Skip to main content
Tools Reference

Auvik Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Auvik Tools

auvik_ · 50 tools · Free 49 · Pro 1 Network monitoring, configuration backup and SaaS management. Authentication is HTTP Basic with your Auvik user name and that user's API key. Keys inherit the user's role, so a 401 means a revoked or regenerated key while a 403 means the role lacks that endpoint. The regional cluster is part of the instance address, us1 by default. Responses follow JSON:API, and paging uses literal bracketed parameters - page[first] with page[after] going forward, page[last] with page[before] going back - with both sizes capped at 1000 here because the vendor documents no maximum. Multi-client scoping is deliberately not uniform: a comma-separated tenants parameter is optional on inventory, alerts and statistics but required on all four SNMP poller reads, the two tenant-detail reads take a domain prefix instead, and the SaaS Management tools filter by client id and take no tenants parameter at all. Read-only apart from a single one-way alert dismissal.

All connector tools · Auvik setup guide

Auvik tool groups

General

ToolPlanAccessSummary
auvik_verify_credentialsFreeRead-onlyVerify that the configured Auvik user name and API key authenticate.

[Auvik] Verify that the configured Auvik user name and API key authenticate. This is Auvik's own purpose-built credential check — the cheapest authenticated call, with no parameters and no side effects — so it is the right first diagnostic when other Auvik tools start failing. Read the result alongside the failure you saw: a 401 elsewhere means the key itself is invalid or was regenerated, while a 403 elsewhere means the credential is fine and the Auvik user's ROLE lacks permission for that specific area (Auvik API keys inherit their user's role rather than carrying their own scopes). If this tool succeeds but another returns access-denied, the fix is a role change in Auvik, not a new key.

Tenants

ToolPlanAccessSummary
auvik_get_tenant_detailFreeRead-onlyGet one tenant's detail by tenant id (ids come from auvik_list_tenants).
auvik_list_tenant_detailsFreeRead-onlyList DETAIL for the tenants associated with your Auvik account — richer per-tenant information than auvik_list_tenants returns.
auvik_list_tenantsFreeRead-onlyList every Auvik tenant — multi-client and client — that the configured Auvik user can reach.

[Auvik] Get one tenant's detail by tenant id (ids come from auvik_list_tenants). This endpoint has no pagination.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik tenant id (from auvik_list_tenants).
tenantDomainPrefixstringnonullYour Auvik account's own domain prefix (subdomain). Optional here — StackJack falls back to the value saved with your Auvik credentials. This is your Auvik account subdomain, NOT the cluster region (not 'us1').

[Auvik] List DETAIL for the tenants associated with your Auvik account — richer per-tenant information than auvik_list_tenants returns. Use auvik_list_tenants when you only need ids to scope another call; use this when you need each tenant's attributes. This endpoint has no pagination.

ParamTypeRequiredDefaultDescription
availableTenantsbooleannonullSet true to return only tenants currently available to your account. Omit for all associated tenants.
tenantDomainPrefixstringnonullYour Auvik account's own domain prefix (subdomain). Optional here — StackJack falls back to the value saved with your Auvik credentials. This is your Auvik account subdomain, NOT the cluster region (not 'us1').

[Auvik] List every Auvik tenant — multi-client and client — that the configured Auvik user can reach. CALL THIS FIRST in any multi-client environment: the ids it returns are exactly what the `tenants` parameter on the other Auvik tools consumes, and Auvik REQUIRES that parameter on the four SNMP poller tools. Takes no parameters. Note that Auvik's SaaS Management tools use their own separate client ids from auvik_list_asm_clients, not these.

Devices

ToolPlanAccessSummary
auvik_get_device_detailFreeRead-onlyGet one device's discovery and management state by device id (from auvik_list_device_info) — per-protocol discovery status, managed/billable flag, and TrafficInsights state.
auvik_get_device_extended_detailFreeRead-onlyGet one device's extended hardware/software details by device id (from auvik_list_device_info).
auvik_get_device_infoFreeRead-onlyGet one device's core inventory attributes by device id (ids come from auvik_list_device_info).
auvik_get_device_lifecycleFreeRead-onlyGet one device's lifecycle milestones (end-of-sale, software and security maintenance, last support) by device id (from auvik_list_device_info).
auvik_get_device_warrantyFreeRead-onlyGet one device's warranty and service-contract coverage by device id (from auvik_list_device_info).
auvik_list_device_detailsFreeRead-onlyList device DISCOVERY and MANAGEMENT state — per-protocol credential/discovery status (SNMP, WMI, login, VMware), whether the device is billed as managed, and TrafficInsights forwarding state.
auvik_list_device_extended_detailsFreeRead-onlyList EXTENDED device details — the deeper hardware/software attributes Auvik collects beyond the basic inventory (per-type fields such as firmware/OS versions, chassis and stack members,…
auvik_list_device_infoFreeRead-onlyList discovered devices with their core inventory attributes (name, IP addresses, make/model, vendor, device type, online status, serial number, last-seen time).
auvik_list_device_lifecyclesFreeRead-onlyList device LIFECYCLE status — vendor end-of-sale, software-maintenance, security-maintenance, and last-support milestones per device.
auvik_list_device_warrantiesFreeRead-onlyList collected WARRANTY and support-contract coverage per device — coverage flags plus contract/expiry information Auvik gathered from the vendor.

[Auvik] Get one device's discovery and management state by device id (from auvik_list_device_info) — per-protocol discovery status, managed/billable flag, and TrafficInsights state. Use this to diagnose why Auvik is not collecting data for a specific device.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik device id (from auvik_list_device_info).

[Auvik] Get one device's extended hardware/software details by device id (from auvik_list_device_info). Unlike the list variant this does NOT need a device type — Auvik resolves the type from the id.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik device id (from auvik_list_device_info).

[Auvik] Get one device's core inventory attributes by device id (ids come from auvik_list_device_info). Returns the raw JSON:API document for that single device. Use auvik_get_device_detail for discovery/management state, auvik_get_device_extended_detail for hardware/software specifics, and auvik_read_device_statistics for time-series metrics.

