Audit log

Every action by a person, a playbook or the platform, attributed and kept for a year.

What is recorded

Sign-ins and failures; every change to alerts, cases, rules, playbooks, suppressions, organizations, users and settings; every response action with its target and result; every playbook run; every report publication; every portal sign-in and ticket action; every export. Each entry carries who, what, when, on which organization, and from where.

Actions from the console, from playbooks and on the endpoint fleet all land in the same trail.

Reading it

Settings › Audit log lists entries with filters by actor, action, organization and time, and a search box. Entries link to the object they concern. Export a filtered range as CSV for an auditor.

Retention and integrity

Entries are append-only and kept for 365 days by default. The retention period is a setting; see Retention.