​
Select Service
Audit Log Reference
Published July 28, 2026 | Last modified July 30, 2026
Overview
Use this reference to look up the fields F5 Distributed Cloud Services writes to audit logs. Audit logs record actions performed on objects. F5 stores them on the Global Controller with longer retention than application logs.
Types of audit logs
Distributed Cloud Services generates two types of audit logs: success and failure. The log information is stored in JSON format. Some information is unique to each type of log, and other information is present in both.
Important: Don't edit or take action on keys marked For use by F5 only in the Description column. F5 will remove these keys in a future release.
| Key | Success | Failure | Description |
|---|---|---|---|
kubernetes | ✅ | ✅ | For use by F5 only. |
dst | ✅ | ✅ | Destination service, origin server, or endpoint receiving the request. |
dst_site | ✅ | ✅ | Routes traffic to the destination endpoint or origin. |
time_start | ✅ | ✅ | Timestamp when request processing started. |
messageid | ✅ | ✅ | Unique identifier for the audit event. |
trace_info | ✅ | ✅ | Distributed tracing identifier used for request correlation across services. |
rsp_seconds | ✅ | ✅ | Seconds spent processing the request and generating a response. |
src_site | ✅ | ✅ | Site that originally received the request. |
hostname | ✅ | ✅ | For use by F5 only. |
original_tenant | ✅ | ✅ | Original tenant associated with the request. |
<uuid>.user_message | ✅ | ✅ | Human-readable description of the audit outcome. |
stream | ✅ | ✅ | For use by F5 only. |
host | ✅ | Host IP address associated with the log record. | |
req_headers | ✅ | Request headers captured for the request. | |
message_key | ✅ | ✅ | Internal unique key used for log indexing and correlation. |
tenant | ✅ | ✅ | Tenant owning the resource or request. |
user_agent | ✅ | ✅ | HTTP User-Agent header value. |
app | ✅ | ✅ | For use by F5 only. |
severity | ✅ | ✅ | Severity level of the audit event. |
cluster_name | ✅ | ✅ | For use by F5 only. |
ctx_creatorid | ✅ | ✅ | Identity of the user who started the operation. |
method | ✅ | ✅ | HTTP method used by the request. |
rpc | ✅ | ✅ | Internal API/RPC method called. |
src | ✅ | ✅ | Source service or origin of the request. |
rsp_code | ✅ | ✅ | HTTP response status code returned by the operation. |
ctx_creatorcls | ✅ | ✅ | Client class that sent the request (for example, Prism). |
transport | ✅ | ✅ | Transport protocol used by the API (for example, REST, gRPC, and others). |
message | ✅ | ✅ | Summary or type of audit event. |
server_id | ✅ | ✅ | Identifier of the service instance generating the record. |
site | ✅ | ✅ | For use by F5 only. |
@timestamp | ✅ | ✅ | For use by F5 only. |
namespace | ✅ | ✅ | Namespace/workspace containing the managed resource. |
req_path | ✅ | ✅ | HTTP request path. |
time | ✅ | ✅ | Event timestamp. |
user | ✅ | ✅ | Signed-in user for the request. |
original_topic_name | ✅ | ✅ | Original message topic from which the audit event was published. |
peer_CN | ✅ | ✅ | Common Name (CN) from the peer certificate identity. |
