Skip to content

Audit Log

Open Reports > Audit Log to investigate administrative activity: who made a change, when it happened, which target was involved, and its reported outcome.

Runtime events describe what applications did. Audit records describe Console activity, including user, API-key, and automated actions. Use both when investigating a change in protection or fleet behavior.

Audit Log requires Operator or Admin access. Users with limited sensor scope can review permitted sensor records and shared administrative records, but not other sensors' records.

Find an action

  1. Choose a Time range.
  2. Narrow by Category and Outcome.
  3. Enter an Actor email or Sensor ID when known.
  4. Use Search for an action, target, or relevant detail.
  5. Select Apply.

The maximum time window is 90 days. Results load in pages of 100; use the page controls to review more records.

Current page summary describes the displayed page, not a total for all matching history.

Audit Log with time, action, actor, outcome, and sensor details.
Filter administrative activity before opening an audit record. Click to enlarge

Read a record

Review the time, action, actor, target, and outcome. Open available details for client information and supporting metadata.

OutcomeInterpretation
SuccessThe recorded action completed successfully.
FailureThe action failed; read the detail before retrying.
PartialOnly part of the requested action completed. Review affected targets.

An empty actor email does not necessarily mean an automated action. Older records or service-account activity may lack a personal email. Use the available actor identity and attribution details.

Audit metadata is a summary, not a complete copy of every request or policy. A recorded administrative success also does not prove that every offline sensor has received a later change.

Useful categories

Use categories to focus on the work under review:

  • Authentication, users, and access changes.
  • Sensor lifecycle, groups, and trust.
  • Runtime security and API security.
  • Investigations and AI assistant activity.
  • Notifications and integrations.
  • Upgrades and telecom capture.
  • License changes and other administrative activity.

Historical records can include Policy Pack assignments. These remain evidence of earlier changes; they do not indicate that the retired assignment screen is still available.

Export records

  1. Apply the required filters.
  2. Select Export CSV.
  3. Check whether the Console reports that the export was truncated.

The export includes up to 10,000 matching records, not only the current page. Narrow the time range or filters and export additional windows when necessary.

Exported fields include action time, type, outcome, actor, sensor, detail, client information, record identity, category, and available attribution metadata.

Keep exports in a location appropriate for your organization's access and retention requirements.

Investigation examples

Unexpected enforcement change

Filter to Runtime security, the sensor, and the relevant time window. Inspect policy creation, edit, enable, or disable activity. Compare the requested change with sensor delivery confirmation.

Unexpected service-account activity

Search for the API-key identity or related action. Review creation, use, and revocation records where available. Changing the creator's account does not substitute for revoking an independent integration key.

Notification changes

Filter to Notifications and review destination or routing changes around the missed or unexpected notification. Then check the notification delivery log for the result at the provider.

Coverage and retention

Audit records are available only for activity that the Console recorded and still retains. An empty search is not proof that no action occurred.

For reviews that need longer retention, export the relevant records before they expire. Data-lake sensor archives are not a substitute for exporting administrative audit evidence.

Released under the Telovix Commercial License.