Exporting events
You can download your events as a CSV or JSON file through the EyalSec API. This page explains how, and how to export exactly what the events page shows.
How to export
There is no export button on the Events page; exports go through the API. One request returns every event that matches your filters as a CSV or JSON file, including the detail you see when you open a row (origin, stack trace and so on). You need an API key.
curl -s -X POST 'https://eyalsec.com/api/events_export?format=csv' \
-H "X-API-Key: es2_EXAMPLE_KEY" \
-H "Content-Type: application/json" \
-d '{"view":"python","severity":["critical","high"],"from":"2026-09-01"}' \
-o findings.csv
Use format=json for JSON. An empty body (-d '{}') exports everything your account can see.
Choosing what to export
The request takes the same filters as the events list, and they mean the same thing, so the file holds the rows the page would show you. The most useful ones:
| Field | Same as on the page |
|---|---|
view |
the list: python, browser, go, ... |
from, to |
the time range (as a date or timestamp) |
machine |
the Machine filter (the machine's name) |
severity |
the Severity filter, a list |
sources |
the es-python Source filter, a list |
tags |
the Tag filter, a list |
bucket |
Show: live, suppressed or all |
advanced |
the conditions, for example a single run |
Your plan's monthly event quota and your blocked events apply to the export exactly as they do on the page.
What the file contains
Each row is one event, with its id, time, severity, product, machine, sink, source, value, count, page or context, origin, repr created, stack trace, whether it is suppressed and why, and its impact tags.
An export stops at 50,000 rows and says so: a CSV ends with a row starting TRUNCATED, and JSON has "truncated": true. Narrow the time range or the filters and export the rest in parts.
Other ways to get events out
To read events page by page, or to fetch one event's full detail, use the events API. The field reference, the response format and more examples are on Events API.