What is recorded
Sign-ins and failures; every change to alerts, cases, rules, playbooks, suppressions, organizations, users and settings; every response action with its target and result; every playbook run; every report publication; every portal sign-in and ticket action; every export. Each entry carries who, what, when, on which organization, and from where.
Actions from the console, from playbooks and on the endpoint fleet all land in the same trail.
Reading it
Settings › Audit log lists entries with filters by actor, action, organization and time, and a search box. Entries link to the object they concern. Export a filtered range as CSV for an auditor.
Retention and integrity
Entries are append-only and kept for 365 days by default. The retention period is a setting; see Retention.