The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Activity logs search request

Prev Next

Searches the user activity for the Admin Users of the client.

POST https://<etp_instance_addr>/api/v1/users/activitylogs/search

Required headers:

x-fireeye-api-key: <key>—Specifies your personal API key.

Content-Type: “application/json”—Content-type of the request body.

Request body:

curl -X POST \
  https://<API_HOST>/api/v1/users/activitylogs/search \
  -H 'Content-Type: application/json' \
  -H 'x-fireeye-api-key: <API_KEY>' \
  -d '{
    "attributes": {
        "user_email_id": ["etp_system@fireeye.com"]
    },
    "size": 5
}'

The query parameters should be nested inside the "attributes" as shown. To get only a specified number of results, use the optional "size" parameter.

All parameters are optional. Any number of these fields can be used in any combination. At minimum, a blank JSON document, {}, should be passed for unfiltered results (within the domain of the API Key used).

Parameters:

Parameter

Value

Description

user_action

string

User action type.

Example: VIEWED_QUARANTINE_MESSAGE

user_action_text

string

Partial text from the display message of the user action type.

Example: Quarantine Message Viewed

user_email_id

Array of string

Email IDs of the user whose activity logs are being fetched.

user_ip

string

IP Address of the user.

Example: xx.xxx.xxx.xxx

details

string

Partial text from the detailed description of the user action.

Example: Viewed Quarantine Message 959E02706CF4D4AF55d49e4a8

time^

object

Time range within which the user activity was logged.

Format: ISO Z

Example: "time": { "from": "2019-07-18T16:30:04+0000Z", "to": "2019-07-18T16:50:04+0000Z" }

size

integer

Number of records returned. Size can be in the range 1-500 (default is 20).

'time' object schema:

Parameter

Type

Value

Description

from

string

"2020-10-10T12:30:22+0000Z"

Starting value of the timestamp in the result set

to

string

"2020-11-11T19:20:32+0000Z"

Ending value of the timestamp in the result set

User logs search response

Values for ID and other fields are for illustration only.

{
  "data": [
    {
      "attributes": {
        "user_email_id": "etp_system@fireeye.com",
        "time": "2020-11-06T04:59:13+0000Z",
        "user_ip": "10.219.120.207",
        "details_values": [
          "Verify_Envelope_From_Equal"
        ],
        "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:82.0) Gecko/20100101 Firefox/82.0",
        "user_action": "CUSTOM_RULE_CREATED",
        "user_action_text": "Custom Rule Creation",
        "details": "Custom Rule \"Verify_Envelope_From_Equal\" created"
      }
    },
    {
      "attributes": {
        "user_email_id": "etp_system@fireeye.com",
        "time": "2020-11-06T04:59:13+0000Z",
        "user_ip": "10.219.120.207",
        "details_values": [
          "111_swayam"
        ],
        "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:82.0) Gecko/20100101 Firefox/82.0",
        "user_action": "POLICY_MODIFY_SUCCESS",
        "user_action_text": "Policy Modification",
        "details": "Policy \"111_swayam\" modified successfully"
      }
    },
    {
      "attributes": {
        "user_email_id": "etp_system@fireeye.com",
        "time": "2020-11-06T04:48:30+0000Z",
        "user_ip": "10.219.121.86",
        "details_values": [
          "959E02706CF4D4AF55d49e4a8"
        ],
        "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/83.0.4103.116 Safari/537.36",
        "user_action": "VIEWED_QUARANTINE_MESSAGE",
        "user_action_text": "Quarantine Message Viewed",
        "details": "Viewed Quarantine Message 959E02706CF4D4AF55d49e4a8"
      }
    },
    {
      "attributes": {
        "user_email_id": "etp_system@fireeye.com",
        "time": "2020-11-06T04:46:00+0000Z",
        "user_ip": "10.219.121.86",
        "details_values": [
          "AcceptRuleAssociateTestForCYRENephfnkzw"
        ],
        "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/83.0.4103.116 Safari/537.36",
        "user_action": "POLICY_DELETE_SUCCESS",
        "user_action_text": "Policy Deletion",
        "details": "Policy \"AcceptRuleAssociateTestForCYRENephfnkzw\" deleted successfully"
      }
    },
    {
      "attributes": {
        "user_email_id": "etp_system@fireeye.com",
        "time": "2020-11-06T04:45:43+0000Z",
        "user_ip": "10.219.121.86",
        "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/83.0.4103.116 Safari/537.36",
        "user_action": "LOGIN_SUCCESS",
        "user_action_text": "Successful Login",
        "details": "Login Successful"
      }
    }
  ],
  "meta": {
    "timestamp_userlog": "2020-11-06T04:45:43+0000Z",
    "type": "User Activity Logs",
    "copyright": "Copyright 2020 FireEye Inc"
  }
}