Skip to main content

Log Management API

Log Management API is available for Nexus Repository Cloud users. This set of endpoints allows us to query and download logs with paging and filtering, returning pre-signed URLs for each log file. These logs are stored in your tenant’s S3 bucket.

Endpoints

The request retrieves logs for a specific hour, organized by log type and date. The user requires the following permissions:

  • The built-in permission: nexus:logging:read

  • The built-in privilege: nx-logging-read

GET /service/rest/v1/logs/{type}/{year}/{month}/{day}/{hour}?page=1&size=50

Where,

  • type: must be one of AUDIT or REQUESTS. Note that type is case sensitive

  • year: integer between 2025 and the current year (inclusive)

  • month: integer between 1 and 12

  • day: integer between 1 and the number of days in the given month

  • hour: integer between 0 and 23

  • page: Optional. Defaults to 1; if missing, 0, or negative, set to default

  • size: Optional. Defaults to 20; if missing, 0, or negative, set to default

Example

GET /service/rest/v1/logs/AUDIT/2025/9/3/14?page=1&size=50
GET /service/rest/v1/logs/REQUESTS/2025/9/3/14?page=1&size=50

Access Window Validation

Each tenant is configured with a retention period that defines the number of days logs are available. This value is set through an environment variable.

If a request attempts to access logs older than the configured retention period, the system will respond with HTTP 403 (Forbidden).

If the variable is not set or contains a negative value, the retention period will default to 7 days.

Pre-signed URL Expiration

The expiration window for pre-signed URLs is controlled by the environment variable log_download_url_expiration_minutes.

  • If the variable is not set, set to 0, or set to a negative value, the expiration time defaults to 5 minutes.

  • If the variable is set to a positive value, the pre-signed URL will expire after the specified number of minutes.

The API that returns links to S3 logs generates pre-signed URLs. By default, these URLs remain valid for 5 minutes from the time they are generated.

Example Response

{
  "type": "audit",
  "year": 2025,
  "month": 9,
  "day": 3,
  "hour": 14,
  "items": [
    "https://s3.amazonaws.com/.../log1",
    "https://s3.amazonaws.com/.../log2"
  ],
  "page": 3,
  "totalCount": 1200
}