Skip to main content

User Guide

View Audit Logs

  1. Click Audit in the left navigation.

    A list of audit events appears, including the following object types:

    • assets

    • authentication

    • business information (tags, terms, data classes)

    • connections

    • datasets

    • policies

    • policy resolution (See View Policy Resolution Audit Logs.)

      Note

      Policy resolution events record whether or not the policies were applied to the query. They do not record the final state of the query. For the latter, review the query log from your query tool.

    • projects

    • transformations

    The list of audit events appears in date order from most recent to oldest.

    Note

    As you navigate throughout the platform, you can also view audit logs for any of the objects listed here directly from that object's page. Click More (the three vertical dots) and select View History.

  2. Enter search criteria in the Search box.

    You can enter any text to search for member IDs, correlation IDs, and object IDs, such as policy IDs.

    You can enter all or part of an ID.

    Note

    Member IDs are not case sensitive, but all other IDs are case sensitive.

    Audit_Log_Search_View_INFA.png
  3. Click the Filter icon.

    The Refine Results window appears.

    1. Select specific criteria within the following categories:

      • Audit Username

      • Audit Event Type

      • Audit Timestamp

      Audit_Log_Filter_Search_View_INFA.png
  4. Click an event to view its details.

    Some high-level information about the event appears at the top of the page, followed by the JavaScript Object Notation (JSON) version of that event's details.

    See "Audit Events" in the Data Security Platform Installation and Administration Guide for a list of audit event descriptions.

    Audit_Log_JSON_View_INFA.png
  5. Click the View (eye) icon to toggle between:

    • a tree view in which you can expand and collapse sections of the tree

    • a fully expanded code view