId":"auth0|6411d34c8f5b8d000071a2c1","userName":"Alex Operator","userEmail":"operator@example.test","groupId":"c1d86e0f-6e8a-4b2c-91a1-9f9a0c2b3d4e","event":"Connection created","details":"VPC vpc-12345 onboarded successfully.","payload":"{\"vpcId\":\"vpc-12345\",\"region\":\"us-east-1\"}"}],"nextCursor":"eyJvZmZzZXQiOjEwMH0="}}}}},"summary":"Returns organization event logs ordered by event time and event ID,\nnewest first","tags":["organizations","configure","mcf","eventLogs"],"x-release-stage":"beta","__originalOperationId":"listEventLogs","security":[{"meraki_api_key":[]},{"bearerAuth":[]},{"oauth2":[]}],"method":"get","path":"/organizations/{organizationId}/mcf/eventLogs"}}