ParamTypeRequiredDefaultDescription
fieldsDeviceDetailstringnonullComma-delimited subset of embedded detail attributes: discoveryStatus, components, connectedDevices, configurations, manageStatus, interfaces. REQUIRES include=deviceDetail.
idstringyesThe Auvik device id (from auvik_list_device_info).
includestringnonullSet to 'deviceDetail' to embed the device's detail object in the response's `included` array.
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik device id (from auvik_list_device_info).
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik device id (from auvik_list_device_info).

[Auvik] List device DISCOVERY and MANAGEMENT state — per-protocol credential/discovery status (SNMP, WMI, login, VMware), whether the device is billed as managed, and TrafficInsights forwarding state. This is the tool for auditing which devices Auvik can actually poll and why a device is missing data. For inventory attributes use auvik_list_device_info instead. Returns a raw JSON:API document; page forward with links.next as pageAfter.

ParamTypeRequiredDefaultDescription
discoveryLoginstringnonullFilter by login (SSH/Telnet) discovery status: disabled, determining, notSupported, notAuthorized, authorizing, authorized, or privileged.
discoverySNMPstringnonullFilter by SNMP discovery status: disabled, determining, notSupported, notAuthorized, authorizing, authorized, or privileged.
discoveryVMwarestringnonullFilter by VMware discovery status: disabled, determining, notSupported, notAuthorized, authorizing, authorized, or privileged.
discoveryWMIstringnonullFilter by WMI discovery status: disabled, determining, notSupported, notAuthorized, authorizing, authorized, or privileged.
manageStatusbooleannonullWhen true, returns only devices counted as managed (billable); when false, only unmanaged. Omit for both.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
trafficInsightsStatusstringnonullFilter by TrafficInsights status: notDetected, detected, notApproved, approved, linking, linkingFailed, or forwarding.

[Auvik] List EXTENDED device details — the deeper hardware/software attributes Auvik collects beyond the basic inventory (per-type fields such as firmware/OS versions, chassis and stack members, virtualization specifics). deviceType is REQUIRED by Auvik on this endpoint: extended attributes differ per device type, so one call returns one type at a time. Use auvik_list_device_info first to learn which types exist in the environment.

ParamTypeRequiredDefaultDescription
deviceTypestringyesREQUIRED. The single device type to return extended details for, e.g. switch, l3Switch, router, accessPoint, firewall, workstation, server, printer, hypervisor, virtualMachine, ups, camera, ipPhone, securityAppliance. Auvik rejects the request without it.
modifiedAfterstringnonullOnly devices modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
notSeenSincestringnonullOnly devices NOT seen since this ISO-8601 instant.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
stateKnownbooleannonullWhen true, only devices whose state Auvik knows with confidence; when false, only unknown-state devices.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

[Auvik] List discovered devices with their core inventory attributes (name, IP addresses, make/model, vendor, device type, online status, serial number, last-seen time). This is the primary device discovery tool — start here to find device ids for every other Auvik device, interface, configuration, and statistics tool. Returns a raw JSON:API document {data:[...], links:{next,prev}, meta:}; page forward by passing links.next's cursor as pageAfter. Set include=deviceDetail to embed each device's discovery/management detail object in the response's `included` array.

ParamTypeRequiredDefaultDescription
deviceTypestringnonullFilter by device type, e.g. switch, l3Switch, router, accessPoint, firewall, workstation, server, printer, hypervisor, virtualMachine, ups, camera, ipPhone, securityAppliance, subnet. Omit for all types.
fieldsDeviceDetailstringnonullComma-delimited subset of embedded detail attributes to return: discoveryStatus, components, connectedDevices, configurations, manageStatus, interfaces. REQUIRES include=deviceDetail — supplying this without include returns nothing extra.
includestringnonullSet to 'deviceDetail' to embed each device's detail object in the response's `included` array. Omit to return device info only.
makeModelstringnonullFilter by make and model string as Auvik discovered it (e.g. 'Cisco Catalyst 2960'). Omit for all models.
modifiedAfterstringnonullOnly devices modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ). Use for incremental syncs.
networksstringnonullComma-delimited network ids — returns only devices attached to those networks (ids from auvik_list_network_info). Omit for all networks.
notSeenSincestringnonullOnly devices NOT seen since this ISO-8601 instant — useful for finding stale or decommissioned hardware.
onlineStatusstringnonullFilter by current online status: online, offline, unreachable, testing, unknown, dormant, notPresent, or lowerLayerDown. Omit for any status.
pageAfterstringnonullOpaque forward cursor — pass the cursor from the previous response's links.next. Omit for the first page.
pageBeforestringnonullOpaque backward cursor — pass the cursor from the previous response's links.prev. Pairs with pageLast.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000). Supplying this switches the request to backward paging and overrides pageFirst.
stateKnownbooleannonullWhen true, restricts results to devices with RECENTLY UPDATED data, which Auvik documents as giving more consistent results. Use it when a sweep must not mix in devices whose data is stale. Omit for all devices.
tenantsstringnonullComma-delimited Auvik tenant (client / multi-client) ids to scope the request — get them from auvik_list_tenants. Omit to span every tenant your Auvik user can see.
vendorNamestringnonullFilter by discovered vendor name (e.g. 'Cisco', 'Ubiquiti'). Omit for all vendors.

[Auvik] List device LIFECYCLE status — vendor end-of-sale, software-maintenance, security-maintenance, and last-support milestones per device. This is the hardware-refresh planning tool: filter by 'expired' on any axis to build a replacement list. Every status filter accepts covered, available, expired, securityOnly, unpublished, or empty.

