honey audit tail
honey audit tail
Stream audit events in real time (like tail -f)
honey audit tail [flags]
Options
--action string Filter by action (exec, recipe_run, approval)
--actor string Filter by actor
--decision string Filter by decision (allow, deny, require_approval)
-h, --help help for tail
--raw Print raw JSON lines
--since string Only show events after this duration ago (e.g. 1h, 30m)
Options inherited from parent commands
--cache-dir string Override cache directory (default: XDG_CACHE_HOME/honey)
--cache-ttl duration Cache time-to-live (host discovery) (default 10m0s)
--config string Path to honey YAML (optional; also HONEY_CONFIG or default paths)
--debug-log string Path to write debug logs (disables debug logging if empty)
--no-cache Bypass read/write cache (host discovery)
--record-dir string Session recording directory for search (TUI), web, and cue-exec; overrides defaults.record_dir; default <directory of config.yaml>/records
--refresh Ignore cached entries and refresh (host discovery)
SEE ALSO
- honey audit - Inspect the audit log