Get the list of event log entries main.eventlog.list
Choose a tool for developing with an AI agent:
- use Alaio Vibecode to build an app for Bitrix24 from a task description without knowing any programming language. The agent writes the code and deploys the app to a server, with no manual hosting setup
- use the MCP server to develop a REST API integration in your own project. The agent refers to the official REST documentation
Scope:
mainWho can execute the method: administrator
This method belongs to REST 3.0. The call specifics and response format of the new API version are described in the REST 3.0 overview.
The method main.eventlog.list returns a list of event log entries based on specified conditions.
Method Parameters
Required parameters are marked with *
|
Name |
Description |
|
select |
List of fields to return in the response. Available fields:
|
|
filter |
Conditions for filtering entries in the format:
Available fields are similar to those in |
|
order |
Sorting results in the format Available values:
Available fields for sorting are similar to those in |
|
pagination |
Pagination parameters:
|
Code Examples
How to Use Examples in Documentation
The new API call differs by adding the /api/ segment to the request URL:
https://{installation_address}/rest/api/{user_id}/{webhook_token}/main.eventlog.list
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"select":["id","timestampX","severity","auditTypeId","moduleId","itemId","userId","description"],"filter":[["timestampX",">=","2026-01-30T00:00:00+02:00"],["timestampX","<","2026-01-31T00:00:00+02:00"]],"order":{"id":"ASC"},"pagination":{"page":1,"limit":20,"offset":0}}' \
https://**put_your_bitrix24_address**/rest/api/**put_your_user_id_here**/**put_your_webhook_here**/main.eventlog.list
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"select":["id","timestampX","severity","auditTypeId","moduleId","itemId","userId","description"],"filter":[["timestampX",">=","2026-01-30T00:00:00+02:00"],["timestampX","<","2026-01-31T00:00:00+02:00"]],"order":{"id":"ASC"},"pagination":{"page":1,"limit":20,"offset":0},"auth":"**put_access_token_here**"}' \
https://**put_your_bitrix24_address**/rest/api/main.eventlog.list
// This snippet is an ES module: top-level await requires type="module" or a bundler.
// $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
import { Text } from '@bitrix24/b24jssdk'
import type { B24Frame, ISODate } from '@bitrix24/b24jssdk'
declare const $b24: B24Frame
type EventLogItem = {
id: number
timestampX: ISODate | null
severity: string
auditTypeId: string
moduleId: string
itemId: string
remoteAddr: string
userAgent: string
requestUri: string
siteId: string
userId: number
guestId: number
description: string
}
// Shape of the payload returned in result (match the "response handling" section of the page)
type EventLogListResult = {
items: EventLogItem[]
}
try {
// main.eventlog.list returns a single page (max 50 records). For the whole result set
// use a list helper: $b24.actions.v3.callList.make() returns every record as one
// array, $b24.actions.v3.fetchList.make() yields them in chunks (async generator).
// NOTE: the list helpers do not accept `order` (it is excluded from their params, so
// passing it is a TS error) — keep this call.make + `pagination` variant when sort matters.
const response = await $b24.actions.v3.call.make<EventLogListResult>({
method: 'main.eventlog.list',
params: {
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description',
],
filter: [
['timestampX', '>=', '2026-01-30T00:00:00+03:00'],
['timestampX', '<', '2026-01-31T00:00:00+03:00'],
],
order: {
id: 'ASC',
},
pagination: {
page: 1,
limit: 20,
offset: 0,
},
},
requestId: Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
} else {
const result = response.getData()!.result
console.info('Event log entries:', result.items.length, result.items)
}
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
<script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
<script>
async function getEventLogList() {
try {
// Initialize the SDK inside a Bitrix24 frame
const $b24 = await B24Js.initializeB24Frame()
// main.eventlog.list returns a single page (max 50 records). For the whole result set
// use a list helper: $b24.actions.v3.callList.make() returns every record as one
// array, $b24.actions.v3.fetchList.make() yields them in chunks (async generator).
