What is an API event in a cloud log?¶
An API event records software making a structured request to a cloud service - for example to read, create, update, delete or administer a resource. It identifies software interaction, not necessarily a person acting at that moment.
Read request and result¶
Useful fields include technical identity, application/client ID, operation or method, target resource, time, source address, outcome/response code and request or correlation ID. One event may record the request while another records the resulting object change.
Mobile apps, sync clients, scripts, service accounts and workflows all use APIs. The request may be interactive, scheduled or triggered by another event.
Follow the authority and trigger¶
Token, application-consent and service-account records show what permission was used. Application or device logs may explain the initiating process. A named user may be the person who granted delegated authority earlier rather than the person who issued this request.
Service-account events provide the next layer where the API actor is a technical identity.
The point to remember
An API event records a defined software request and outcome. Identify the client, permission and trigger before attributing it to a person.