For the complete documentation index, see llms.txt. This page is also available as Markdown.

Audit Logs

You can use Audit Logs to review user activity and administrative events across your organization. Audit logs help you investigate actions performed in OX, verify scan activity, and troubleshoot authentication or operational issues.

The Audit Logs page displays audit events in chronological order and provides filters to help you quickly locate specific events.

From the menu pane, go to ADMIN > Audit Logs.

Use this page to:

  • monitor logins, scans, and user actions

  • investigate unusual or unauthorized activity

Prerequisites

You need read/write permissions to view audit logs.

Audit log columns

The Audit Logs table includes the following columns.

Column
Description

User

User who performed the action.

Action

Action that was performed, such as Login, Scan Now, or Scan Finished.

Additional Info

Additional information about the event. The displayed information depends on the event type. For example, authentication events display the login method and assigned user roles, while scan events display the scan ID, enabled connectors, or scan status.

Log Type

Category of the audit event, such as Authentication or Scan.

Date

When the event occurred.

Filter audit logs

You can filter the displayed audit logs to show only the events that you want to review.

Filter
Description

Action

Displays only logs for the selected actions.

User

Displays only logs generated by the selected users.

Log Type

Use the tooltips to identify icons.

  • User: The name of the user.

  • Action: Login or Scan.

  • Additional Info: Shows additional details like the User Role or Scan ID.

  • Log Type

  • Date: The date of the action.

View scan details

You can view additional information about scan events from the Audit Logs page.

To view scan details:

  • On the Audit Logs page, select a Scan event.

General info

The General Info section summarizes the audit event.

Field
Description

Time

Time when the audit event was recorded.

User

User who initiated the scan.

Operation

Operation associated with the audit event, such as Scan Finished.

Details

The Details section provides information about the scan.

Field
Description

Scan ID

Unique identifier of the scan.

Started

Time when the scan started.

Finished

Time when the scan completed.

Status

Final scan status, such as Succeeded, Failed, or Canceled.

Note: Detailed information is available only for scan events.

Last updated