// NOTE: the list helpers do not accept `order` (it is excluded from their params, so
// passing it is a TS error) — keep this call.make + `pagination` variant when sort matters.
const response = await $b24.actions.v3.call.make({
method: 'main.eventlog.list',
params: {
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description',
],
filter: [
['timestampX', '>=', '2026-01-30T00:00:00+03:00'],
['timestampX', '<', '2026-01-31T00:00:00+03:00'],
],
order: {
id: 'ASC',
},
pagination: {
page: 1,
limit: 20,
offset: 0,
},
},
requestId: B24Js.Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
return
}
const result = response.getData().result
console.info('Event log entries:', result.items.length, result.items)
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
}
document.addEventListener('DOMContentLoaded', getEventLogList)
</script>
from b24pysdk.errors import BitrixAPIError, BitrixSDKException
select = [
"id",
"timestampX",
"severity",
"auditTypeId",
"moduleId",
"itemId",
"userId",
"description",
]
filter = [
[
"timestampX",
">=",
"2026-01-30T00:00:00+03:00",
],
[
"timestampX",
"<",
"2026-01-31T00:00:00+03:00",
],
]
order = {
"id": "ASC",
}
pagination = {
"page": 1,
"limit": 20,
"offset": 0,
}
try:
bitrix_response = client.main.eventlog.list(
select=select,
filter=filter,
order=order,
pagination=pagination,
).response
result = bitrix_response.result
print(result)
except BitrixAPIError as error:
print(
"Bitrix API error",
f"error: {error.error}",
f"error_description: {error.error_description}",
sep="\n",
)
except BitrixSDKException as error:
print(f"Bitrix SDK error: {error.message}")
except Exception as error:
print(f"Unexpected error: {error}")
SDKs do not yet support the /rest/api/ address in calls. Use direct HTTP requests, for example, via curl or fetch.
try {
$response = $b24Service
->core
->call(
'main.eventlog.list',
[
'select' => [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
'filter' => [
['timestampX', '>=', '2026-01-30T00:00:00+02:00'],
['timestampX', '<', '2026-01-31T00:00:00+02:00']
],
'order' => [
'id' => 'ASC'
],
'pagination' => [
'page' => 1,
'limit' => 20,
'offset' => 0
]
]
);
$result = $response
->getResponseData()
->getResult();
echo 'Success: ' . print_r($result, true);
} catch (Throwable $e) {
error_log($e->getMessage());
echo 'Error: ' . $e->getMessage();
}
SDKs do not yet support the /rest/api/ address in calls. Use direct HTTP requests, for example, via curl or fetch.
BX24.callMethod(
'main.eventlog.list',
{
select: [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
filter: [
['timestampX', '>=', '2026-01-30T00:00:00+02:00'],
['timestampX', '<', '2026-01-31T00:00:00+02:00']
],
order: {
id: 'ASC'
},
pagination: {
page: 1,
limit: 20,
offset: 0
}
},
function(result){
console.info(result.data());
console.log(result);
}
);
SDKs do not yet support the /rest/api/ address in calls. Use direct HTTP requests, for example, via curl or fetch.
require_once('crest.php');
$result = CRest::call(
'main.eventlog.list',
[
'select' => [
'id',
'timestampX',
'severity',
'auditTypeId',
'moduleId',
'itemId',
'userId',
'description'
],
'filter' => [
['timestampX', '>=', '2026-01-30T00:00:00+02:00'],
['timestampX', '<', '2026-01-31T00:00:00+02:00']
],
'order' => [
'id' => 'ASC'
],
'pagination' => [
'page' => 1,
'limit' => 20,
'offset' => 0
]
]
);
echo '<PRE>';
print_r($result);
echo '</PRE>';
// client and ctx are already created — see the Go SDK section
res, err := client.Core().Call(ctx, "main.eventlog.list", b24.Params{
"select": []string{"id", "timestampX", "severity", "auditTypeId", "moduleId", "itemId", "userId", "description"},
"filter": []any{
[]string{"timestampX", ">=", "2026-01-30T00:00:00+03:00"},
[]string{"timestampX", "<", "2026-01-31T00:00:00+03:00"},
},
"order": b24.Params{
"id": "ASC",
},
"pagination": b24.Params{
"page": 1,
"limit": 20,
"offset": 0,
},
}, b24.WithIdempotent())
if err != nil {
return fmt.Errorf("main.eventlog.list: %w", err)
}
// The method wraps the response in an object with the "items" key.
raw, ok := b24.Unwrap(res.Result, "items")
if !ok {
return fmt.Errorf("no items key in the response")
}
var items []struct {
ID b24.ID `json:"id"`
TimestampX string `json:"timestampX"`
Severity string `json:"severity"`
AuditTypeID string `json:"auditTypeId"`
ModuleID string `json:"moduleId"`
ItemID b24.ID `json:"itemId"`
}
if err := json.Unmarshal(raw, &items); err != nil {
return fmt.Errorf("parse response: %w", err)
}
for _, it := range items {
fmt.Println(it.ID)
}
Response Handling
HTTP Status: 200
{
"result": {
"items": [
{
"id": 443585,
"timestampX": "2026-01-22T02:52:25+02:00",
"severity": "SECURITY",
"auditTypeId": "USER_AUTHORIZE",
"moduleId": "main",
"itemId": "751",
"userId": 751,
"description": "{\u0022userId\u0022:751,\u0022requestId\u0022:\u00225636cd3e45c524c55a68a19dccb72c3b-0\u0022,\u0022method\u0022:\u0022external\u0022}"
},
// ...
