Audit Trail
Overviewโ
The Audit Trail provides a comprehensive record of all system activities and changes made to the platform. This feature offers administrators and security teams visibility into user actions, system modifications, and critical events, creating an immutable record for compliance, troubleshooting, and security monitoring.
Accessing the Audit Trailโ
- Navigate to the left sidebar navigation panel
- Click on "Monitoring" in the menu options
- Select "Audit Trail" from the submenu (indicated by the arrow icon)
- The Audit Trail interface will load, displaying a tabular view of all logged events
Audit Trail Interface Componentsโ
Time Range Selectionโ
Located near the top of the interface, this control allows filtering of audit events by different time periods:
- 24H: Displays events from the past 24 hours
- 7D: Displays events from the past 7 days
- 1M: Displays events from the past month
- 3M: Displays events from the past 3 months
- All: Displays all historical events
Export Functionalityโ
- EXPORT ALL DATA: Button located next to time filters that allows exporting the current view of audit data for external analysis, reporting, or compliance documentation
View Controlsโ
Located at the top-right corner of the table:
- Search: Magnifying glass icon to search through audit records
- Table View: Toggle between different table view modes
- Fullscreen: Expand the audit table to fullscreen mode
Audit Log Tableโ
The main component displaying detailed audit information in tabular format with the following columns:
Column | Description | Example Value |
---|---|---|
Selection Checkbox | Allows selection of individual or multiple audit records | โ |
Created At | Timestamp of when the event occurred | MM/DD/YYYY, H:MM:SS PM |
Level | Severity or type of the action | INFO, MODERATE, CRITICAL |
Message | Description of the action that occurred | "Created new project", "Deleted resource", "Edited configuration" |
User | User who performed the action | [User identifier] |
Module | System component or section affected | "Deployment", "General Settings", "Persona Management" |
Log Details Modalโ
When clicking on a specific audit record, a detailed view appears in a modal window showing:
- Created At: Exact timestamp of the event
- User: User who performed the action
- IP Address: Origin IP address of the request
- Message: Descriptive message about the action
- Level: Severity level (with color coding)
- Data: JSON representation of the affected data or changes made
A "Close" button at the bottom allows closing the modal to return to the audit log list.
Table Controlsโ
- Column Headers: Each column has sortable headers (indicated by arrows)
- More Options: Each column has a menu with additional options (indicated by "..." icon)
- Pagination Controls: Located at the bottom of the table, showing:
- Rows per page selector (typically set to 10)
- Page navigation buttons (Previous, Next, First, Last)
- Current page indicator
- Total number of pages (indicated by numbered buttons)
Audit Event Types and Levelsโ
Level Categoriesโ
Audit events are categorized by severity/action level:
INFO: Informational events such as:
- Resource creation
- Project starts/stops
- Login activities
- Configuration views
- Status changes
MODERATE: Modification events such as:
- Resource edits
- Configuration changes
- Permission adjustments
- Settings updates
CRITICAL: High-impact events such as:
- Resource deletions
- System resets
- Security setting changes
- User removals
Common Event Messagesโ
Examples of typical audit events include:
Event Type | Example Message | Level |
---|---|---|
Creation | "Created a new project" | INFO |
Start | "Started Project [project-name]" | INFO |
Stop | "Stopped Project [project-name]" | INFO |
Edit | "Edited [resource-name]" | MODERATE |
Update | "Updated configuration settings" | MODERATE |
Deletion | "Deleted [resource-name]" | CRITICAL |
Using the Audit Trail Effectivelyโ
Security Monitoringโ
- Monitor login activities and access patterns
- Review critical actions like deletions and configuration changes
- Track actions by administrative users
- Identify unusual activity patterns or access times
Compliance Documentationโ
- Export audit logs for compliance reporting
- Document system changes for regulatory requirements
- Maintain records of user access and actions
- Preserve evidence of security controls
Troubleshootingโ
- Track system changes that preceded errors
- Identify which users made specific changes
- Review the exact data modifications in the log details
- Correlate timestamps with system performance issues
Change Trackingโ
- Monitor project lifecycle events (creation, modification, deletion)
- Track configuration changes across the platform
- Follow the history of specific resources or projects
- Verify that authorized changes were implemented correctly
Best Practicesโ
Regular Auditingโ
- Review critical events daily
- Conduct weekly reviews of moderate-level changes
- Perform monthly compliance checks of all audit data
- Set up automated alerts for specific critical actions
Filtering Strategiesโ
- Use time range selectors to focus on relevant periods
- Filter by level to prioritize critical events
- Search for specific resources or actions when troubleshooting
- Sort by user to track activities of specific team members
Record Keepingโ
- Export audit data regularly for long-term storage
- Maintain historical audit logs for compliance purposes
- Document findings from audit reviews
- Correlate audit events with other system logs
Security Insightsโ
- Look for patterns of failed actions
- Monitor activities outside normal business hours
- Track administrative account usage
- Verify that critical changes follow change management processes
Troubleshooting Common Issuesโ
Issue | Possible Cause | Solution |
---|---|---|
Missing audit events | Filtering too narrow | Expand time range or clear filters |
Unclear event messages | Complex actions or system events | Review the detailed data in the log details modal |
Too many events to review | High system activity | Use filtering and sorting to focus on critical events |
Incomplete data export | Export process interrupted | Retry export with smaller time ranges |
Integration with Other Monitoring Featuresโ
The Audit Trail is part of a broader monitoring ecosystem that includes:
- Dashboard: Provides overview metrics of platform performance
- Requests: Tracks specific API and user requests
- User Analytics: Analyzes usage patterns at the user level
- Platform Monitoring: Monitors technical aspects of the platform infrastructure
These components work together to provide comprehensive visibility into all aspects of platform usage, security, and performance.