Command map

show audit

Show who did what and when on this box.

Ze command

Registry path
show audit
Usage
show audit [action <action>] [actor <actor>] [surface <surface>] [since <since>] [until <until>] [count <count>]
Mode
Read-only
Wire method
ze-show:audit
Backends
any backend
Task support
optional: the MCP call is synchronous, which is the default
Subcommands
none: this command takes no subcommand
Pipes, always
json, ndjson, table, text, yaml, raw, no-more, save
Pipes, when the answer has rows
match, count, first, last, display, fill
Pipes, while streaming
log
Pipes, local process only
save

Description

Returns audit log entries with timestamps, actors, and actions.
Filters (all optional, combinable): action <type>, actor <name>,
surface <name> (cli, web, api), since/until <RFC3339>, count <N>.
Actions include config-commit, login, peer-teardown, and more.

Arguments

NameTypeRequiredValuesSummaryDescription
actionstringnoany value of this typeFilter by action typeThe value is an action name as the action column reports it, such as config-commit or login, compared as text. Absent, entries of every action are shown.
actorstringnoany value of this typeFilter by actor nameThe value is the name of the user or process that acted, compared as text with the actor column. Absent, entries of every actor are shown.
surfacestringnoany value of this typeFilter by surface nameThe value is the surface the action came through: cli, web or api, compared as text. Absent, entries of every surface are shown.
sincestringnoany value of this typeStart time (RFC3339)The value is an RFC 3339 timestamp such as 2026-09-15T08:00:00Z, and any other form is refused. Entries recorded before it are left out.
untilstringnoany value of this typeEnd time (RFC3339)The value is an RFC 3339 timestamp such as 2026-09-15T18:00:00Z, and any other form is refused. Entries recorded after it are left out.
countuintnoany value of this typeMaximum number of entriesThe value is a whole number of 1 or more. The query stops after that many matching entries, oldest first. Absent, every matching entry is shown.

Mapping status

No vendor equivalent has been curated yet for this Ze command.

Juniper Junos MX

No equivalent is listed for this vendor yet.

Cisco IOS XR

No equivalent is listed for this vendor yet.

Nokia SR OS

No equivalent is listed for this vendor yet.

VyOS

No equivalent is listed for this vendor yet.