---
title: "ExportAuditLogs"
description: "Export agent audit logs as CSV"
canonical: "https://pgbeam.com/docs/go-sdk/agents/exportAuditLogs"
last-updated: "2026-09-14T19:37:21.000Z"
---

# ExportAuditLogs

> Export agent audit logs as CSV

URL: https://pgbeam.com/docs/go-sdk/agents/exportAuditLogs

Streams the project's agent audit entries as a CSV file, newest first, honoring the same credential, event, decision, source and date-range filters as the list endpoint. The full filtered set is streamed (no pagination); the result is suitable for spreadsheets, SIEM ingestion, and compliance archives.

## Usage

## Parameters

Parameter

Type

Required

Description

ctx

`context.Context`

Yes

Request context

projectID

`string`

Yes

Unique project identifier (prefixed, e.g. prj\_xxx).

params

`*pgbeam.ExportAuditLogsParams`

No

Query parameters

params.CredentialID

`string`

No

Filter to a single agent credential.

params.Event

`string`

No

Filter to a single event type (e.g. blocked, masked, query).

params.Decision

`pgbeam.AuditDecision`

No

Coarse outcome filter that groups events. `allow` = query, auto\_approved; `block` = blocked, budget\_exhausted, auth\_failed, credential\_expired, canary\_tripped, rejected, approval\_expired; `mask` = masked; `truncate` = truncated.

params.Source

`pgbeam.AuditSource`

No

Filter by statement origin (wire, mcp, rest, or control).

params.Start

`string`

No

Return entries at or after this timestamp (inclusive lower bound).

params.End

`string`

No

Return entries strictly older than this timestamp (cursor / upper bound).

## Response

`(*pgbeam.unknown, error)`: the result.

## Example

## Errors

Status

Description

400

The request was rejected. `code` is `INVALID_INPUT`, and `errors` names the offending fields when the failure was a validation one.

401

Missing or invalid authentication. `code` is `UNAUTHORIZED`.

403

The caller is authenticated but not allowed to perform this operation. `code` is `FORBIDDEN` when the caller's role is insufficient, and `PLAN_LIMIT_REACHED` when the organization's plan is what stands in the way. The two are answered differently, so branch on the code rather than the status.

404

The resource does not exist, or the caller is not entitled to know that it does. `code` is `NOT_FOUND`.

429

Rate limited. `code` is `RATE_LIMITED`.

500

The request failed for a reason on our side. `code` is `INTERNAL_ERROR`. Quote `request_id` when reporting it.