Audit Log
NAVIGATION Administration > Server Admin > Audit Log
PERMISSIONS Administrator
The Audit Log page allows administrators to view and search a list of account activities. The Default view on the page displays all activity log data from the last seven days.
Additionally, there are two other built in views, Errors and Warnings, show audit log entries from the last seven days for only their respective log entry types.
Searching and filtering the Audit Log
By default, the Audit Log is set to search for all activities executed in the account from the last seven days.
The list is sorted chronologically by the date the activity occurred, from most recent to least recent. Click the Timestamp column header to sort from least recent to most recent. Or, you can sort the list alphabetically by any other column.
To search the current view, enter your criteria in the Search bar at the top of the page. The results will automatically filter to only show results that match your search query.
To add a filter to the current view, click the Add Filter button in the upper left, and select the filter criteria. You can then configure the filter criteria in the space below the Search bar.
Any configured search or filter criteria will reset the next time the page is accessed. To save a custom view, you will need to create a new view. Refer to New View.
The following filter criteria is available:
| Field | Description |
|---|---|
| Device | Filters the list by the Device column. Enter all or part of a device name in the account to populate the list with activities executed on that device. |
| Device Group | Filters the list by the Device Group column. Enter all or part of a device group name in the account to populate the list with activities executed on devices in that device group. |
| Category | Filters the list by the Category column. Select a category from the drop-down menu to populate the list with activities that fall under that category. |
| Username or id containing | Filters the list by the Username column. Enter all or part of a user name in the account to populate the list with activities executed by that user. |
| System or group containing | Filters the list by the System/Group column. Enter all or part of a device name or group name to populate the list with activities associated with that device/group. |
| Type | Filters the list by the Type field, which is visible upon clicking a row to view the full details of an activity. Select a type of activity from the drop-down menu to populate the list with activities of that type. |
| From/To | Filters the list by the Date and Time column. In the From and To fields, click the calendar icons to select dates from the calendar tool or manually enter dates in the format MM/DD/YY to populate the list with activities executed during that time frame. |
Click any row to view the full details of that activity, including the following additional information: the source of the activity, the IP address the activity was executed from, and the Action ID.
Audit Log column definitions
The Audit Log page displays the following columns for each audit log entry:
| Field | Description |
|---|---|
| Date and Time | The date and time when the activity was executed. |
| Username | The user name of the user who executed the activity. |
| Device | The name of the registered user device used to execute the activity. Refer to Managing user account device access. |
| System/Group | The name of the monitored device the activity pertains to followed by the name of the group the device belongs to. |
| Category | The category of the activity. |
| Description | The description of the activity. To view the full description, click anywhere in the row. |
Exporting the Audit Log
In the upper-right corner of the page, click the ellipses icon and select Export Comma-separated Values (CSV) to download the account activity data in a Comma-separated Values (CSV) file on your local device. The export will contain data in accordance with the currently applied filters. The spreadsheet contains the following additional information not displayed within VSA 10: the ID and description of the user's device and the device ID.