openapi: 3.2.0 info: title: Fenergo Nebula Audit Query Sensitive Data Access Log API description: The Audit Query API enables the retrieval of audit event data related to various activities within the system. version: '3.0' servers: - url: /auditquery security: - Bearer: [] tags: - name: SensitiveDataAccessLog paths: /api/v3/sensitive-data-access-log/{entityId}/users: post: tags: - SensitiveDataAccessLog summary: Retrieve sensitive data access log events for given Entity description: 'This method requires EntityId and it returns a list of sensitive data access log events for the specified Entity. This method also accepts an optional ''searchTerm'' parameter, which can be used to further filter entries based on either a field name or a username. Required permissions: Following permissions are required: AuditAccessAndSearch' operationId: GetPiiAccessLogBySearchTerm parameters: - name: entityId in: path description: The Unique ID of the Entity. required: true schema: type: string format: uuid - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Sensitive Data access log request content: application/json: schema: allOf: - $ref: '#/components/schemas/GetPiiAccessLogBySearchTermRequestDtoServiceRequest' responses: '200': description: Success. The list of sensitive data access log events for the given entity is returned content: application/json: schema: $ref: '#/components/schemas/GetPiiAccessLogResultDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '403': description: Forbidden. User has no access to retrieve access log data '500': description: Internal server error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT /api/v3/sensitive-data-access-log/{userId}/entities: post: tags: - SensitiveDataAccessLog summary: Retrieve sensitive data access log events for given user id description: 'This method requires UserId and it returns a list of sensitive data access log events for the specified user id. Required permissions: Following permissions are required: AuditAccessAndSearch' operationId: GetPiiAccessLogByUserId parameters: - name: userId in: path description: The Unique ID of the Entity. required: true schema: type: string - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Sensitive Data access log request content: application/json: schema: allOf: - $ref: '#/components/schemas/GetPiiAccessLogByUserIdRequestDtoServiceRequest' responses: '200': description: Success. The list of sensitive data access log events for the given user id is returned content: application/json: schema: $ref: '#/components/schemas/GetPiiAccessLogResultDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '403': description: Forbidden. User has no access to retrieve access log data '500': description: Internal server error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT /api/v3/sensitive-data-access-log/entities: post: tags: - SensitiveDataAccessLog summary: Retrieve sensitive data access log events for list of entities description: 'This method requires list of EntityIds and it returns a list of sensitive data access log events for the specified entities. Required permissions: Following permissions are required: AuditAccessAndSearch' operationId: GetPiiAccessLogByresourceIds parameters: - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Sensitive Data access log request content: application/json: schema: allOf: - $ref: '#/components/schemas/GetPiiAccessLogByResourceIdsRequestDtoServiceRequest' responses: '200': description: Success. The list of sensitive data access log events for the entities and optionally fields is returned content: application/json: schema: $ref: '#/components/schemas/GetPiiAccessLogResultDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '403': description: Forbidden. User has no access to retrieve access log data '500': description: Internal server error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT components: schemas: PagerDto: type: object properties: size: type: integer format: int32 exclusiveMinimum: 0 from: minimum: 0 type: integer format: int32 sortBy: type: - string - 'null' sortOrder: allOf: - $ref: '#/components/schemas/SortOrder' additionalProperties: false GetPiiAccessLogByResourceIdsRequestDtoServiceRequest: required: - data type: object properties: data: allOf: - $ref: '#/components/schemas/GetPiiAccessLogByResourceIdsRequestDto' additionalProperties: false SortOrder: enum: - Ascending - Descending type: string GetPiiAccessLogByResourceIdsRequestDto: allOf: - $ref: '#/components/schemas/GetPiiAccessLogBaseRequestDto' - type: object properties: entityIds: type: - array - 'null' items: type: string description: The list of resource IDs for which to fetch Audit Events. example: - 7304b842-769f-4c22-9499-7c5d069ffb8f - ad6cf1b0-0925-4d65-98e7-a4e7901cce46 - abb80516-3914-4366-a061-2f10e018fdeb fieldNames: type: - array - 'null' items: type: string description: Optional list of field names for which to fetch Audit Events. example: - passport - dateOfBirth additionalProperties: false GetPiiAccessLogBySearchTermRequestDto: allOf: - $ref: '#/components/schemas/GetPiiAccessLogBaseRequestDto' - type: object properties: searchTerm: type: - string - 'null' description: A search term that can be used to further filter your results. Can be any data found in your Pii Audit Events, e.g. 'Username','Fieldname' etc. example: passport additionalProperties: false GetPiiAccessLogByUserIdRequestDtoServiceRequest: type: object properties: data: allOf: - $ref: '#/components/schemas/GetPiiAccessLogByUserIdRequestDto' additionalProperties: false GetPiiAccessLogResultDtoServiceResponse: type: object properties: data: allOf: - $ref: '#/components/schemas/GetPiiAccessLogResultDto' description: Response DTO representing get by resource ids results messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false ValidationErrorModel: type: object properties: propertyName: type: - string - 'null' errorMessage: type: - string - 'null' attemptedValue: {} errorCode: type: - string - 'null' additionalProperties: false GetPiiAccessLogBaseRequestDto: type: object properties: pager: allOf: - $ref: '#/components/schemas/PagerDto' description: A pager object to specify pagination parameters example: size: 10 from: 0 sortBy: date sortOrder: Descending additionalProperties: false QuerySideAuditEventDto: type: object properties: eventId: type: - string - 'null' description: Unique identifier for this event resourceId: type: - string - 'null' description: Id used if this audit event is related to one specific resource resourceType: type: - string - 'null' description: Resource type if this audit event is related to one specific resource entityReferenceId: type: - string - 'null' description: Entity Id if this audit event is related to one Entity propertyName: type: - string - 'null' description: Pii Property Name that has been revealed journeyReferenceId: type: - string - 'null' description: Journey Id if this audit event is related to one Journey eventType: type: - string - 'null' description: Event Type version: type: integer description: Version of resource if versioning is being used format: int64 date: type: string description: Date when this event happened format: date-time userId: type: - string - 'null' description: User id who performed this event userName: type: - string - 'null' description: User id who performed this event clientId: type: - string - 'null' description: Client id which identifies the source of this event service: type: - string - 'null' description: Service where this event was created correlationId: type: - string - 'null' description: Correlation Id additionalProperties: false ServiceResponseMessage: type: object properties: message: type: - string - 'null' type: type: - string - 'null' errorCode: type: - string - 'null' additionalProperties: false GetPiiAccessLogResultDto: type: object properties: items: type: - array - 'null' items: $ref: '#/components/schemas/QuerySideAuditEventDto' description: Items for the current page. totalItems: type: integer description: Total count of items. format: int64 example: 1 additionalProperties: false description: Response DTO representing get by resource ids results GetPiiAccessLogBySearchTermRequestDtoServiceRequest: type: object properties: data: allOf: - $ref: '#/components/schemas/GetPiiAccessLogBySearchTermRequestDto' additionalProperties: false GetPiiAccessLogByUserIdRequestDto: allOf: - $ref: '#/components/schemas/GetPiiAccessLogBaseRequestDto' - type: object additionalProperties: false ValidationErrorModelListServiceResponse: type: object properties: data: type: - array - 'null' items: $ref: '#/components/schemas/ValidationErrorModel' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false example: data: - propertyName: data errorMessage: Data is required attemptedValue: '' errorCode: NotNullValidator messages: - message: Data is required type: Error errorCode: Error Code StringServiceResponse: type: object properties: data: type: - string - 'null' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false securitySchemes: Bearer: type: apiKey description: Please insert JWT with Bearer into field name: Authorization in: header