Audit
Within a Kyndryl Bridge account, actions are recorded via an Audit service. These records provide a reliable foundation for security and compliance, enabling you to monitor and verify activities that affect operations or procedures.
The Audit service uses the existing Kyndryl Bridge roles to manage the audit capabilities. These roles are:
- Platform Administrator
- Platform Viewer
Audit page navigation
Navigate the Audit page with confidence by following straightforward steps, helping you feel assured in managing audit data efficiently:
From the Kyndryl Bridge main menu , go to Administration → Service Operations →Audit.
The Audit page displays all user and system actions across Bridge services, where you can view and track activity to ensure transparency, compliance and accountability.
Audit page components
The Audit page displays the following components:
- Filter: Filter actions by date range, event type, initiator, outcome, or observer. As you filter your results, tags will appear at the top of the window. The Clear All option is always available in case you need to remove the filters.
- Audit table: A table of events with select details for each event.
- Export: This option allows exporting the log data in CSV or JSON format.
- Settings: This option is only available with Admin permissions. This allows us to set the log retention to 30,60 or 90 days.
Audit table
The table shows all actions based on your filter selections, sorted chronologically for each app or service. Each row contains details for a single event. The following columns each display a single type of information:
- Initiator: User who created the action/log. The user associated with the event.
- Action: What action was triggered
- Event type: Provides information about the status of a resource or its attributes and properties.
- Monitor: Characterizes events that provide information about the status of a resource or of its attributes or properties.
- Control: Characterizes events that reflect or provide information about the application of a policy or business rule, or more generally express the outcome of a decision-making process.
- Activity: Characterizes events that provide information about actions having occurred or intended to occur and initiated by some resource or done against some resource.
- Date: The time at which the event occurred.
- Target (Endpoint): The resource or endpoint where the action was performed.
- Outcome: Status of the request, which can be In progress, Success, or Failed.
- Observer (Module): App/Service in which the action got triggered.
- Status code: API code
The exported audit file includes significantly more audit metadata than what is shown in the UI.
Retention and archival
Retaining audit data is essential for regulatory compliance, security investigations, operational monitoring and internal audits. As organizations grow, audit services must provide scalable and efficient storage to support increasing volumes of audit records while maintaining fast access to historical data.
To address long-term audit and governance requirements, the Kyndryl Bridge Audit Service now retains audit data for 365 days in the Elasticsearch database. This retention period enables teams to retrieve and analyze historical audit data for a full year, supporting comprehensive investigations, trend analysis, compliance reporting and data-driven decision-making.
The Kyndryl Bridge Audit Service supports the following retention periods:
- 30 days
- 60 days
- 90 days
- 180 days
- 365 days
Audit data older than the supported 365-day retention period is not available and will not be displayed. If an error occurs while applying a date range within the 365-day retention limit, verify that the selected date range is valid and falls within the supported retention period, and then try again.
You need to have admin permissions to update the retention period. Once the permission is granted, click the Settings button. A window will appear, allowing you to select the data range you need and save the results. A pop-up message indicating that the settings have been saved successfully will appear at the top of the page.
Export
Creating clear audit reports is essential in today’s business environment. They showcase operational effectiveness, build stakeholder trust, and help identify risks and compliance issues. Additionally, strong audit reports enhance accountability and governance.
Users can export audit data in CSV and JSON formats, ensuring transparency. The export includes all relevant information, which can be filtered by date range, observer, (apps/services), initiator and outcome. Requests for sensitive data, like IP addresses, will be rejected and will not appear.
To export specific audit logs:
- Select the Export button; a pop-up window will appear. If no filters are applied, all data will be exported. When filters are used, only matching data will be exported.
- Select your preferred format: .CSV or. JSON; there is no default option.
- Select the Export button. An export preloader appears, and once the export finishes, a toast notification appears at the top.