Skip to content

Audit logs

Audit logs list events recorded by the application in your organization. They are separate from syslogs sent by your devices and from search results within those syslogs.

Open Audit logs from your organization. Owner, Member and Reader roles can use this page.

Use the search field and date, resource type, action and user filters. Each entry shows its date, user, action and available resource details.

Details may include an IP address or browser information when supplied by the event. These fields are not necessarily present on every event.

Set the Action filter to Export to find period export operations.

EventWhat it means
CreationA request was recorded for a user, locations and date range.
AvailabilityPreparation succeeded and the export is available.
CancellationCancellation was requested.
RetryAnother attempt was requested after a failure.
FailurePreparation failed.
Download link issuedAccess to the prepared file was granted.

Issuing a link for a daily download is also recorded. An issued link does not prove that the browser received the entire file.

An export being prepared also produces processing events associated with the original request. These events do not mean the user stayed signed in during preparation.

  1. Apply the required filters on the page.
  2. Open the export menu and choose CSV or JSON.
  3. Download the file and check its period and events.

This export contains audit events, not your devices’ syslog files. It uses the filters submitted by the page. Exporting audit logs is itself recorded.

Look for changes to settings, allowed IP addresses or permissions around the time of an incident. To inspect your devices’ events, use log search instead.

Displayed events depend on the operations actually logged. For audit retention policies or specific commitments, consult the documents applicable to your service and the security guide.