Skip to main content
By the end of this page, you can find any audited action in your organization and read its full record. You can also export the evidence and confirm that the log is intact.

Before you start

Before you start, sign in to the dashboard and select the organization you want to work in.
  • You need the Admin or Auditor role. Other roles do not see Audit log in Settings.
  • Exports and chain verification use the same permission, so both roles can run them.

Open the audit log

Open Settings, then select Audit log under the Workspace heading. The page opens on the Log tab. The SIEM streaming tab appears only for Admin members on the Enterprise plan. See Stream audit events to your SIEM.
The Audit log page with the search box, the combined filter, the Verify chain integrity button, the date range picker, the Export button, and a table of events

Read the event table

Each row is one audit event. Select a row to open its drawer. The table loads 25 events at a time and shows a loaded count above it. Scroll to load more. When no event matches, the table says No audit events match your filters. Opening the page is itself audited. The event audit.accessed records who viewed the log and with which filters.

Find an event

1

Type in the search box

Search matches words in the event description. Type role to see every role change.
2

Add filters

Open the combined filter and pick from four dimensions:
  • Event lists exact event names, each labelled with its area. It offers only the events your organization has recorded, so the list grows as your organization does more.
  • Category lists the display categories.
  • Member lists your organization’s members by name or email.
  • Outcome offers Success, Failure, or Denied.
3

Set the date range

The date range picker on the right defaults to the last 30 days. Presets such as Today and Last 7 days fit inside your plan’s searchable window. All retained logs clears the range. Older dates are disabled.
4

Follow a target

Select a linked name in a description to filter by that target. A Target chip appears above the table. Select the chip’s X to clear it.

Read the event drawer

Select a row and a drawer opens on the right. The header repeats the description, the time, the exact event name, the outcome, and the sequence number. Use the up and down arrows, or the arrow keys, to step through the loaded events without closing the drawer.
The event drawer for a member role change, with the Actor, Target, Changes, Integrity, and Raw payload sections
The drawer shows these sections. Sections with no data are hidden.

Export audit data

1

Filter the table first

The export contains only the events that match your current filters.
2

Select Export

The Export audit log dialog opens. Switch between CSV and JSON at the top of the dialog. Set the Export date range in the dialog. That range applies only to the export and does not change the table.
The Export audit log dialog with the CSV and JSON toggle, the Export date range picker, a note that no archived logs are available, a line saying the export runs in the background, and the Cancel and Generate export buttons
The dialog omits the next step’s option when your organization has no archived events.
3

Decide whether to include archived events

If your organization has archived events, the dialog offers Include archived logs (may take longer). It is on by default. Turn it off for a faster export of recent events only.
4

Select Generate export

The dialog closes and a toast confirms that the export started. The export runs in the background.
5

Collect the file

When the export is ready, the browser starts the download if the tab is visible. Otherwise, open the Tasks panel from the tracker at the foot of the sidebar. Select Download on the Audit log export row.
Every export is recorded as audit.exported, so reviewers can see who exported which records and when. The exported file contains one line per event. Columns include the sequence number, time, action, description, category, outcome, actor, target, source IP, changes, payload, and both hashes.

Verify chain integrity

Each audit record carries a hash that chains it to the record before it. A changed, inserted, or removed record breaks the chain. You can check the chain yourself, without contacting Tars. Select Verify chain integrity above the table. While the check runs, the button changes to a counter such as Verifying… 336 events checked. The result replaces the button:
  • A green Chains verified · 336 events banner means every record matches its hash and the sequence has no gaps.
  • A red Integrity issue · tenant seq 812 (prevHash) banner names the first record that fails, and the kind of break. The kind is gap, prevHash, rowHash, or head.
  • No hash-chained events yet appears in a new organization with no events.
  • Verification failed to run appears above the button when the check itself fails. Run it again.
A green banner reporting verified chains and the number of events checked, sitting where the Verify chain integrity button was, above the event table and its Seq column
The count in the banner covers every chained record, so it is larger than the loaded count beside it, which counts only the rows fetched so far. If the check cannot run, the page shows Verification failed to run and offers the button again.

How far back the log reaches

The searchable window depends on your plan. The info icon beside the date range picker states the window in days, and that older archived logs are available through Export. Archived events are not searchable in the table, but exports can include them. See Data retention for the windows on each plan.

Verify

Set the date range to Today, select Export, keep CSV, and select Generate export. The file downloads or appears in the Tasks panel. Refresh the table and the newest row reads that you exported the audit log.