Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
This system table is in Public Preview.
This article outlines the audit log table schema and has sample queries you can use with the audit log system table to answer common account activity questions. For information on audit log events, see Diagnostic log reference.
Table path: This system table is located at system.access.audit.
Audit log considerations
- Most audit logs are only available in the region of the workspace.
- Account-level audit logs record
workspace_idas0. - When you delete a workspace, Azure Databricks removes that workspace's audit events that are older than 14 days from
system.access.audit. - If the
__databricks_internalcatalog appears in audit events or other system tables, it is a reserved catalog that Azure Databricks uses to store internal state. See The__databricks_internalcatalog. - For some events, keys in
request_paramsthat contain SQL definitions are omitted unless you are an account admin or a member of thedatabricks_pii_accessgroup. See Access masked request parameters.
Audit log system table schema
The audit log system table uses the following schema:
| Column name | Data type | Description | Example |
|---|---|---|---|
account_id |
string | ID of the account | 23e22ba4-87b9-4cc2-9770-d10b894bxx |
workspace_id |
string | ID of the workspace | 1234567890123456 |
version |
string | Audit log schema version | 2.0 |
event_time |
timestamp | Timestamp of the event. Timezone information is recorded at the end of the value with +00:00 representing UTC timezone. |
2023-01-01T01:01:01.123+00:00 |
event_date |
date | Calendar date the action took place. To improve query performance, filter on event_date rather than event_time. |
2023-01-01 |
source_ip_address |
string | IP address where the request originated | 10.30.0.242 |
user_agent |
string | Origination of request | Apache-HttpClient/4.5.13 (Java/1.8.0_345) |
session_id |
string | ID of the session where the request came from | 123456789 |
user_identity |
struct | Identity of user initiating request | {"email": "user@domain.com","subjectName": null} |
service_name |
string | Service name initiating request | unityCatalog |
action_name |
string | Category of the event captured in audit log | getTable |
request_id |
string | ID of request | ServiceMain-4529754264 |
request_params |
map | Map of key values containing all the request parameters. Depends on request type. For some events, keys that contain SQL definitions are omitted unless you are an account admin or a member of the databricks_pii_access group. See Access masked request parameters. |
[["full_name_arg", "user.chat.messages"],["workspace_id", "123456789"],["metastore_id", "123456789"]] |
response |
struct | Struct of response return values | {"statusCode": 200, "errorMessage": null,"result": null} |
audit_level |
string | Workspace or account level event | ACCOUNT_LEVEL |
event_id |
string | ID of the event | 34ac703c772f3549dcc8671f654950f0 |
identity_metadata |
struct | Identities involved in the action, including run_by and run_as. See Identity metadata reference and Auditing group dedicated compute activity. |
{"run_by": "example@email.com","run_as": "example@email.com"} |
Identity metadata reference
The identity_metadata struct has the following schema:
{
"run_by": "string",
"run_as": "string",
"run_by_display_name": "string",
"run_as_display_name": "string",
"acting_resource": "string",
"acting_resource_type": "string",
"acting_resource_display_name": "string"
}
The struct captures the identities involved in an action:
run_byis the identity that initiated the event, andrun_asis the identity used for authorization.run_by_display_nameandrun_as_display_nameare their human-readable display names.acting_resource,acting_resource_type, andacting_resource_display_nameare populated when a resource acts on behalf of a user, such as an OAuth app.acting_resourceis the resource path,acting_resource_typeis the type of resource, andacting_resource_display_nameis its human-readable name (for an OAuth app, the name of the app).
The acting_resource path takes one of the following forms:
accounts/<account_id>/published-app-client-ids/<client_id>when the actor is a published OAuth app, for exampledatabricks-cli.accounts/<account_id>/oauth2/custom-app-integrations/<client_id>when the actor is a customer OAuth app, where<client_id>is a UUID.
Access masked request parameters
Some audit events store SQL definitions in request_params. Those keys are omitted unless you are an account admin or a member of the databricks_pii_access account-level group:
function_infoview_definitiondefinition_jsonmanaged_definition
Other keys in request_params and all other columns are unchanged. Access to unmasked values uses the databricks_pii_access group. To create the group and manage its membership and permissions, see Create and manage the databricks_pii_access group.