Audit logs
Audit logs list events recorded by the application in your organization. They are separate from syslogs sent by your devices and from search results within those syslogs.
View and filter
Section titled “View and filter”Open Audit logs from your organization. Owner, Member and Reader roles can use this page.
Use the search field and date, resource type, action and user filters. Each entry shows its date, user, action and available resource details.
Details may include an IP address or browser information when supplied by the event. These fields are not necessarily present on every event.
Find a log export
Section titled “Find a log export”Set the Action filter to Export to find period export operations.
| Event | What it means |
|---|---|
| Creation | A request was recorded for a user, locations and date range. |
| Availability | Preparation succeeded and the export is available. |
| Cancellation | Cancellation was requested. |
| Retry | Another attempt was requested after a failure. |
| Failure | Preparation failed. |
| Download link issued | Access to the prepared file was granted. |
Issuing a link for a daily download is also recorded. An issued link does not prove that the browser received the entire file.
An export being prepared also produces processing events associated with the original request. These events do not mean the user stayed signed in during preparation.
Export audit events
Section titled “Export audit events”- Apply the required filters on the page.
- Open the export menu and choose CSV or JSON.
- Download the file and check its period and events.
This export contains audit events, not your devices’ syslog files. It uses the filters submitted by the page. Exporting audit logs is itself recorded.
Use audits to investigate
Section titled “Use audits to investigate”Look for changes to settings, allowed IP addresses or permissions around the time of an incident. To inspect your devices’ events, use log search instead.
Displayed events depend on the operations actually logged. For audit retention policies or specific commitments, consult the documents applicable to your service and the security guide.