main.eventlog.tail
Получить новые записи журнала
Описание
Метод относится к REST 3.0. Особенности вызова и формат ответа новой версии API описаны в обзоре REST 3.0.
Метод main.eventlog.tail возвращает новые записи журнала, которые появились после заданной точки отсчета cursor, с учетом фильтра.
Параметры
select
array
необязательный
Список полей, которые нужно вернуть в ответе.
Доступные поля:
- id — идентификатор записи журнала
- timestampX — дата и время события
- severity — уровень важности события
- auditTypeId — тип события
- moduleId — идентификатор модуля
- itemId — идентификатор объекта
- remoteAddr — IP-адрес
- userAgent — User-Agent запроса
- requestUri — URI запроса
- siteId — идентификатор сайта
- userId — идентификатор пользователя
- guestId — идентификатор гостя
- description — описание события
filter
array
необязательный
Условия фильтрации записей в формате:
- ["field", "operator", value]
- ["field", value], оператор по умолчанию =
Доступные поля аналогичны полям в select.
Подробнее о работе фильтрации в REST 3.0
cursor
object
необязательный
Точка отсчета для получения новых записей:
field— поле сортировки, по умолчаниюidorder— направление сортировкиASCилиDESC, по умолчаниюASCvalue— стартовое значение, по умолчанию0limit— лимит записей, по умолчанию50
Примеры запроса
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"select":["id","timestampX","severity","auditTypeId","moduleId","itemId","userId","description"],"filter":[],"cursor":{"field":"id","value":446313,"order":"ASC"}}' \
https://**put_your_bitrix24_address**/rest/api/**put_your_user_id_here**/**put_your_webhook_here**/main.eventlog.tail
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"select":["id","timestampX","severity","auditTypeId","moduleId","itemId","userId","description"],"filter":[],"cursor":{"field":"id","value":446313,"order":"ASC"},"auth":"**put_access_token_here**"}' \
https://**put_your_bitrix24_address**/rest/api/main.eventlog.tail
// This snippet is an ES module: top-level await requires type="module" or a bundler.
// $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
import { Text } from '@bitrix24/b24jssdk'
import type { B24Frame, ISODate } from '@bitrix24/b24jssdk'
declare const $b24: B24Frame
type EventLogEntry = {
id: number
timestampX: ISODate
severity: string
auditTypeId: string
moduleId: string
itemId: string
remoteAddr: string
userAgent: string
requestUri: string
siteId: string
userId: number
guestId: number
description: string
}
// Shape of the payload returned in result (match the "response handling" section of the page)
type EventLogTailResult = {
items: EventLogEntry[]
}
try {
const response = await $b24.actions.v3.call.make<EventLogTailResult>({
method: 'main.eventlog.tail',
params: {
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description',
],
filter: [],
cursor: {
field: 'id',
value: 446313,
order: 'ASC',
},
},
requestId: Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
} else {
const result = response.getData()!.result
console.info('Received entries:', result.items.length, result.items[0]?.id)
}
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
<script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
<script>
async function fetchEventLogTail() {
try {
// Initialize the SDK inside a Bitrix24 frame
const $b24 = await B24Js.initializeB24Frame()
const response = await $b24.actions.v3.call.make({
method: 'main.eventlog.tail',
params: {
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description',
],
filter: [],
cursor: {
field: 'id',
value: 446313,
order: 'ASC',
},
},
requestId: B24Js.Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
return
}
const result = response.getData().result
console.info('Received entries:', result.items.length, result.items[0]?.id)
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
}
document.addEventListener('DOMContentLoaded', fetchEventLogTail)
</script>
from b24pysdk.errors import BitrixAPIError, BitrixSDKException
select = [
"id",
"timestampX",
"severity",
"auditTypeId",
"moduleId",
"itemId",
"userId",
"description",
]
filter = []
cursor = {
"field": "id",
"value": 446313,
"order": "ASC",
}
try:
bitrix_response = client.main.eventlog.tail(
select=select,
filter=filter,
