Every audit log entry has one of the event names below, in the form resource.action (a few have an extra part, such as portal.session.create). Filter on them in the dashboard’s Events menu or in a log drain.
The Events menu and the log drain picker also list six names that are never recorded: environment.create, deployment.redeploy, secret.update, and three webhook.* names. Filtering on them matches nothing. Unkey doesn’t send webhooks. Use a log drain to forward entries to your own endpoint.
Workspace
Keyspaces and keys
Authorization
Identities
Rate limiting
Developer portal
Compute
Compute actions appear in the same log.
Last modified on September 29, 2026