Access to audit logs
When the feature is enabled for your organization, audit logs are automatically collected as activity occurs. You do not need to manually enable log collection.
In order to view and export audit logs, you must have the View User Activity Log access control permission granted (found under the Data Governance category). To learn how to manage individual permissions for Platform features, please refer to the access control documentation.
Managing audit logs in the UI
You can view audit logs for different Experience Platform features within the Audits workspace in the Platform UI. The workspace shows a list of recorded logs, by default sorted from most recent to least recent.
Audit logs are retained for 365 days after which they will be deleted from the system. If you require data of more than 365 days, you should export logs at a regular cadence to meet your internal policy requirements.
Your method of requesting audit logs changes the allowable time period and the number of records you will have access to. Exporting logs allows you to go back 365 days (in 90 day intervals) to a maximum of 10,000 records, where as the activity log UI in Experience Platform displays the past 90 days to a maximum of 1000 records.
Select an event from the list to view its details in the right rail.
Filter audit logs
Select the funnel icon (
The following filters are available for audit events in the UI:
Filter | Description |
---|---|
Category | Use the dropdown menu to filter displayed results by category. |
Action | Filter by action. The actions available for each service can be seen in the resource table above. |
User | Enter the complete user ID (for example, johndoe@acme.com ) to filter by user. |
Status | Filter by whether the action was allowed (completed) or denied due to lack of access control permissions. |
Date | Select a start date and/or an end date to define a date range to filter results by. Data can be exported with a 90-day lookback period (for example, 2021-12-15 to 2022-03-15). This can differ by event type. |
To remove a filter, select the “X” on the pill icon for the filter in question, or select Clear all to remove all filters.
The returned audit log data contains the following information on all queries that meet your chosen filter criteria.
Column name | Description |
---|---|
Timestamp | The exact date and time of the action performed in a month/day/year hour:minute AM/PM format. |
Asset Name | The value for the Asset Name field depends on the category chosen as a filter. |
Category | This field matches the category selected in the filter dropdown. |
Action | The available actions depend on the category chosen as a filter. |
User | This field provides the user ID that executed the query. |