Reviewing the audit log

The audit log records who did what, on which record, and when, with the values before and after a change. This page shows how to find the entry you need and read it.

Open Administration › Audit Logs. You need view_audit_logs; Internal Auditors and ICT Administrators have it. The log is read-only: nobody can edit or delete entries from the suite.

What is recorded

Each entry stores the person as they were at that moment (name, email, role, units), so it still reads correctly after they change job or leave.

Find an entry

The audit log, searched for test accounts.
  1. Search the description, the person's name or email.
  2. Filters: Entity types (what kind of record), Action types (what was done), Statuses (Success only or Failed only) and a date range.
  3. An entry. Newest first. Columns: Timestamp, User, Action, Entity, Description and Status. Select a row to open it.

Read an entry

An entry's page shows:

Status
Whether the action succeeded.
User
Name, email, role and units of the person who did it.
Entity
The type of record and its ID.
IP Address / User Agent
Where the action came from and the browser used.
Data Snapshots
Previous Data and New Data: the record before and after the change, as JSON.

Common questions

Who changed this person's permissions?

  1. Open the person in Users and select the Logs tab. It lists the last 50 entries about them.
  2. Look for a Permission Changed entry and open it. Compare Previous Data with New Data.

Who approved or rejected a request?

The request's own page shows its full approval trail, which is usually quicker. In the log, filter Action types to Request Approved or Request Rejected and search for its reference.

When was a setting changed?

Filter Action types to Setting Changed, and use the date range.

Were there failed actions?

Set Statuses to Failed only.

Filters and search are kept in the page address. Copy the address to share exactly what you are looking at with a colleague who also has access.

There is an export_audit_logs permission, but the Audit Logs screen does not have an export button yet.

Related