# Audit Logs Retrieves Neat Pulse audit log entries — system-generated, immutable records of significant control-plane actions (who did what, when, and to what) across an organisation's Neat device fleet. Entries cover user invites and role changes, SAML configuration, device enrollment, factory resets, reboots, remote-control sessions, API key lifecycle, room/location/region/profile CRUD, and actions taken by Neat Support staff on the customer's fleet. **Sync Type: Incremental** ## Prerequisites - A **Neat Pulse Pro** paid subscription with administered Neat hardware. - Organisation admin access to the Neat Pulse management platform. - The **Organisation ID** (`orgid`) of the org you want to collect audit logs from. Neat Pulse API keys are bound to a single organisation, so you need one Monad input instance per org. - An **API account** with the **Read** scope, created in Pulse admin under **Organisation settings → API accounts**. ## Authentication Neat Pulse uses a static, long-lived Bearer API key issued per organisation. To obtain one: 1. Sign in to the [Neat Pulse management platform](https://pulse.neat.no/) as an organisation admin. 2. Navigate to **Organisation settings → API accounts**. 3. Click **Create** and give the API account a descriptive name (e.g. `monad-audit-logs`). 4. Grant the **Read** scope on the organisation. Write is not required to fetch audit logs. 5. Copy the generated API key immediately — it is displayed only once. Store it in your secret manager and paste it into the **API Key** field when configuring the input in Monad. 6. Note the **Organisation ID**: it is shown under **Organisation settings**, and is also the path segment in your Pulse URL — in `https://pulse.neat.no/DvwPzbY/p/rooms` the org ID is `DvwPzbY`. See Neat's official guide for managing API accounts: [Managing API accounts on Neat Pulse](https://support.neat.no/article/managing-api-accounts-on-neat-pulse-management-platform/). ## Configuration The following configuration defines the input parameters. Each field's specifications, such as type, requirements, and descriptions, are detailed below. #### Settings | Setting | Type | Required | Description | |---------|------|----------|-------------| | Organisation ID | string | Yes | Neat Pulse organisation ID that owns the API key (e.g. `org_abc123`). API keys are org-scoped; use one input instance per organisation. | | Backfill Start Time | string | No | RFC 3339 / ISO 8601 timestamp to start fetching audit logs from (e.g. `2026-06-01T00:00:00Z`). If not specified, the first sync starts from now and all subsequent syncs are incremental. | | API Rate Limit | object | No | Maximum outbound request rate to the Neat Pulse API (`rate` + `unit`). Neat publishes no documented rate ceiling, so this defaults to **1 request/second** and is capped at 10 requests/second. | | Use Synthetic Data | boolean | No | Generate synthetic demo data instead of connecting to the real data source. Useful for pipeline testing without a live Neat Pulse tenant. | #### Secrets | Secret | Type | Required | Description | |---------|------|----------|-------------| | API Key | string | Yes | Neat Pulse API key sent as `Authorization: Bearer `. Requires the **Read** scope on the target organisation and a Neat Pulse Pro subscription. | ## Setup Walk-through 1. In Neat Pulse, create an API account with the Read scope and copy the API key (see [Authentication](#authentication)). 2. In Monad, create a new input and select **Neat Pulse → Audit Logs**. 3. Paste your Neat Pulse **Organisation ID** into the **Organisation ID** field. 4. Paste the API key into the **API Key** secret field. 5. Optionally raise **API Rate Limit** above the 1 request/second default if you are backfilling a large window and Neat tolerates it. 6. Optionally set **Backfill Start Time** to an RFC 3339 timestamp if you want to pull historical entries. Neat does not publish a retention window; older logs may be unavailable. 7. Attach the input to a pipeline and save. ## Sync Behaviour Each sync fetches the window `[last watermark, now - 1 minute)`. The one-minute lag is deliberate: Neat Pulse writes audit entries asynchronously, so an entry timestamped "now" may not yet be queryable. Ending the window a minute in the past avoids stepping over those late-arriving entries. The practical effect is that new audit events appear in Monad roughly one minute after they occur, in addition to your pipeline's scheduled sync interval. Requests are rate-limited to 1 request/second by default (see **API Rate Limit**). A large backfill is therefore paced at 100 entries/second and may take several syncs to drain. ## Troubleshooting ### Common Issues - **`401 Unauthorized`** — the API key is invalid, has been revoked, or was rotated. Issue a fresh key in **Pulse → Organisation settings → API accounts** and update the input's **API Key** secret. - **`403 Forbidden`** — the API key lacks the **Read** scope on the organisation, or the **Organisation ID** setting does not match the org the key was issued for. Recreate the API account with the correct scope and verify the `orgid`. - **`404 Not Found`** — the **Organisation ID** is incorrect or the org is archived. Confirm the ID in Pulse admin. - **`400 Bad Request`** — usually caused by an invalid **Backfill Start Time**. Use RFC 3339 UTC format, e.g. `2026-06-01T00:00:00Z`. - **Newest events missing** — expected. The sync window ends one minute in the past (see [Sync Behaviour](#sync-behaviour)); the entries arrive on the next sync. - **Backfill progressing slowly** — the default rate limit is 1 request/second (100 entries/page). Raise **API Rate Limit** if needed. - **No entries returned but no error** — audit log volume is normally low (control-plane events only, not device telemetry). Verify by taking an admin action in Pulse (e.g. changing a room name) and waiting for the next sync. ## Related Articles - [Neat Pulse Audit Logs API reference](https://api.pulse.neat.no/docs/#api-Audit-auditLogs) - [Managing API accounts on Neat Pulse](https://support.neat.no/article/managing-api-accounts-on-neat-pulse-management-platform/) - [Neat Pulse API key rotation](https://api.pulse.neat.no/docs/#api-ApiKeys-apiKeysRotate) - [Neat Pulse product overview](https://neat.no/pulse/)