Audit Logs
Retrieves Neat Pulse audit log entries — system-generated, immutable records of significant control-plane actions (who did what, when, and to what) across an organisation's Neat device fleet. Entries cover user invites and role changes, SAML configuration, device enrollment, factory resets, reboots, remote-control sessions, API key lifecycle, room/location/region/profile CRUD, and actions taken by Neat Support staff on the customer's fleet.
Sync Type: Incremental
Prerequisites
- A Neat Pulse Pro paid subscription with administered Neat hardware.
- Organisation admin access to the Neat Pulse management platform.
- The Organisation ID (
orgid) of the org you want to collect audit logs from. Neat Pulse API keys are bound to a single organisation, so you need one Monad input instance per org. - An API account with the Read scope, created in Pulse admin under Organisation settings → API accounts.
Authentication
Neat Pulse uses a static, long-lived Bearer API key issued per organisation. To obtain one:
- Sign in to the Neat Pulse management platform as an organisation admin.
- Navigate to Organisation settings → API accounts.
- Click Create and give the API account a descriptive name (e.g.
monad-audit-logs). - Grant the Read scope on the organisation. Write is not required to fetch audit logs.
- Copy the generated API key immediately — it is displayed only once. Store it in your secret manager and paste it into the API Key field when configuring the input in Monad.
- Note the Organisation ID: it is shown under Organisation settings, and is also the path segment in your Pulse URL — in
https://pulse.neat.no/DvwPzbY/p/roomsthe org ID isDvwPzbY.
See Neat's official guide for managing API accounts: Managing API accounts on Neat Pulse.
Configuration
The following configuration defines the input parameters. Each field's specifications, such as type, requirements, and descriptions, are detailed below.
Settings
| Setting | Type | Required | Description |
|---|---|---|---|
| Organisation ID | string | Yes | Neat Pulse organisation ID that owns the API key (e.g. org_abc123). API keys are org-scoped; use one input instance per organisation. |
| Backfill Start Time | string | No | RFC 3339 / ISO 8601 timestamp to start fetching audit logs from (e.g. 2026-06-01T00:00:00Z). If not specified, the first sync starts from now and all subsequent syncs are incremental. |
| API Rate Limit | object | No | Maximum outbound request rate to the Neat Pulse API (rate + unit). Neat publishes no documented rate ceiling, so this defaults to 1 request/second and is capped at 10 requests/second. |
| Use Synthetic Data | boolean | No | Generate synthetic demo data instead of connecting to the real data source. Useful for pipeline testing without a live Neat Pulse tenant. |
Secrets
| Secret | Type | Required | Description |
|---|---|---|---|
| API Key | string | Yes | Neat Pulse API key sent as Authorization: Bearer <key>. Requires the Read scope on the target organisation and a Neat Pulse Pro subscription. |
Setup Walk-through
- In Neat Pulse, create an API account with the Read scope and copy the API key (see Authentication).
- In Monad, create a new input and select Neat Pulse → Audit Logs.
- Paste your Neat Pulse Organisation ID into the Organisation ID field.
- Paste the API key into the API Key secret field.
- Optionally raise API Rate Limit above the 1 request/second default if you are backfilling a large window and Neat tolerates it.
- Optionally set Backfill Start Time to an RFC 3339 timestamp if you want to pull historical entries. Neat does not publish a retention window; older logs may be unavailable.
- Attach the input to a pipeline and save.
Sync Behaviour
Each sync fetches the window [last watermark, now - 1 minute). The one-minute lag
is deliberate: Neat Pulse writes audit entries asynchronously, so an entry
timestamped "now" may not yet be queryable. Ending the window a minute in the past
avoids stepping over those late-arriving entries. The practical effect is that new
audit events appear in Monad roughly one minute after they occur, in addition to
your pipeline's scheduled sync interval.
Requests are rate-limited to 1 request/second by default (see API Rate Limit). A large backfill is therefore paced at 100 entries/second and may take several syncs to drain.
Troubleshooting
Common Issues
401 Unauthorized— the API key is invalid, has been revoked, or was rotated. Issue a fresh key in Pulse → Organisation settings → API accounts and update the input's API Key secret.403 Forbidden— the API key lacks the Read scope on the organisation, or the Organisation ID setting does not match the org the key was issued for. Recreate the API account with the correct scope and verify theorgid.404 Not Found— the Organisation ID is incorrect or the org is archived. Confirm the ID in Pulse admin.400 Bad Request— usually caused by an invalid Backfill Start Time. Use RFC 3339 UTC format, e.g.2026-06-01T00:00:00Z.- Newest events missing — expected. The sync window ends one minute in the past (see Sync Behaviour); the entries arrive on the next sync.
- Backfill progressing slowly — the default rate limit is 1 request/second (100 entries/page). Raise API Rate Limit if needed.
- No entries returned but no error — audit log volume is normally low (control-plane events only, not device telemetry). Verify by taking an admin action in Pulse (e.g. changing a room name) and waiting for the next sync.
Related Articles
- Neat Pulse Audit Logs API reference
- Managing API accounts on Neat Pulse
- Neat Pulse API key rotation
- Neat Pulse product overview