ParamTypeRequiredDefaultDescription
lastSupportStatusstringnonullFilter by last-support (end-of-support) status: covered, available, expired, securityOnly, unpublished, or empty.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
salesAvailabilitystringnonullFilter by sales availability (end-of-sale) status: covered, available, expired, securityOnly, unpublished, or empty.
securitySoftwareMaintenanceStatusstringnonullFilter by security-software maintenance status: covered, available, expired, securityOnly, unpublished, or empty.
softwareMaintenanceStatusstringnonullFilter by software maintenance status: covered, available, expired, securityOnly, unpublished, or empty.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

[Auvik] List collected WARRANTY and support-contract coverage per device — coverage flags plus contract/expiry information Auvik gathered from the vendor. Use it to find hardware that has fallen out of warranty or off a service contract. Pair with auvik_list_device_lifecycles for end-of-sale / end-of-support status.

ParamTypeRequiredDefaultDescription
coveredUnderServicebooleannonullWhen true, only devices covered under a service contract; when false, only devices without one. Omit for both.
coveredUnderWarrantybooleannonullWhen true, only devices currently covered under warranty; when false, only devices NOT covered — the usual way to find at-risk hardware. Omit for both.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Networks

ToolPlanAccessSummary
auvik_get_network_detailFreeRead-onlyGet one network's scanning and collector configuration by network id (from auvik_list_network_info) — scope, primary and secondary collectors, collector selection, and excluded IP addresses.
auvik_get_network_infoFreeRead-onlyGet one network's core attributes by network id (ids come from auvik_list_network_info).
auvik_list_network_detailsFreeRead-onlyList network DETAIL — the scanning and collector configuration behind each discovered network: public vs private scope, which collector polls it (primary and secondary), how the collector was…
auvik_list_network_infoFreeRead-onlyList the networks Auvik discovered, with their core attributes (network name, address range, network type, scan status, description).
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik network id (from auvik_list_network_info).

[Auvik] Get one network's core attributes by network id (ids come from auvik_list_network_info). Use auvik_get_network_detail for its collector assignment and scope instead.

ParamTypeRequiredDefaultDescription
fieldsNetworkDetailstringnonullComma-delimited subset of embedded detail attributes: scope, primaryCollector, secondaryCollectors, collectorSelection, excludedIpAddresses. REQUIRES include=networkDetail.
idstringyesThe Auvik network id (from auvik_list_network_info).
includestringnonullSet to 'networkDetail' to embed the network's detail object in the response's `included` array.

[Auvik] List network DETAIL — the scanning and collector configuration behind each discovered network: public vs private scope, which collector polls it (primary and secondary), how the collector was selected, and any excluded IP addresses. This is the tool for auditing scan coverage and for finding networks Auvik is not allowed to scan. For addressing and network names use auvik_list_network_info instead.

ParamTypeRequiredDefaultDescription
devicesstringnonullComma-delimited device ids — returns only networks those devices are attached to (from auvik_list_device_info).
modifiedAfterstringnonullOnly networks modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
networkTypestringnonullFilter by network type: routed, vlan, wifi, loopback, network, layer2, or internet.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
scanStatusstringnonullFilter by scan status. A STRING enum, not a boolean — accepted values are the literal strings 'true', 'false', 'notAllowed', and 'unknown'.
scopestringnonullFilter by address scope: private or public. Useful for separating internal ranges from internet-facing ones.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

[Auvik] List the networks Auvik discovered, with their core attributes (network name, address range, network type, scan status, description). Use this to map a client's addressing and to get network ids for auvik_list_device_info's networks filter. Returns a raw JSON:API document {data:[...], links:{next,prev}, meta:}; page forward by passing links.next's cursor as pageAfter. Set include=networkDetail to embed each network's collector/scope detail object in the response's `included` array.

ParamTypeRequiredDefaultDescription
devicesstringnonullComma-delimited device ids — returns only networks those devices are attached to (ids from auvik_list_device_info). Omit for all networks.
fieldsNetworkDetailstringnonullComma-delimited subset of embedded detail attributes to return: scope, primaryCollector, secondaryCollectors, collectorSelection, excludedIpAddresses. REQUIRES include=networkDetail — supplying this without include returns nothing extra.
includestringnonullSet to 'networkDetail' to embed each network's detail object in the response's `included` array. Omit to return network info only.
modifiedAfterstringnonullOnly networks modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ). Use for incremental syncs.
networkTypestringnonullFilter by network type: routed, vlan, wifi, loopback, network, layer2, or internet. Omit for all types.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
scanStatusstringnonullFilter by scan status. This is a STRING enum, not a boolean — the accepted values are the literal strings 'true', 'false', 'notAllowed', and 'unknown'. Omit for any status.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Interfaces

ToolPlanAccessSummary
auvik_get_interface_infoFreeRead-onlyGet one interface's attributes by interface id (ids come from auvik_list_interface_info).
auvik_list_interface_infoFreeRead-onlyList the interfaces Auvik discovered on client devices — interface name and type, parent device, administrative state, operational status, addressing, and speed.

[Auvik] Get one interface's attributes by interface id (ids come from auvik_list_interface_info). For that interface's bandwidth, utilization or packet-loss history use auvik_read_interface_statistics.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik interface id (from auvik_list_interface_info).

[Auvik] List the interfaces Auvik discovered on client devices — interface name and type, parent device, administrative state, operational status, addressing, and speed. Use it to find which ports are down, which are administratively disabled, and to get interface ids for auvik_read_interface_statistics (bandwidth, utilization, packet loss). Returns a raw JSON:API document; page forward with links.next as pageAfter.

ParamTypeRequiredDefaultDescription
adminStatusbooleannonullFilter by administrative state: true = admin-enabled, false = admin-disabled. Omit for both. (This one IS a real boolean, unlike the network scanStatus filter.)
interfaceTypestringnonullFilter by interface type. Legal values: ethernet, wifi, bluetooth, cdma, coax, cpu, distributedVirtualSwitch, firewire, gsm, ieee8023AdLag, inferredWired, inferredWireless, interface, linkAggregation, loopback, modem, wimax, optical, other, parallel, ppp, radiomac, rs232, tunnel, unknown, usb, virtualBridge, virtualNic, virtualSwitch, vlan. Omit for all types.
modifiedAfterstringnonullOnly interfaces modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
operationalStatusstringnonullFilter by operational status: online, offline, unreachable, testing, unknown, dormant, notPresent, or lowerLayerDown. Combine with adminStatus=true to find ports that should be up but aren't.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
parentDevicestringnonullReturn only interfaces belonging to this device id (from auvik_list_device_info). The usual way to enumerate one switch's ports.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Components

ToolPlanAccessSummary
auvik_get_component_infoFreeRead-onlyGet one component's attributes and current health status by component id (ids come from auvik_list_component_info).
auvik_list_component_infoFreeRead-onlyList device COMPONENTS — the sub-parts Auvik monitors inside each device: CPUs and cores, disks, fans, memory, power supplies, and system boards, each with its current health status.

