chainsaw audit
Audit event commands
Audit event commands
| Subcommand | What it does |
|---|---|
chainsaw audit export | Export audit events to a file (CSV/JSON/NDJSON) |
chainsaw audit view | View audit events for the current org |
chainsaw audit [command]
chainsaw audit export
Export audit events to a file (CSV/JSON/NDJSON)
chainsaw audit export [flags]
Export audit events for the current org to a machine-readable file (or stdout). Mirrors the filter flags supported by ‘audit view’ so an export is “view + machine-readable output”. Useful for compliance handoffs and offline analysis.
Examples: chainsaw audit export –format csv –since 24h –out audit.csv chainsaw audit export –format json –start 2026-04-01 –end 2026-04-30 –out april.json chainsaw audit export –format ndjson –actor alice@example.com
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--action | string | — | Filter by action (substring match) |
--actor | string | — | Filter by actor (substring match) |
--allow-truncated | bool | — | Write the export even when the server reports it is incomplete (default: refuse) |
--end | string | — | Filter events on or before this date (RFC3339 or YYYY-MM-DD) |
--format | string | csv | Output format: csv|json|ndjson |
--limit | int | 0 | Maximum number of events to export (default 0 = all, unlike ‘audit view’ which defaults to 50) |
--out | string | — | Write to file instead of stdout (use - for stdout); the global –output/-o is an alias |
--since | string | — | Relative time window (e.g. 24h, 7d, 30m); overrides –start if set |
--start | string | — | Filter events on or after this date (RFC3339 or YYYY-MM-DD) |
The global flags apply here too.
chainsaw audit view
View audit events for the current org
chainsaw audit view [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--action | string | — | Filter by action (substring match) |
--actor | string | — | Filter by actor (substring match) |
--end | string | — | Filter events on or before this date (RFC3339 or YYYY-MM-DD) |
--json | bool | — | Output as JSON |
--limit | int | 50 | Maximum number of events to display (default 50; 0 = all). Note: ‘audit export’ defaults to 0/all. |
--since | string | — | Relative time window (e.g. 24h, 7d, 30m); mutually exclusive with –start |
--start | string | — | Filter events on or after this date (RFC3339 or YYYY-MM-DD) |
The global flags apply here too.