Audit Logs
You can use Audit Logs to review user activity and administrative events across your organization. Audit logs help you investigate actions performed in OX, verify scan activity, and troubleshoot authentication or operational issues.
The Audit Logs page displays audit events in chronological order and provides filters to help you quickly locate specific events.
From the menu pane, go to ADMIN > Audit Logs.

Use this page to:
monitor logins, scans, and user actions
investigate unusual or unauthorized activity
Prerequisites
You need read/write permissions to view audit logs.
Audit log columns
The Audit Logs table includes the following columns.
User
User who performed the action.
Action
Action that was performed, such as Login, Scan Now, or Scan Finished.
Additional Info
Additional information about the event. The displayed information depends on the event type. For example, authentication events display the login method and assigned user roles, while scan events display the scan ID, enabled connectors, or scan status.
Log Type
Category of the audit event, such as Authentication or Scan.
Date
When the event occurred.
Filter audit logs
You can filter the displayed audit logs to show only the events that you want to review.
Action
Displays only logs for the selected actions.
User
Displays only logs generated by the selected users.
Log Type
Use the tooltips to identify icons.
User: The name of the user.
Action: Login or Scan.
Additional Info: Shows additional details like the User Role or Scan ID.
Log Type
Date: The date of the action.
View scan details
You can view additional information about scan events from the Audit Logs page.
To view scan details:
On the Audit Logs page, select a Scan event.

General info
The General Info section summarizes the audit event.
Time
Time when the audit event was recorded.
User
User who initiated the scan.
Operation
Operation associated with the audit event, such as Scan Finished.
Details
The Details section provides information about the scan.
Scan ID
Unique identifier of the scan.
Started
Time when the scan started.
Finished
Time when the scan completed.
Status
Final scan status, such as Succeeded, Failed, or Canceled.
Note: Detailed information is available only for scan events.
Last updated
