chainsaw audit

Audit event commands

Audit event commands

SubcommandWhat it does
chainsaw audit exportExport audit events to a file (CSV/JSON/NDJSON)
chainsaw audit viewView audit events for the current org
chainsaw audit [command]

chainsaw audit export

Export audit events to a file (CSV/JSON/NDJSON)

chainsaw audit export [flags]

Export audit events for the current org to a machine-readable file (or stdout). Mirrors the filter flags supported by ‘audit view’ so an export is “view + machine-readable output”. Useful for compliance handoffs and offline analysis.

Examples: chainsaw audit export –format csv –since 24h –out audit.csv chainsaw audit export –format json –start 2026-04-01 –end 2026-04-30 –out april.json chainsaw audit export –format ndjson –actor alice@example.com

Flags

FlagTypeDefaultDescription
--actionstring—Filter by action (substring match)
--actorstring—Filter by actor (substring match)
--allow-truncatedbool—Write the export even when the server reports it is incomplete (default: refuse)
--endstring—Filter events on or before this date (RFC3339 or YYYY-MM-DD)
--formatstringcsvOutput format: csv|json|ndjson
--limitint0Maximum number of events to export (default 0 = all, unlike ‘audit view’ which defaults to 50)
--outstring—Write to file instead of stdout (use - for stdout); the global –output/-o is an alias
--sincestring—Relative time window (e.g. 24h, 7d, 30m); overrides –start if set
--startstring—Filter events on or after this date (RFC3339 or YYYY-MM-DD)

The global flags apply here too.

chainsaw audit view

View audit events for the current org

chainsaw audit view [flags]

Flags

FlagTypeDefaultDescription
--actionstring—Filter by action (substring match)
--actorstring—Filter by actor (substring match)
--endstring—Filter events on or before this date (RFC3339 or YYYY-MM-DD)
--jsonbool—Output as JSON
--limitint50Maximum number of events to display (default 50; 0 = all). Note: ‘audit export’ defaults to 0/all.
--sincestring—Relative time window (e.g. 24h, 7d, 30m); mutually exclusive with –start
--startstring—Filter events on or after this date (RFC3339 or YYYY-MM-DD)

The global flags apply here too.