{
"id": 443623,
"timestampX": "2026-01-22T05:21:51+02:00",
"severity": "SECURITY",
"auditTypeId": "USER_AUTHORIZE",
"moduleId": "main",
"itemId": "751",
"userId": 751,
"description": "{\u0022userId\u0022:751,\u0022requestId\u0022:\u002239aae4ca278ad75ca3dc631c7b4f8fe2-0\u0022,\u0022method\u0022:\u0022external\u0022}"
}
]
},
"time": {
"start": 1769773532,
"finish": 1769773532.960023,
"duration": 0.9600229263305664,
"processing": 0,
"date_start": "2026-01-30T14:45:32+02:00",
"date_finish": "2026-01-30T14:45:32+02:00",
"operating_reset_at": 1769774132,
"operating": 0
}
}
Returned Data
|
Name |
Description |
|
result |
Object with response data |
|
items |
Array of log entry objects |
|
items[] |
Log entry object |
|
id |
Log entry identifier |
|
timestampX |
Date and time of the event |
|
severity |
Importance level of the event |
|
auditTypeId |
Type of event |
|
moduleId |
Module identifier |
|
itemId |
Object identifier |
|
remoteAddr |
IP address |
|
userAgent |
Request User-Agent |
|
requestUri |
Request URI |
|
siteId |
Site identifier |
|
userId |
User identifier |
|
guestId |
Guest identifier |
|
description |
Event description |
|
time |
Information about the request execution time |
Error Handling
HTTP Status: 400
{
"error": {
"code": "BITRIX_REST_V3_EXCEPTION_INVALIDPAGINATIONEXCEPTION",
"message": "Cannot recognize pagination parameter `{\"limit\":\"abc\"}`"
}
}
|
Name |
Description |
|
error.code |
String error code. Use it to identify the type of exception |
|
error.message |
Text description of the error |
|
error.validation |
Array with error details. Present only in data validation errors |
|
error.validation[].field |
Name of the field where the validation error occurred |
|
error.validation[].message |
Description of the error related to the specified field |
Possible Error Codes
Access Errors
Error Code: BITRIX_REST_V3_EXCEPTION_ACCESSDENIEDEXCEPTION
|
Field |
Error Description |
How to Fix |
|
|
Access denied |
No administrator rights or missing scope main |
Pagination Errors
Error Code: BITRIX_REST_V3_EXCEPTION_INVALIDPAGINATIONEXCEPTION
|
Field |
Error Description |
How to Fix |
|
|
Cannot recognize pagination parameter |
Provide numeric values. |
Statuses and System Error Codes
HTTP Status: 4xx, 5xx
The errors described below are returned by the REST API itself, not by the logic of a specific method. They can arrive in response to any method.
|
Status |
Code |
Description |
|
|
|
An internal server error has occurred. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The server returned an unexpected response. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The request intensity limit has been exceeded |
|
|
|
The method is blocked because the request resource intensity limit has been exceeded. The block is lifted automatically once the accumulated execution time of the method no longer exceeds the limit |
|
|
|
The request contains no authorization data: neither an access token nor a webhook code was passed |
|
|
|
Methods are called over the HTTPS protocol only |
|
|
|
The REST API is blocked due to overload. This is a manual individual block. To have it lifted, contact Bitrix24 technical support |
|
|
|
REST API access is not active for this account. In Bitrix24 Cloud, check the current plan or trial status: Vibe+ plans include REST API access, while Essentials plans do not. A webhook receives a different error message — |
|
|
|
No active webhook with the specified user identifier and secret code was found |
|
|
|
No method with this name was found. The name is misspelled, the method does not exist in the REST API, or it is unavailable without the required scope |
|
|
|
The request requires broader permissions than the token has: for a webhook these are the permissions granted to it, for an application it is the scope. For an application, the error message ends with |
|
|
|
The access token has expired |
|
|
|
The application is installed, but the Bitrix24 administrator has granted access to it only to specific users |
|
|
|
The public part of the site is closed. To open it on an on-premise installation, disable the "Temporary closure of the public part of the site" option. Path to the setting: Desktop > Settings > Product Settings > Module Settings > Main Module > Temporary closure of the public part of the site |