[Auvik] Get one component's attributes and current health status by component id (ids come from auvik_list_component_info). For that component's metric history use auvik_read_component_statistics.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik component id (from auvik_list_component_info).

[Auvik] List device COMPONENTS — the sub-parts Auvik monitors inside each device: CPUs and cores, disks, fans, memory, power supplies, and system boards, each with its current health status. Filtering currentStatus to failed or degraded is the hardware-fault triage path: it surfaces dying fans, failed power supplies and full disks across the whole fleet in one call. Component ids from here feed auvik_read_component_statistics for temperature and utilization history.

ParamTypeRequiredDefaultDescription
currentStatusstringnonullFilter by component health: ok, degraded, or failed. Use failed or degraded to build a hardware-fault list.
deviceIdstringnonullReturn only components belonging to this device id (from auvik_list_device_info).
deviceNamestringnonullReturn only components whose parent device name matches this value. Use deviceId when you have the id — it is exact.
modifiedAfterstringnonullOnly components modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Entity Notes & Audits

ToolPlanAccessSummary
auvik_get_entity_auditFreeRead-onlyGet one entity audit entry by audit id (ids come from auvik_list_entity_audits) — the session's user, category, status, target entity and timing.
auvik_get_entity_noteFreeRead-onlyGet one entity note by note id (ids come from auvik_list_entity_notes), including its full text and the entity it annotates.
auvik_list_entity_auditsFreeRead-onlyList the entity AUDIT trail — the record of remote-access sessions run against client entities through Auvik (tunnels, terminal sessions, remote browser sessions), with the user who initiated each…
auvik_list_entity_notesFreeRead-onlyList the operator-written NOTES attached to entities — devices, networks and interfaces — with their text, the entity they annotate, who last edited them, and when.
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik entity-audit id (from auvik_list_entity_audits).
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik entity-note id (from auvik_list_entity_notes).

[Auvik] List the entity AUDIT trail — the record of remote-access sessions run against client entities through Auvik (tunnels, terminal sessions, remote browser sessions), with the user who initiated each one, its outcome, and when. This is the who-touched-what surface: use it to answer access-review questions or to correlate a change with the session that made it. Distinct from auvik_list_entity_notes, which holds written annotations rather than access events.

ParamTypeRequiredDefaultDescription
categorystringnonullFilter by session category: unknown, tunnel, terminal, or remoteBrowser.
modifiedAfterstringnonullOnly audit entries modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
statusstringnonullFilter by session outcome: unknown, initiated, created, closed, or failed. Filter to failed to find access attempts that did not succeed.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
userstringnonullReturn only audit entries for sessions initiated by this Auvik user.

[Auvik] List the operator-written NOTES attached to entities — devices, networks and interfaces — with their text, the entity they annotate, who last edited them, and when. This is the human context Auvik holds about a client's infrastructure: why a device is configured a way, what a network is for, known quirks. Read it before drawing conclusions from telemetry alone.

ParamTypeRequiredDefaultDescription
entityIdstringnonullReturn only notes attached to this entity id (a device, network or interface id).
entityNamestringnonullReturn only notes whose annotated entity's name matches this value. Use entityId when you have the id — it is exact.
entityTypestringnonullFilter by the kind of entity the note is attached to: root, device, network, or interface.
lastModifiedBystringnonullReturn only notes last edited by this Auvik user.
modifiedAfterstringnonullOnly notes modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Configurations

ToolPlanAccessSummary
auvik_get_configurationFreeRead-onlyGet one configuration capture by id (ids come from auvik_list_configurations), including the full configuration TEXT as Auvik stored it.
auvik_list_configurationsFreeRead-onlyList the device configuration BACKUPS Auvik has captured — one entry per capture, with its device, backup time, and whether it is the running or a stored configuration.

[Auvik] Get one configuration capture by id (ids come from auvik_list_configurations), including the full configuration TEXT as Auvik stored it. Use this to diff two captures or to inspect exactly what was running on a device at a point in time. Configuration text can be long — fetch a specific id rather than looping over a whole client's history.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik configuration capture id (from auvik_list_configurations).

[Auvik] List the device configuration BACKUPS Auvik has captured — one entry per capture, with its device, backup time, and whether it is the running or a stored configuration. Use it to confirm a device is actually being backed up, to find when its config last changed, or to locate the capture immediately before an outage. This returns capture metadata; call auvik_get_configuration with an id to read the configuration text itself.

ParamTypeRequiredDefaultDescription
backupTimeAfterstringnonullOnly captures taken after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
backupTimeBeforestringnonullOnly captures taken before this ISO-8601 instant. Combine with backupTimeAfter to window a change.
deviceIdstringnonullReturn only captures for this device id (from auvik_list_device_info).
isRunningbooleannonulltrue = only configurations that are CURRENTLY RUNNING; false = only configurations that are not currently running (superseded captures). Omit for both.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Alerts

ToolPlanAccessSummary
auvik_dismiss_alertProDestructiveDismiss a single Auvik alert.
auvik_get_alertFreeRead-onlyGet one alert in full by alert id (ids come from auvik_list_alerts) — its severity, status, triggering entity, detection and resolution times, and any related alert.
auvik_list_alertsFreeRead-onlySearch Auvik ALERT HISTORY — the alert events the collectors have raised, with severity, current status, the entity that triggered them, detection time, and whether they were dismissed or dispatched.

