# AuditTrailConfigs Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/audittrailconfigs/

Schema for the `AuditTrailConfigs` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`config_id`** _(string)_
  The provider's own identifier for the trail or logging configuration.
- **`config_kind`** _(string)_
  Which audit mechanism this row describes.
  Allowed: `trail`, `event_data_store`, `diagnostic_setting`, `log_sink`, `other`
- **`scope_type`** _(string)_
  The level the configuration applies at.
  Allowed: `organisation`, `grouping`, `account`, `resource`, `unknown`
- **`scope_id`** _(string)_
  The provider reference for the scope.
- **`enabled`** _(boolean)_
  Whether the trail is actually recording. A trail can look complete (multi-region, encrypted, validated) yet be fully stopped, so this must be checked separately from the trail's description.
- **`is_logging`** _(boolean)_
  The provider's raw logging flag, kept separate from `enabled`. A value of true does not prove logs are arriving — a trail writing to a deleted destination can still report true.
- **`covers_all_regions`** _(boolean)_
  Whether the configuration captures every region rather than just one.
- **`covers_whole_organisation`** _(boolean)_
  Whether the configuration applies across the organisation rather than a single account.
- **`log_categories_enabled`** _(array<string>)_
  Which categories of event are recorded, as the provider names them.
- **`management_events_included`** _(boolean)_
  Whether control-plane events are recorded. Not the whole answer on its own — see excluded_management_event_sources.
- **`excluded_management_event_sources`** _(array<string>)_
  Management event sources excluded from the trail. Coverage is incomplete even when management_events_included is true, if sources appear here.
- **`data_access_logging_by_service`** _(array<object>)_
  Per-service data-plane logging coverage, as the selectors that produced the answer.
  - **`type`** _(string)_
    The resource type the selector matches.
  - **`values`** _(array<string>)_
    The selector values recorded for that type.
- **`data_event_selector_type`** _(string)_
  Which selector dialect produced data_access_logging_by_service. 'classic' lists resource types explicitly; 'advanced' is a predicate language that can't be fully evaluated offline.
  Allowed: `classic`, `advanced`, `none`, `unknown`
- **`data_access_inference_confidence`** _(string)_
  How confident Truto is in data_access_logging_by_service: exact, inferred, or unknown.
  Allowed: `exact`, `inferred`, `unknown`
- **`destination`** _(object)_
  Where the audit records are delivered.
  - **`id`** _(string)_
    The target's `id`.
- **`destination_type`** _(string)_
  What kind of destination that is, as the provider names it.
- **`tamper_evidence_enabled`** _(boolean)_
  Whether the trail is cryptographically protected against alteration. Distinct from deletion protection: preventing deletion does not prove records weren't altered.
- **`log_file_validation_enabled`** _(boolean)_
  The provider's own integrity validation flag, carried separately.
- **`encryption_key`** _(object)_
  The customer-managed key protecting the audit records. Absent means the provider's own key.
  - **`id`** _(string)_
    The target's `id`.

## Methods

- [GET /unified/cloud-infrastructure/audit_trail_configs](/docs/api-reference/unified-cloud-infrastructure-api/audittrailconfigs/list) — List Audit trail configs