req_body | ✅ | ✅ | Request payload submitted to the API. |
req_error | ✅ | Error details returned when request validation or processing failed. | |
<uuid>.rsp_body | ✅ | Response payload for the audited object operation. | |
<uuid>.req_body | ✅ | Request payload associated with the audited object operation. | |
<uuid>.oper_name | ✅ | Object lifecycle operation performed (for example, Create, Update, Delete, and more). | |
<uuid>.object_json | ✅ | Complete serialized representation of the affected resource. | |
req_size | ✅ | Size of the request payload in bytes. | |
<uuid>.object_type | ✅ | Schema type of the affected object. | |
rsp_body | ✅ | API response payload; may contain DEPRECATED placeholder values. | |
rsp_size | ✅ | Size of the response payload in bytes. | |
<uuid>.object_name | ✅ | Name of the affected resource. | |
<uuid>.object_uid | ✅ | Unique identifier (UID) of the affected resource. | |
<uuid>.object_namespace | ✅ | Namespace containing the affected resource. |
Example of failure audit log
{ "kubernetes": {}, "dst": "<DST>", "dst_site": "UNKNOWN", "time_start": "2026-06-11 23:13:46.800759613 +0000 UTC m=+146444.274632121", "messageid": "942ceca3-5e0a-492d-baea-64a2a71657f2", "trace_info": "21de9d1397943cd2:21de9d1397943cd2:0000000000000000:1", "rsp_seconds": 0.000940851, "src_site": "UNKNOWN", "hostname": "<HOSTNAME>", "original_tenant": "<TENANT>", "caf4bbc7-8c99-4614-8224-b24562a28a83.user_message": "A 'dns_load_balancer' create attempt failed validation.", "stream": "svcfw", "host": "<HOST-IPADDRESS>", "req_headers": "map[Accept:[application/json] Accept-Encoding:[gzip, deflate, br, zstd] Accept-Language:[en-US,en;q=0.9] Baggage:[sentry-environment=production,sentry-release=stellar%4081794ed7,sentry-public_key=71685aad0fd242dfab536b77770de57d,sentry-trace_id=8c450aec4a0b41d485dd8dd580bdc8bb,sentry-sample_rate=1,sentry-sampled=true] Content-Length:[383] Content-Type:[application/json] Cookie:[s_fid=743462CC04F2FEA1-1B042D1353B24A64; AMCVS_347AE3BC558C64417F000101%40AdobeOrg=1; s_cc=true; notice_behavior=implied,eu; notice_preferences=2:; TAconsentID=1533e7a9-475e-4694-a2ee-3dc75a5ce1de; notice_gdpr_prefs=0,1,2:; cmapi_gtm_bl=; cmapi_cookie_privacy=permit 1,2,3; _ga_LCQJ4PN7YC=GS2.1.s1781037529$o8$g0$t1781037529$j60$l0$h0; AMCV_347AE3BC558C64417F000101%40AdobeOrg=359503849%7CMCIDTS%7C20616%7CMCMID%7C11580729639282519162395750200226723139%7CMCAAMLH-1781816314%7C9%7CMCAAMB-1781816314%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1781218714s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.0.1; _ga=GA1.2.1627976970.1779122724; _gid=GA1.2.1956504791.1781211515; utag_main=v_id:019e3bfa4ec500591f20e7fd357005075012006d00b3b$_sn:17$_se:4$_ss:0$_st:1781221367997$vapi_domain:volterra.us$ses_id:1781219371478%3Bexp-session$session; s_sq=f5networksvolterraconsoleprod%3D%2526pid%253Dhttps%25253A%25252F%25252F<TENANT>%25252Fweb%25252Fhome%2526oid%253DAdd%252520DNS%252520Load%252520Balancer%2526oidt%253D3%2526ot%253DSUBMIT] Origin:[<TENANT>] Priority:[u=1, i] Referer:[https://<TENANT>/web/workspaces/dns-management/manage/dns_lb_management/dns_load_balancer] Sec-Ch-Ua:[\"Chromium\";v=\"148\", \"Google