cursor=cursor,
).response
result = bitrix_response.result
print(result)
except BitrixAPIError as error:
print(
"Ошибка Bitrix API",
f"error: {error.error}",
f"error_description: {error.error_description}",
sep="\n",
)
except BitrixSDKException as error:
print(f"Ошибка Bitrix SDK: {error.message}")
except Exception as error:
print(f"Непредвиденная ошибка: {error}")
try {
$response = $b24Service
->core
->call(
'main.eventlog.tail',
[
'select' => [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
'filter' => [],
'cursor' => [
'field' => 'id',
'value' => 446313,
'order' => 'ASC'
]
]
);
$result = $response
->getResponseData()
->getResult();
echo 'Success: ' . print_r($result, true);
} catch (Throwable $e) {
error_log($e->getMessage());
echo 'Error: ' . $e->getMessage();
}
BX24.callMethod(
'main.eventlog.tail',
{
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
filter: [],
cursor: {
field: 'id',
value: 446313,
order: 'ASC'
}
},
function(result){
console.info(result.data());
console.log(result);
}
);
require_once('crest.php');
$result = CRest::call(
'main.eventlog.tail',
[
'select' => [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
'filter' => [],
'cursor' => [
'field' => 'id',
'value' => 446313,
'order' => 'ASC'
]
]
);
echo '<PRE>';
print_r($result);
echo '</PRE>';
// client и ctx уже созданы — см. раздел «SDK для Go»
res, err := client.Core().Call(ctx, "main.eventlog.tail", b24.Params{
"select": []string{"id", "timestampX", "severity", "auditTypeId", "moduleId", "itemId", "userId", "description"},
"filter": []any{},
"cursor": b24.Params{
"field": "id",
"value": 446313,
"order": "ASC",
},
})
if err != nil {
return fmt.Errorf("main.eventlog.tail: %w", err)
}
// Метод заворачивает ответ в объект с ключом "items".
raw, ok := b24.Unwrap(res.Result, "items")
if !ok {
return fmt.Errorf("в ответе нет ключа items")
}
var items []struct {
ID b24.ID `json:"id"`
TimestampX string `json:"timestampX"`
Severity string `json:"severity"`
AuditTypeID string `json:"auditTypeId"`
ModuleID string `json:"moduleId"`
ItemID b24.ID `json:"itemId"`
}
if err := json.Unmarshal(raw, &items); err != nil {
return fmt.Errorf("разбор ответа: %w", err)
}
for _, it := range items {
fmt.Println(it.ID)
}
Ответ
HTTP-статус: 200
{
"result": {
"items": [
{
"id": 446315,
"timestampX": "2026-01-30T14:05:38+03:00",
"severity": "SECURITY",
"auditTypeId": "USER_AUTHORIZE",
"moduleId": "main",
"itemId": "1463",
"userId": 1463,
"description": "{\"userId\":1463,\"applicationId\":\"mobile\",\"applicationPasswordId\":977,\"requestId\":\"1649cc2c8540e12c1f3aeb1e670c13f8\\\"-\\\"0\",\"method\":\"appPassword\"}"
},
// ....
{
"id": 446325,
"timestampX": "2026-01-30T15:03:02+03:00",
"severity": "SECURITY",
"auditTypeId": "USER_AUTHORIZE",
"moduleId": "rest",
"itemId": "971",
"userId": 971,
"description": "{\"userId\":971,\"method\":\"rest\",\"applicationType\":\"apauth\",\"applicationId\":383,\"timePeriod\":\"2026-01-30 15\"}"
}
]
},
"time": {
"start": 1769774582,
"finish": 1769774583.014603,
"duration": 1.0146028995513916,
"processing": 0,
"date_start": "2026-01-30T15:03:02+03:00",
"date_finish": "2026-01-30T15:03:03+03:00",
"operating_reset_at": 1769775183,
"operating": 0
}
}
Возвращаемые данные
result
object
Объект с данными ответа
items
array
Массив объектов записей журнала
items[]
object
Объект записи журнала
id
integer
Идентификатор записи журнала
timestampX
datetime
Дата и время события
severity
string
Уровень важности события
auditTypeId
string
Тип события
moduleId
string
Идентификатор модуля
itemId
string
Идентификатор объекта
remoteAddr
string
IP-адрес
userAgent
string
User-Agent запроса
requestUri
string
URI запроса
siteId
string
Идентификатор сайта
userId
integer
Идентификатор пользователя
guestId
integer
Идентификатор гостя
description
string
Описание события
time
time
Информация о времени выполнения запроса
Обработка ошибок
HTTP-статус: 400
{
"error": {
"code": "BITRIX_REST_V3_EXCEPTION_INVALIDFILTEREXCEPTION",
"message": "Не удается распознать выражение фильтра `Cursor field id cannot be used at filter.`"
}
}
| Код | Описание | Значение |
|---|---|---|
Поле |
Описание ошибки | Как исправить |
| — | Доступ запрещен | Нет прав администратора или не хватает scope main |