[Auvik] Dismiss a single Auvik alert. IRREVERSIBLE: Auvik exposes no un-dismiss operation, so once an alert is dismissed through the API it cannot be restored to the open queue from here — an operator would have to work with it in the Auvik console. This is the only write operation the Auvik API offers. Get the alert id from auvik_list_alerts, and read the alert first (auvik_get_alert) if there is any doubt about whether it is still relevant.

ParamTypeRequiredDefaultDescription
idstringyesThe Auvik alert id to dismiss (from auvik_list_alerts). This cannot be undone.
ParamTypeRequiredDefaultDescription
idstringyesThe Auvik alert id (from auvik_list_alerts).

[Auvik] Search Auvik ALERT HISTORY — the alert events the collectors have raised, with severity, current status, the entity that triggered them, detection time, and whether they were dismissed or dispatched. This is the triage entry point: filter severity to emergency or critical with status=created and dismissed=false to find what still needs attention. Returns a raw JSON:API document; page forward with links.next as pageAfter.

ParamTypeRequiredDefaultDescription
alertDefinitionIdstringnonullFilter to alerts raised by a specific alert definition id.
alertSpecificationIdstringnonullDEPRECATED by Auvik — the vendor's own guidance is to use alertDefinitionId instead. Kept for parity with the API; prefer alertDefinitionId for new queries.
detectedTimeAfterstringnonullOnly alerts detected after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
detectedTimeBeforestringnonullOnly alerts detected before this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ). Combine with detectedTimeAfter to window an incident.
dismissedbooleannonullFilter by dismissal: false = still open in the console, true = already dismissed. Omit for both.
dispatchedbooleannonullFilter by whether Auvik dispatched a notification for the alert.
entityIdstringnonullFilter to alerts that fired on this entity id — a device, network or interface id.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
severitystringnonullFilter by severity: unknown, emergency, critical, warning, or info. Combine emergency/critical with dismissed=false for an actionable queue.
statusstringnonullFilter by alert status: created, resolved, paused, or unpaused.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

Usage & Billing

ToolPlanAccessSummary
auvik_read_client_usageFreeRead-onlyRead a client's billable USAGE summary for a date window — and, for a multi-client, its children's too.
auvik_read_device_usageFreeRead-onlyRead one device's billable usage over a date window.

[Auvik] Read a client's billable USAGE summary for a date window — and, for a multi-client, its children's too. This is the data Auvik invoices from, so it is the surface for reconciling an Auvik bill against what you believe you are managing, and for spotting a client whose billable device count jumped. Both dates are required. This endpoint has no pagination. For a single device's usage use auvik_read_device_usage.

ParamTypeRequiredDefaultDescription
fromDatestringyesREQUIRED. Start of the billing window. Auvik's examples for this endpoint are DATE-ONLY (YYYY-MM-DD, e.g. 2019-06-01) rather than full timestamps — prefer that form here.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruDatestringyesREQUIRED. End of the billing window, date-only (YYYY-MM-DD, e.g. 2019-06-30) to match Auvik's examples for this endpoint.

[Auvik] Read one device's billable usage over a date window. Use it to answer why a specific device is (or is not) counted as billable in a period — the per-device drill-down behind auvik_read_client_usage's totals. Both dates are required. This endpoint takes no tenant scope and has no pagination.

ParamTypeRequiredDefaultDescription
fromDatestringyesREQUIRED. Start of the billing window. Auvik's examples for this endpoint are DATE-ONLY (YYYY-MM-DD, e.g. 2019-06-01) rather than full timestamps — prefer that form here.
idstringyesThe Auvik device id (from auvik_list_device_info).
thruDatestringyesREQUIRED. End of the billing window, date-only (YYYY-MM-DD, e.g. 2019-06-30) to match Auvik's examples for this endpoint.

Statistics

ToolPlanAccessSummary
auvik_read_component_statisticsFreeRead-onlyRead historical COMPONENT metrics as a time series — the inside-the-box telemetry for CPUs, disks, fans, memory, power supplies and system boards.
auvik_read_device_availability_statisticsFreeRead-onlyRead historical device UPTIME or OUTAGE statistics as a time series.
auvik_read_device_statisticsFreeRead-onlyRead historical DEVICE performance metrics as a time series.
auvik_read_interface_statisticsFreeRead-onlyRead historical INTERFACE metrics as a time series — throughput, utilization, and error/loss counters per port.
auvik_read_oid_statisticsFreeRead-onlyRead the CURRENT value of numeric SNMP pollers (device monitors).
auvik_read_service_statisticsFreeRead-onlyRead historical CLOUD PING CHECK statistics — the reachability probes Auvik runs against monitored services.

[Auvik] Read historical COMPONENT metrics as a time series — the inside-the-box telemetry for CPUs, disks, fans, memory, power supplies and system boards. This call needs TWO path values: which kind of component (componentType) and which metric (statId). Not every metric is meaningful for every component kind — temperature suits fan and systemBoard, utilization suits cpu, disk and memory, speed suits fan. Pair with auvik_list_component_info, which reports each component's current health and supplies componentId.

ParamTypeRequiredDefaultDescription
componentIdstringnonullRestrict to a single component id (from auvik_list_component_info).
componentTypestringyesREQUIRED. The kind of component: cpu, cpuCore, disk, fan, memory, powerSupply, or systemBoard.
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
parentDevicestringnonullRestrict to every matching component on this device id (from auvik_list_device_info).
statIdstringyesREQUIRED. The metric to read: capacity, counters, idle, latency, power, queueLatency, rate, readiness, ready, speed, swap, swapRate, temperature, totalLatency, or utilization. Must be a metric the chosen componentType actually reports.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

[Auvik] Read historical device UPTIME or OUTAGE statistics as a time series. This is the availability/SLA surface: statId=uptime gives the up-percentage per interval, statId=outage gives the outage events. Use it for uptime reporting and for confirming whether an incident was a real outage or a polling gap.

ParamTypeRequiredDefaultDescription
deviceIdstringnonullRestrict to a single device id (from auvik_list_device_info).
deviceTypestringnonullRestrict to one device type, e.g. switch, l3Switch, router, accessPoint, firewall, server, hypervisor, ups.
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
omitUndiscoveredbooleannonullWhen true, omits availability data for the TIME PERIODS before each device was first discovered (compare firstDiscoveredDateTime). This trims the leading pre-discovery window out of each device's series — it does NOT filter which devices are returned. Use it so a recently-onboarded device does not read as having been down before Auvik could see it.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
statIdstringyesREQUIRED. The statistic to read: uptime or outage.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

[Auvik] Read historical DEVICE performance metrics as a time series. Pick one statistic per call via statId. Use it to answer capacity and saturation questions — is this switch's CPU pinned, is memory climbing, is a link saturated. For uptime and outage history use auvik_read_device_availability_statistics instead.

ParamTypeRequiredDefaultDescription
deviceIdstringnonullRestrict to a single device id (from auvik_list_device_info). The cheapest way to read one device's history.
deviceTypestringnonullRestrict to one device type, e.g. switch, l3Switch, router, accessPoint, firewall, workstation, server, printer, hypervisor, virtualMachine, ups.
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
statIdstringyesREQUIRED. The statistic to read: bandwidth, cpuUtilization, memoryUtilization, storageUtilization, packetUnicast, packetMulticast, or packetBroadcast.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

[Auvik] Read historical INTERFACE metrics as a time series — throughput, utilization, and error/loss counters per port. This is where link-saturation and packet-loss investigations happen: statId=utilization for saturation, packetLoss or packetDiscard for quality problems. Get interface ids from auvik_list_interface_info, or pass parentDevice to cover every port on one device.

ParamTypeRequiredDefaultDescription
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
interfaceIdstringnonullRestrict to a single interface id (from auvik_list_interface_info).
interfaceTypestringnonullRestrict to one interface type. Legal values: ethernet, wifi, bluetooth, cdma, coax, cpu, distributedVirtualSwitch, firewire, gsm, ieee8023AdLag, inferredWired, inferredWireless, interface, linkAggregation, loopback, modem, wimax, optical, other, parallel, ppp, radiomac, rs232, tunnel, unknown, usb, virtualBridge, virtualNic, virtualSwitch, vlan. Omit for all types.
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
parentDevicestringnonullRestrict to every interface on this device id (from auvik_list_device_info) — the usual way to review one switch's ports.
statIdstringyesREQUIRED. The statistic to read: bandwidth, utilization, packetLoss, packetDiscard, packetMulticast, packetUnicast, or packetBroadcast.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

[Auvik] Read the CURRENT value of numeric SNMP pollers (device monitors). Unlike every other Auvik statistics tool this is a point-in-time read, NOT a time series — it takes no time range and no interval, and returns each poller's latest value. For the historical values of a numeric poller use auvik_read_snmp_poller_int_history; for string pollers use auvik_read_snmp_poller_string_history. Poller configuration itself lives in auvik_list_snmp_poller_settings.

ParamTypeRequiredDefaultDescription
deviceIdstringnonullRestrict to a single device id (from auvik_list_device_info).
deviceTypestringnonullRestrict to one device type, e.g. switch, l3Switch, router, accessPoint, firewall, server, ups.
oidstringnonullRestrict to a specific SNMP OID string (e.g. 1.3.6.1.2.1.1.3). Omit to return every polled OID in scope.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
statIdstringno"deviceMonitor"REQUIRED. The statistic id; deviceMonitor is currently the only value Auvik accepts.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.

[Auvik] Read historical CLOUD PING CHECK statistics — the reachability probes Auvik runs against monitored services. statId=pingTime gives round-trip latency, statId=pingPacket gives packet-level results. Use it to distinguish a client-side problem from an upstream service being slow or unreachable.

ParamTypeRequiredDefaultDescription
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
serviceIdstringnonullRestrict to a single monitored service id. Omit to span every monitored service in scope.
statIdstringyesREQUIRED. The statistic to read: pingTime or pingPacket.
tenantsstringnonullComma-delimited Auvik tenant ids to scope the request (from auvik_list_tenants). Omit to span every visible tenant.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

SNMP Pollers

ToolPlanAccessSummary
auvik_get_snmp_poller_settingFreeRead-onlyGet one SNMP poller setting by its id (ids come from auvik_list_snmp_poller_settings) — its name, OID, value type and usage.
auvik_list_snmp_poller_setting_devicesFreeRead-onlyList the DEVICES a given SNMP poller setting applies to, with each device's online status and identifying attributes.
auvik_list_snmp_poller_settingsFreeRead-onlyList the custom SNMP POLLER SETTINGS configured in Auvik — each one's name, the OID it polls, whether it is a string or numeric poller, and what it is used as.

[Auvik] Get one SNMP poller setting by its id (ids come from auvik_list_snmp_poller_settings) — its name, OID, value type and usage. Unlike the list variants in this group, this endpoint takes no tenant scope.

ParamTypeRequiredDefaultDescription
snmpPollerSettingIdstringyesThe Auvik SNMP poller setting id (from auvik_list_snmp_poller_settings).

[Auvik] List the DEVICES a given SNMP poller setting applies to, with each device's online status and identifying attributes. Use it to confirm a custom poller is actually reaching the hardware you expect, or to find devices where it should apply but doesn't. Auvik REQUIRES an explicit tenant scope on this endpoint.

ParamTypeRequiredDefaultDescription
deviceTypestringnonullRestrict to one device type, e.g. switch, l3Switch, router, firewall, ups.
makeModelstringnonullRestrict to devices of this make and model.
modifiedAfterstringnonullOnly devices modified after this ISO-8601 instant (YYYY-MM-DDTHH:MM:SS.sssZ).
notSeenSincestringnonullOnly devices NOT seen since this ISO-8601 instant — finds stale hardware still matched by the poller.
onlineStatusstringnonullFilter by device online status: online, offline, unreachable, testing, unknown, dormant, notPresent, or lowerLayerDown.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
snmpPollerSettingIdstringyesThe Auvik SNMP poller setting id (from auvik_list_snmp_poller_settings).
tenantsstringyesREQUIRED. Comma-delimited Auvik tenant ids (from auvik_list_tenants). Auvik rejects this endpoint without it.
vendorNamestringnonullRestrict to devices from this vendor.

[Auvik] List the custom SNMP POLLER SETTINGS configured in Auvik — each one's name, the OID it polls, whether it is a string or numeric poller, and what it is used as. Start here when you need to know what bespoke SNMP data a client's Auvik is collecting. The type value decides which history tool applies afterwards: numeric pollers go to auvik_read_snmp_poller_int_history, string pollers to auvik_read_snmp_poller_string_history. Auvik REQUIRES an explicit tenant scope on this endpoint.

ParamTypeRequiredDefaultDescription
deviceIdstringnonullReturn only pollers applied to this device id (from auvik_list_device_info).
deviceTypestringnonullRestrict to pollers targeting one device type, e.g. switch, l3Switch, router, firewall, ups.
makeModelstringnonullRestrict to pollers targeting devices of this make and model.
namestringnonullFilter by the poller setting's display name as configured in Auvik.
oidstringnonullFilter by the SNMP OID string the poller reads (e.g. 1.3.6.1.2.1.1.3).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
tenantsstringyesREQUIRED. Comma-delimited Auvik tenant ids (from auvik_list_tenants). Auvik rejects this endpoint without it.
typestringnonullFilter by poller value type: string or numeric. This decides which history tool can read its values.
useAsstringnonullFilter by how the poller's value is used: serialNo or poller.
vendorNamestringnonullRestrict to pollers targeting devices from this vendor.

SNMP Poller History

ToolPlanAccessSummary
auvik_read_snmp_poller_int_historyFreeRead-onlyRead the historical values of NUMERIC SNMP pollers over a time range, aggregated by interval.
auvik_read_snmp_poller_string_historyFreeRead-onlyRead the historical values of STRING SNMP pollers over a time range.

[Auvik] Read the historical values of NUMERIC SNMP pollers over a time range, aggregated by interval. Use this for pollers whose type is 'numeric' in auvik_list_snmp_poller_settings — temperatures, counters, custom gauges — to trend a value over time. For the current value only, auvik_read_oid_statistics is cheaper; for string pollers use auvik_read_snmp_poller_string_history (which takes no interval). Auvik REQUIRES an explicit tenant scope.

ParamTypeRequiredDefaultDescription
deviceIdstringnonullRestrict to a single device id (from auvik_list_device_info).
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
intervalstringyesREQUIRED. Aggregation interval: minute, hour, or day. Narrow intervals over long ranges return very large result sets — widen the interval or shorten the range.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
snmpPollerSettingIdstringnonullComma-delimited list of SNMP poller setting ids to read (from auvik_list_snmp_poller_settings). Accepts multiple ids, not just one. These are Auvik's internal poller setting ids.
tenantsstringyesREQUIRED. Comma-delimited Auvik tenant ids (from auvik_list_tenants). Auvik rejects this endpoint without it.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

[Auvik] Read the historical values of STRING SNMP pollers over a time range. Use this for pollers whose type is 'string' in auvik_list_snmp_poller_settings — firmware versions, serial numbers, textual status fields — to see when a value changed. Note this endpoint takes NO interval (string values are not aggregated); for numeric pollers use auvik_read_snmp_poller_int_history instead. Auvik REQUIRES an explicit tenant scope.

ParamTypeRequiredDefaultDescription
compactbooleannonullCompact view shows ONLY the points where the value changed, rather than every sample. IMPORTANT: when compact is false (or omitted), Auvik limits the time range to a MAXIMUM OF 24 HOURS — so set compact=true for any window wider than a day, or the request is rejected.
deviceIdstringnonullRestrict to a single device id (from auvik_list_device_info).
fromTimestringyesREQUIRED. Start of the time range, ISO-8601 (YYYY-MM-DDTHH:MM:SS.sssZ).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
snmpPollerSettingIdstringnonullComma-delimited list of SNMP poller setting ids to read (from auvik_list_snmp_poller_settings). Accepts multiple ids, not just one. These are Auvik's internal poller setting ids.
tenantsstringyesREQUIRED. Comma-delimited Auvik tenant ids (from auvik_list_tenants). Auvik rejects this endpoint without it.
thruTimestringnonullEnd of the time range, ISO-8601. Omit to read through now.

SaaS Management

ToolPlanAccessSummary
auvik_list_asm_applicationsFreeRead-onlyList the SaaS APPLICATIONS Auvik discovered in use at a client — what is actually being signed into, when it first appeared, and (via include) its publisher, contracts, users, access data, and known…
auvik_list_asm_clientsFreeRead-onlyList the clients covered by Auvik SaaS Management.
auvik_list_asm_licensesFreeRead-onlyList the LICENCES assigned within one SaaS application at a client — who holds which licence type and when they last signed in.
auvik_list_asm_security_logsFreeRead-onlyList SaaS SECURITY EVENTS Auvik recorded for a client — the security-relevant activity across their SaaS applications.
auvik_list_asm_tagsFreeRead-onlyList the TAGS applied within a client's Auvik SaaS Management data — how the client's applications have been categorized (sanctioned, under review, and so on).
auvik_list_asm_usersFreeRead-onlyList the SaaS USERS Auvik discovered at a client — the people whose accounts show up across the client's SaaS applications.

[Auvik] List the SaaS APPLICATIONS Auvik discovered in use at a client — what is actually being signed into, when it first appeared, and (via include) its publisher, contracts, users, access data, and known breaches. This is the shadow-IT discovery surface: filter dateAddedAfter to see what appeared recently. Application ids from here are required by auvik_list_asm_licenses. Requires the Auvik SaaS Management product; an access-denied response usually means the account is not licensed for it.

ParamTypeRequiredDefaultDescription
clientIdstringyesREQUIRED. The ASM client id — get it from auvik_list_asm_clients (NOT from auvik_list_tenants; ASM uses its own client ids).
dateAddedAfterstringnonullReturn only applications added after this date — the shadow-IT 'what appeared recently' filter. Same date-format caveat as dateAddedBefore.
dateAddedBeforestringnonullReturn only applications added before this date. Vendor examples use MM/DD/YYYY HH:MM:SS (e.g. 10/10/2024 05:43:26) while the spec's general note says ISO-8601 — if one is rejected, try the other.
includestringnonullComma-delimited extras to embed: all, breaches, users, contracts, publisher, accessData (e.g. 'users,contracts'). Omit for the application records alone.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
queryDatestringnonullLower bound on BREACH age: returns the associated breaches added after this date. This is NOT an as-of snapshot and does not filter which applications come back. Pair it with include=breaches (or include=all) so the breaches are actually present in the response.
userLastUsedAfterstringnonullLower bound on the ASSOCIATED USERS returned with each application. Auvik names this parameter user_lastUsedAfter but documents it as 'associated users ADDED after this date' — the vendor's name and description disagree, so treat the exact semantics as unverified and prefer a wide bound.
userLastUsedBeforestringnonullUpper bound on the associated users returned with each application. Same vendor name-vs-description disagreement as userLastUsedAfter (the name implies last-used, the description says added) — treat the exact semantics as unverified.

[Auvik] List the clients covered by Auvik SaaS Management. CALL THIS FIRST for anything SaaS-related: the client ids it returns are what every other ASM tool's clientId parameter requires, and they are NOT the same ids as auvik_list_tenants returns. Set include=totals for per-client roll-up counts. Requires the separately-licensed Auvik SaaS Management product — an access-denied response here usually means the account is not licensed for it, and the rest of the Auvik connector is unaffected.

ParamTypeRequiredDefaultDescription
includestringnonullSet to 'totals' to include per-client roll-up counts alongside each client.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
queryDatestringnonullLower bound on BREACH age: only breaches added after this date are counted. This is NOT an as-of snapshot. Auvik documents it as only useful together with include=totals, since it narrows the breach counts that appear in the roll-up. Vendor examples use MM/DD/YYYY HH:MM:SS (e.g. 10/10/2024 05:43:26) while the spec's general note says ISO-8601 — if one is rejected, try the other.

[Auvik] List the LICENCES assigned within one SaaS application at a client — who holds which licence type and when they last signed in. Set underutilizedOnly=true for the licence-reclamation path: it surfaces seats that are paid for but barely used, which is usually the fastest SaaS cost saving available. lastLoginBefore finds dormant accounts. Needs BOTH a client id and an application id. Requires the Auvik SaaS Management product; an access-denied response usually means the account is not licensed for it.

ParamTypeRequiredDefaultDescription
applicationIdstringyesREQUIRED. The application id whose licences to list (from auvik_list_asm_applications).
clientIdstringyesREQUIRED. The ASM client id — get it from auvik_list_asm_clients (NOT from auvik_list_tenants; ASM uses its own client ids).
emailstringnonullRestrict to the licence held by this user's email address.
lastLoginBeforestringnonullReturns only users whose last login was before this date OR who have NO last-login time at all — so never-signed-in seats are included, not excluded. That makes it the dormant-account filter. Vendor examples use MM/DD/YYYY HH:MM:SS (e.g. 10/10/2024 05:43:26) while the spec's general note says ISO-8601 — if one is rejected, try the other.
licenseTypestringnonullRestrict to one licence type as the vendor names it (e.g. a specific plan or SKU).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
underutilizedOnlybooleannonullFilters to users Auvik has flagged as underutilized — paid-for seats with little or no real usage, the licence-reclamation shortcut. Auvik documents this as acting when the parameter is INCLUDED, so send true to apply it and omit it entirely to disable it rather than sending false.

[Auvik] List SaaS SECURITY EVENTS Auvik recorded for a client — the security-relevant activity across their SaaS applications. Use include to embed the users and applications each event relates to so you can act on it without a second lookup. Requires the Auvik SaaS Management product; an access-denied response usually means the account is not licensed for it.

ParamTypeRequiredDefaultDescription
clientIdstringyesREQUIRED. The ASM client id — get it from auvik_list_asm_clients (NOT from auvik_list_tenants; ASM uses its own client ids).
includestringnonullComma-delimited extras to embed: users, applications (e.g. 'users,applications'). Omit for the event records alone.
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.
queryDatestringnonullLower bound: return only security logs added after this date. This is NOT an as-of snapshot — it is how you page forward through new events over time. Vendor examples use MM/DD/YYYY HH:MM:SS (e.g. 10/10/2024 05:43:26) while the spec's general note says ISO-8601 — if one is rejected, try the other.

[Auvik] List the TAGS applied within a client's Auvik SaaS Management data — how the client's applications have been categorized (sanctioned, under review, and so on). Pass applicationId to see the tags on one application. Requires the Auvik SaaS Management product; an access-denied response usually means the account is not licensed for it.

ParamTypeRequiredDefaultDescription
applicationIdstringnonullRestrict to the tags on this application id (from auvik_list_asm_applications). Omit for every tag at the client.
clientIdstringyesREQUIRED. The ASM client id — get it from auvik_list_asm_clients (NOT from auvik_list_tenants; ASM uses its own client ids).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.

[Auvik] List the SaaS USERS Auvik discovered at a client — the people whose accounts show up across the client's SaaS applications. Use it for offboarding checks (does a departed employee still hold accounts) and as the population behind licence usage. Requires the Auvik SaaS Management product; an access-denied response usually means the account is not licensed for it.

ParamTypeRequiredDefaultDescription
clientIdstringyesREQUIRED. The ASM client id — get it from auvik_list_asm_clients (NOT from auvik_list_tenants; ASM uses its own client ids).
pageAfterstringnonullOpaque forward cursor from the previous response's links.next.
pageBeforestringnonullOpaque backward cursor from the previous response's links.prev.
pageFirstintegerno100Forward page size (default 100, max 1000). Pairs with pageAfter.
pageLastintegernonullBackward page size (max 1000); supplying it switches to backward paging and overrides pageFirst.