Activity logs
Use the filters to identify and download relevant activity logs in CSV file format. The Activity Log combines Change Log and Security Log data into a single CSV export.
Time and user filters
Security event filters
Change log event filters
Accessing activity logs
To access activity log tools, click the Security tile under the Administration Tools section, and select either Activity Logs, or Activity Log Exports.
Time period and user filters
Use the Activity Log to view security events and change log activity.
Use the filters below to sort entries:
Time Period — Filter results by the specified date and time range. Select one of the preconfigured time periods available on the dropdown list, or select Custom and use the date range boxes: use the calendars to find and click the beginning and end dates. Times are based on your browser's timezone.
Restriction: By default, when you apply no filters the maximum export window is one week. Note that different types of data retention conditions apply depending on the log type. For reference, see the below table.Filter Date range No filters 1 week Users filter Up to 6 months All filters applied Up to 6 months Users filter not applied: Include security events active.
No security event type selected (Include change logs not active, or Include change logs active with selected entity type).
1 week Users filter not applied: Include change logs active.
No entity type selected (Include security events not active, or Include security events active with selected security event type).
1 week Users filter not applied: Include security events and Include change logs active.
Neither security event type nor entity type selected.
1 week Users — Select one or more users to view their associated security and change log events.
Security event filters
To fetch security events, select Include Security Events, and select one or more security event types to view specific authentication, access, role, permission, and system administration activities.
To select filter attributes , click Add on the corresponding filter and select an attribute from the list, or click
Search to find the desired one.
The available security events are:
Bifrost
Grant manager
Grant user
Revoke manager
Revoke user
Update role
Command Center
Action
Command
Grant permission to role
Grant role to user
Revoke role to user
System Connections
create
Delete
List
Read
Update
User
Login
Logout
Switch back
Tenant key change
Change log event filters
To fetch configuration activity, select Include Change Logs, and select one or more change-log event types to filter events by action performed.
To select filter attributes , click Add on the corresponding filter and select an attribute from the list, or click
Search to find the desired one.
Available event types are:
Create
Update
Delete
Optionally, select one or more entities to view changes made to specific asset and configuration categories, such as:
Account
Action plans
Ad hoc
Alerts
Alternative groups
Analytics reports
Anonymous surveys
Ask Now
Athena Studio
Athena Themes
Attribute rating
Rules
Auto-exclude rules
Auto opt-out rules
Availability window configurations
Activity log exports
Once you have selected the necessary filters, click Download CSV.
When a download is triggered, a new tracking window displays the progress in real-time, allowing navigation away from the page without interrupting the process.
You can track the download process in the Exports queue section.
Once the download process is complete, the files are securely stored and accessible at any time within the Exports section.
On the Exports Queue, select the file and click Download.
Open the downloaded file in a spreadsheet editor.
Exported file
The downloaded file is in RFC-4180-compliant CSV file format. Each row in the spreadsheet represents a log event. Key columns are:
Timestamp (in ISO-8601 format:
YYYY-MM-DDTHH:mm:ss.SSSZ)Event type
Event sub-type
User name
Extra details (in JSON format)
