# Audit-events API Reference

> Source: https://centric-api-docs.certn.co/#audit-events

## Endpoints

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/public/audit-events/` |  |

### GET /api/public/audit-events/

Return audit subscription events for SIEM polling (commit-order, cursor-based).

``event_id`` is the per-customer ``publish_seq`` (commit-visibility sequence),
so events are delivered in ascending ``event_id`` order - which is commit
order, NOT ``event_datetime`` order. A late-committed row is appended at the
tail (higher ``publish_seq`` / ``event_id``) and delivered late but never
lost; consumers sort by ``event_datetime`` and dedupe on ``event_id``.

#### Parameters

| Name | In | Type | Required | Description |
|------|-----|------|----------|-------------|
| `last_processed_event_id` | query | integer | No | Cursor - the event_id of the last event you processed. An empty last_processed_event_id is treated as omitted (not an error). Delivery resumes strictly after it. A malformed value or one below 1 is rejected with 400; a well-formed id that is unknown or aged-out is forward-only and simply resumes after that sequence position (no error). If you lose your cursor, re-poll with no last_processed_event_id (from the earliest available event) and de-duplicate on event_id. |
| `limit` | query | integer | No | Maximum number of records to return per request (batch size for cursor paging). The server enforces a batch cap; values above the cap are reduced to the cap. If limit is omitted, a server-side default batch size applies. |

#### Example Request

```bash
curl -X GET "https://api.sandbox.certn.co/api/public/audit-events/" \
  -H "Authorization: Api-Key YOUR_API_KEY"
```

---

*See the [interactive documentation](https://centric-api-docs.certn.co/#audit-events) for more details.*