maqpna audit export
Export audit records, filtered by session, namespace, agent or time
Synopsis#
maqpna audit export FILE [--session S] [--namespace NS] [--agent A] [--since RFC3339] [--until RFC3339] [--out FILE]
maqpna audit export --gateway URL [--session S] [--namespace NS] [--agent A] [--user U] [--since RFC3339] [--until RFC3339] [--out FILE]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent | string | agent filter | none |
--namespace | string | namespace filter | none |
--out | string | write bundle to file instead of stdout | none |
--session | string | session filter | none |
--since | string | RFC3339 start (inclusive) | none |
--until | string | RFC3339 end (exclusive) | none |
--user | string | user filter | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna audit export --gateway "$GW" --session fix-test-7k2 --out evidence.jsonlWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |