---
title: "Read Firewall Actions by Project"
method: GET
path: "/v1/security/firewall/events"
tags: ["security"]
---

# Read Firewall Actions by Project

`GET /v1/security/firewall/events`

Retrieve firewall actions for a project Rule names are resolved against the project's *current* active firewall configuration and the team's active rulesets, so a rule that has since been renamed reports its new name and one that has been deleted reports `null`. System rules such as `sys_dos_mitigation` and `ip_blocking` have no configured name and always report `null`.

## Query parameters

- `projectId` string, required
- `startTimestamp` number
- `endTimestamp` number
- `hosts` string
- `teamId` string
- `slug` string

## Response `200`

- object
  - `actions` object[], required
    - `ruleName` string, nullable, required
    - `startTime` string, required
    - `endTime` string, required
    - `isActive` false | true, required
    - `action_type` string, required
    - `action` string, required
    - `ruleId` string, nullable, required
    - `host` string, required
    - `public_ip` string, required
    - `count` number, required

## Other responses

- `400` — One of the provided values in the request query is invalid.
- `401` — The request is not authorized.
- `403` — You do not have permission to access this resource.
- `404`
- `410`
- `500`

## Changes

> 39 revisions in range; 26 could not be searched.

- **2026-07-21** `2ae10ee9d21c` — 1 info
  - added the non-success response with the status `410`

[Change history](https://skmtc.dev/vercel/apis/api/changes/v1/security/firewall/events/get.md)

---

[API](https://skmtc.dev/vercel/apis/api.md) · [All operations](https://skmtc.dev/vercel/apis/api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/vercel/api/revisions/4191ba96b0c1/schema)
