Appearance
Audit logs Optional feature
Records important user operations and system events. You can view it from global nav > Workspace settings > Audit logs, and from each resource's Change logs. Only a Workspace Owner can view it (Workspace permissions).
TIP
This is an optional feature. Depending on your contract, it might not be available.
Information shown on screen
The audit log screen has the following columns.
| Column | Content |
|---|---|
| Time | When the operation occurred |
| Status | Success / Error / Deny |
| IP | The IP address the operation came from (only on the workspace settings audit log screen; not shown in each resource's Change logs) |
| Log | The operation described in natural-language text, including the actor (user, API key, and so on) and the target resource |
- Log text is recorded in English.
- Email addresses are partially masked.
- Content such as notebook body text isn't recorded. Metadata such as resource IDs and names is recorded.
Search
- Open global nav > Workspace settings > Audit logs.
- In the search field, choose a user, group, or API key, or enter a keyword.
- Select Search.
- There's no filtering by category or operation type.
- Keywords do a partial match against the log text. Prefix a word with
-to exclude logs containing it. - Select Refresh logs to get the latest list.
Relationship with change logs
You can view workspace-wide logs from Audit logs. Resource-scoped logs are available from the paths in the following table as Change logs (on some screens, Logs or History).
| Path | Scope |
|---|---|
| Workspace settings > General > Change logs | Changes to the workspace itself |
| Workspace settings > Users > Change logs | Changes related to users and invitations |
| Workspace settings > Groups > group edit screen > Change logs | Changes to that group |
| Workspace settings > Teamspaces > teamspace edit screen > Change logs | Changes to that teamspace |
| Workspace settings > API Keys > Change logs | API key management operations |
| Workspace settings > Personal Access Tokens > Change logs | PAT management operations |
| Workspace settings > Connections > permission settings screen > Change logs | Permission changes for that connection |
| Notebook Share > Public link > Change logs | Changes to that public link |
| Notebook Share > additional permissions Change logs | Changes to that notebook's additional permissions |
| Report Report settings > Logs | Changes to that report |
Using an API key or PAT (token use) is included in the workspace-wide audit log. It's excluded from each key's management Change logs.
Recorded operations
Examples of operations recorded for audit purposes.
| Resource | Example operations |
|---|---|
| Workspace | Creation, renaming, deletion, setting changes |
| Users / invitations | Sending, deleting, resending, accepting, and declining invitations; joining via invite link or allowed domain; role changes; user removal; adding, changing, and removing permissions |
| Group | Creation, renaming, deletion, icon changes, member joining and leaving, adding and removing owners, adding, changing, and removing permissions |
| API key | Creation, renaming, deletion, retrieving/adding/removing secrets, usage |
| PAT | Creation, updates, revocation, suspension, unsuspension, usage |
| Connection | Creation, deletion, access level changes, adding and removing owners, running SQL, getting results, exporting, cancelling |
| Teamspace / folder | Creation, renaming, deletion, moving, owner changes |
| Notebook | Creation, deletion, renaming, moving, duplicating, restoring, opening, updates, additional permission changes |
| Notebook version | Creation, renaming, deletion, opening |
| Report | Publishing, publishing changes, deletion, sharing, guest invitations, viewing |
| Public link | Publishing, publishing changes, deletion |
| Signed embed | Publishing, publishing changes, deletion, updating allowed origins, adding and removing API keys and parameters, issuing tokens |
| Catalog-related | Creating, updating, and deleting tags, updating table annotations |
| Workflow | Creation, duplication, updates, deletion, running and cancelling jobs |
| Notebook theme | Adding, updating, and deleting |
Retention and export
- The retention period is 1 year (Fixed limits and constraints).
- There's currently no export feature on the screen. If you need to export data, contact Codatum support.