Hosmel Quintana
Laravel Audit Logs
Introduction
Installation
Configuration
Basic usage
Recording Audit Logs
Actors and Targets
Recording Attribute Changes
Querying Audit Logs
Testing Audit Logs
Advanced usage
Configuring Audit Context
Redacting Sensitive Data
Batching and Correlating Logs
Customizing the Audit Log Model
View on GitHub

Querying Audit Logs

Query stored logs with Eloquent and work with their columns.

Query with Eloquent

Query stored logs with the HosmelQ\AuditLog\Models\AuditLog model:

php
use HosmelQ\AuditLog\Models\AuditLog;

$logs = AuditLog::query()
    ->where('tenant_id', 'org_123')
    ->where('bucket', 'application')
    ->latest('occurred_at')
    ->get();

The model uses the connection and table from the audit-log.storage options. To add scopes or relationships, extend the model.

Columns

ColumnTypeDescription
idstringLog ID.
eventstringEvent name.
tenant_idstringTenant ID, or an empty string.
actor_idstringActor ID.
actor_typestringActor type.
actor_namestring or nullActor display name.
actor_metadataarrayActor metadata.
targetsarrayList of targets. Each target has id, type, name, and metadata keys.
metadataarrayEvent metadata.
attribute_changesarray or nullChanged attributes under before and after keys. See attribute changes.
descriptionstringDescription, or an empty string.
bucketstringBucket.
sourcestringSource.
correlation_idstring or nullCorrelation ID shared by related logs.
remote_ipstring or nullRemote IP of the request.
user_agentstring or nullUser agent of the request.
occurred_atCarbonImmutableWhen the event happened.
inserted_atCarbonImmutableWhen the log was written.
expires_atCarbonImmutable or nullWhen the log becomes eligible for pruning.

Array columns are stored as JSON and cast to PHP arrays. Date columns are stored with millisecond precision.

Indexes

The table has single-column indexes on event, actor_id, actor_type, correlation_id, occurred_at, inserted_at, and expires_at. A composite index on tenant_id, bucket, occurred_at, and id supports listing a tenant's logs in chronological order. Filter by tenant_id first to use it.

Query JSON columns

Use Laravel's JSON query methods to filter by metadata or targets:

php
use HosmelQ\AuditLog\Models\AuditLog;

$logs = AuditLog::query()
    ->where('tenant_id', 'org_123')
    ->where('metadata->visibility', 'public')
    ->whereJsonContains('targets', [['type' => 'document', 'id' => 'doc_123']])
    ->get();

whereJsonContains() requires a database that supports JSON containment, such as MySQL or PostgreSQL. JSON columns are not indexed, so combine these filters with an indexed column.

Recording Attribute ChangesTesting Audit Logs