Chrome\";v=\"148\", \"Not/A)Brand\";v=\"99\"] Sec-Ch-Ua-Mobile:[?0] Sec-Ch-Ua-Platform:[\"macOS\"] Sec-Fetch-Dest:[empty] Sec-Fetch-Mode:[cors] Sec-Fetch-Site:[same-origin] Sentry-Trace:[8c450aec4a0b41d485dd8dd580bdc8bb-93cd0d67741d665e-1] User-Agent:[Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36] X-Envoy-Expected-Rq-Timeout-Ms:[60000] X-Envoy-External-Address:[<IPADDRESS>] X-Envoy-Original-Authority:[<TENANT>] X-Envoy-Original-Path:[/api/config/dns/namespaces/system/dns_load_balancers?csrf=eyJ0ZW5hbnQiOiJjdXN0b21lcjEiLCJ1c2VyIjoicy5sYXRlZWZAZjUuY29tIiwiZXhwaXJ5IjoiMTc4MTIxMTUxNDkwMjI4ODAwMDAifQ==.0f7dc8a6239f744f78141a5b39d39a64edbe3190a3b03c2fe4fc7db5a06f2b30] X-Forwarded-Client-Cert:[Hash=3a63f8cf9e4a7dba4ebcfa9af30510124bf90f78a720947e153d9b6264dfe7bf Cert=\"-----BEGIN%20CERTIFICATE-----<CERTIFICATE>-----END%20CERTIFICATE-----%0A\"] X-Forwarded-For:[<IPADDRESS>] X-Forwarded-Proto:[https] X-Request-Id:[5decac8b-5486-4402-b74a-66560a58357d] X-Volterra-Apigw-Authtype:[oidc] X-Volterra-Apigw-F5xc-Instance:[gc01] X-Volterra-Apigw-Namespace:[system] X-Volterra-Apigw-Original-Tenant:[<TENANT>] X-Volterra-Apigw-Real-Src-Ip:[IPADDRESS] X-Volterra-Apigw-Role:[ves-io-admin-role] X-Volterra-Apigw-Tenant:[<TENANT>] X-Volterra-Apigw-Tenant-Cname:[<TENANT>] X-Volterra-Apigw-User:[name@f5.com] X-Volterra-Gw-Skip-Jwt:[true]]", "message_key": "8189266518350495310", "tenant": "<TENANT>", "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36", "app": "<APP>", "severity": "info", "cluster_name": "<CLUSTER-NAME>", "ctx_creatorid": "name@f5.com", "method": "POST", "rpc": "ves.io.schema.dns_load_balancer.API.Create", "src": "N:Public", "rsp_code": 400, "ctx_creatorcls": "prism", "transport": "rest", "message": "API Audit post-handling", "server_id": "<SERVER-ID>", "site": "<SITE>", "@timestamp": "2026-06-11T23:13:46.801Z", "req_body": "{\"namespace\":\"system\",\"metadata\":{\"name\":\"name-test-dns\",\"description\":\"Name test DNS\",\"disable\":false},\"spec\":{\"record_type\":\"MX\",\"rule_list\":{\"rules\":[{\"geo_location_label_selector\":{\"expressions\":[\"geoip.ves.io/continent = EU\"]},\"pool\":{\"tenant\":\"<TENANT>\",\"namespace\":\"system\",\"name\":\"aj-go-lb-pool4-a-members-cule\",\"kind\":\"dns_lb_pool\"}}]},\"response_cache\":{\"disable\":{}}}}", "req_error": "{\"code\":3,\"details\":[{\"code\":\"UNKNOWN\",\"details\":\"items rules: element 0: Field spec.rule_list.rules.score fails rule ves.io.schema.rules.uint32.gte constraint 1 due to value 0\",\"timestamp\":\"2026-06-11T23:13:46Z\"}],\"message\":\"Field spec.rule_list.rules.score should be greater than or equal to 1, got 0 in request.\"}", "namespace": "system", "req_path": "/public/namespaces/system/dns_load_balancers", "time": "2026-06-11T23:13:46.801Z", "user": "name@f5.com", "original_topic_name": "fluentd.svcfw.publicaudit", "peer_CN": "prism"}Example of success audit log
