Audit
within a account, actions are recorded via an service these records provide a reliable foundation for security and compliance, enabling you to monitor and verify activities that affect operations or procedures pre requisites the service uses the existing roles to manage the audit capabilities these roles are platform administrator platform viewer page composition the page displays the following components filter filter actions by date range, event type, initiator, outcome, or observer as you filter your results, tags will appear at the top of the window the clear all option is always available in case you need to remove the filters table a table of events with select details for each event export this option allows exporting the log data in csv or json format settings this option is only available with admin permissions this allows us to set the log retention to 30,60 or 90 days navigating the page navigate to the page with confidence by following straightforward steps, helping you feel assured in managing audit data efficiently use the following steps to access the page from the main menu , go to → table the table shows all actions based on your filter selections, sorted chronologically for each app or service each row contains details for a single event the following columns each display a single type of information initiator user who created the action/log the user associated with the event action what action was triggered event type provides information about the status of a resource or its attributes and properties monitor characterizes events that provide information about the status of a resource or of its attributes or properties control characterizes events that reflect or provide information about the application of a policy or business rule, or more generally express the outcome of a decision making process activity characterizes events that provide information about actions having occurred or intended to occur and initiated by some resource or done against some resource date the time at which the event occurred target the resource or endpoint where the action was performed outcome status of the request, which can be in progress, success, or failed observer app/service in which the action got triggered status code api code the exported audit file includes significantly more audit metadata than what is shown in the ui retention and archival retaining audit data is essential for regulatory compliance, security investigations, operational monitoring and internal audits as organizations grow, audit services must provide scalable and efficient storage to support increasing volumes of audit records while maintaining fast access to historical data to address long term audit and governance requirements, the audit service now retains audit data for 365 days in the elasticsearch database this retention period enables teams to retrieve and analyze historical audit data for a full year, supporting comprehensive investigations, trend analysis, compliance reporting and data driven decision making the audit service supports the following retention periods 30 days 60 days 90 days 180 days 365 days audit data older than the supported 365 day retention period is not available and will not be displayed if an error occurs while applying a date range within the 365 day retention limit , verify that the selected date range is valid and falls within the supported retention period, and then try again you need to have admin permissions to update the retention period once the permission is granted, click the settings button a window will appear, allowing you to select the data range you need and save the results a pop up message indicating that the settings have been saved successfully will appear at the top of the page export creating clear audit reports is essential in today’s business environment they showcase operational effectiveness, build stakeholder trust, and help identify risks and compliance issues additionally, strong audit reports enhance accountability and governance users can export audit data in csv and json formats, ensuring transparency the export includes all relevant information, which can be filtered by date range, observer, (apps/services), initiator and outcome requests for sensitive data, like ip addresses, will be rejected and will not appear to export specific audit logs select the export button; a pop up window will appear if no filters are applied, all data will be exported when filters are used, only matching data will be exported select your preferred format csv or json; there is no default option select the export button an export preloader appears, and once the export finishes, a toast notification appears at the top