# Audit logs MCP tools

This page documents **4 tools** in the audit logs group. Return to the [complete MCP tool reference](/docs/developers/api/mcp/tools) to browse another group.

Select a tool to inspect its schemas and behavior. Schema links open the exact definition in GitHub.

### `getAuditLogEntry` — Get Audit Log Entry

Get an audit log entry by ID.

- **Input:** [`GetAuditLogEntryInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11202-L11209)
- **Output:** [`GetAuditLogEntryOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11211-L11217)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19223–L19234 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19223-L19234)

### `listAuditLogEntries` — List Audit Log Entries

List audit log entries for the organization. Audit log entries record write actions (create, update, delete) performed by users and API keys.

- **Input:** [`ListAuditLogEntriesInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11236-L11267)
- **Output:** [`ListAuditLogEntriesOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11269-L11280)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19235–L19246 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19235-L19246)

### `requestAuditLogExport` — Request Audit Log Export

Request an export of audit log entries for the organization within a time range. The export will be emailed as a CSV download link.

- **Input:** [`RequestAuditLogExportInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11282-L11301)
- **Output:** [`RequestAuditLogExportOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11303-L11310)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L19247–L19258 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19247-L19258)

### `requestSCIMEventExport` — Request SCIM Event Export

Request an export of SCIM events for the organization within a time range. The export will be emailed as a CSV download link.

- **Input:** [`RequestSCIMEventExportInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11312-L11331)
- **Output:** [`RequestSCIMEventExportOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11333-L11340)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L19259–L19270 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19259-L19270)