{ "kubernetes": {}, "1749c66a-ef5c-4b3a-93b8-b67abc04f627.rsp_body": "{\"metadata\":{\"name\":\"name-test-fw\",\"namespace\":\"system\",\"description\":\"Test network firewall\"},\"systemMetadata\":{\"uid\":\"665c0f38-8df9-47b3-a669-22c9c7d03044\",\"creationTimestamp\":\"2026-06-11T22:13:11.837950313Z\",\"tenant\":\"<TENANT>\",\"creatorClass\":\"prism\",\"creatorId\":\"name@f5.com\"},\"spec\":{\"disableNetworkPolicy\":{},\"disableForwardProxyPolicy\":{},\"disableFastAcl\":{}}}", "dst": "S:akar", "dst_site": "UNKNOWN", "time_start": "2026-06-11 22:13:11.837347349 +0000 UTC m=+60542.173414245", "messageid": "942ceca3-5e0a-492d-baea-64a2a71657f2", "trace_info": "71de924c9d78e0d9:71de924c9d78e0d9:0000000000000000:1", "1749c66a-ef5c-4b3a-93b8-b67abc04f627.req_body": "{\"metadata\":{\"name\":\"name-test-fw\",\"namespace\":\"system\",\"description\":\"Test network firewall\"},\"spec\":{\"disableNetworkPolicy\":{},\"disableForwardProxyPolicy\":{},\"disableFastAcl\":{}}}", "rsp_seconds": 0.018497252, "src_site": "UNKNOWN", "4d8ebda7-5263-4dac-8545-33c18c25adf1.oper_name": "Create", "4d8ebda7-5263-4dac-8545-33c18c25adf1.object_json": "{\"metadata\":{\"name\":\"name-test-fw\",\"namespace\":\"system\",\"uid\":\"665c0f38-8df9-47b3-a669-22c9c7d03044\",\"description\":\"Test network firewall\"},\"system_metadata\":{\"uid\":\"665c0f38-8df9-47b3-a669-22c9c7d03044\",\"creation_timestamp\":\"2026-06-11T22:13:11.837950313Z\",\"tenant\":\"<TENANT>\",\"creator_class\":\"prism\",\"creator_id\":\"name@f5.com\",\"trace_info\":\"71de924c9d78e0d9:71de924c9d78e0d9:0000000000000000:1\",\"namespace\":[{\"kind\":\"namespace\",\"uid\":\"023cafad-8958-41b8-ae04-a0255b16847a\",\"tenant\":\"<TENANT>\",\"name\":\"system\"}]},\"spec\":{\"gc_spec\":{\"disable_network_policy\":{},\"disable_forward_proxy_policy\":{},\"disable_fast_acl\":{},\"view_internal\":{\"tenant\":\"<TENANT>\",\"namespace\":\"system\",\"name\":\"network-firewall-name-test-fw\"}}}}", "hostname": "<HOSTNAME>", "original_tenant": "<TENANT>", "caf4bbc7-8c99-4614-8224-b24562a28a83.user_message": "The 'network_firewall' 'name-test-fw' in namespace 'system' was successfully created.", "stream": "svcfw", "message_key": "-8522687506159077704", "req_size": 190, "tenant": "<TENANT>", "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36", "app": "akar", "severity": "info", "cluster_name": "<CLUSTER-NAME>", "ctx_creatorid": "name@f5.com", "4d8ebda7-5263-4dac-8545-33c18c25adf1.object_type": "ves.io.schema.network_firewall.Object", "method": "POST", "rpc": "ves.io.schema.network_firewall.API.Create", "src": "N:Public", "rsp_code": 200, "ctx_creatorcls": "prism", "rsp_body": "DEPRECATED", "transport": "rest", "message": "API Audit post-handling", "server_id": "<SERVER-ID>", "rsp_size": 755, "4d8ebda7-5263-4dac-8545-33c18c25adf1.object_name": "name-test-fw", "site": "<SITE>", "@timestamp": "2026-06-11T22:13:12.418Z", "4d8ebda7-5263-4dac-8545-33c18c25adf1.object_uid": "665c0f38-8df9-47b3-a669-22c9c7d03044", "namespace": "system", "req_path": "/public/namespaces/system/network_firewalls", "time": "2026-06-11T22:13:12.418Z", "4d8ebda7-5263-4dac-8545-33c18c25adf1.object_namespace": "system", "user": "name@f5.com", "original_topic_name": "fluentd.svcfw.publicaudit", "peer_CN": "prism"}