Before you start
Before you start, sign in to the dashboard and select the organization you want to work in.- You need the Admin or Auditor role. Other roles do not see Audit log in Settings.
- Exports and chain verification use the same permission, so both roles can run them.
Open the audit log
Open Settings, then select Audit log under the Workspace heading. The page opens on the Log tab. The SIEM streaming tab appears only for Admin members on the Enterprise plan. See Stream audit events to your SIEM.Read the event table
Each row is one audit event. Select a row to open its drawer.
The table loads 25 events at a time and shows a loaded count above it. Scroll to load more. When no event matches, the table says No audit events match your filters.
Opening the page is itself audited. The event audit.accessed records who viewed the log and with which filters.
Find an event
1
Type in the search box
Search matches words in the event description. Type
role to see every role change.2
Add filters
Open the combined filter and pick from four dimensions:
- Event lists exact event names, each labelled with its area. It offers only the events your organization has recorded, so the list grows as your organization does more.
- Category lists the display categories.
- Member lists your organization’s members by name or email.
- Outcome offers Success, Failure, or Denied.
3
Set the date range
The date range picker on the right defaults to the last 30 days. Presets such as Today and Last 7 days fit inside your plan’s searchable window. All retained logs clears the range. Older dates are disabled.
4
Follow a target
Select a linked name in a description to filter by that target. A Target chip appears above the table. Select the chip’s X to clear it.
Read the event drawer
Select a row and a drawer opens on the right. The header repeats the description, the time, the exact event name, the outcome, and the sequence number. Use the up and down arrows, or the arrow keys, to step through the loaded events without closing the drawer.Export audit data
1
Filter the table first
The export contains only the events that match your current filters.
2
Select Export
The Export audit log dialog opens. Switch between CSV and JSON at the top of the dialog. Set the Export date range in the dialog. That range applies only to the export and does not change the table.
The dialog omits the next step’s option when your organization has no archived events.
3
Decide whether to include archived events
If your organization has archived events, the dialog offers Include archived logs (may take longer). It is on by default. Turn it off for a faster export of recent events only.
4
Select Generate export
The dialog closes and a toast confirms that the export started. The export runs in the background.
5
Collect the file
When the export is ready, the browser starts the download if the tab is visible. Otherwise, open the Tasks panel from the tracker at the foot of the sidebar. Select Download on the Audit log export row.
Verify chain integrity
Each audit record carries a hash that chains it to the record before it. A changed, inserted, or removed record breaks the chain. You can check the chain yourself, without contacting Tars. Select Verify chain integrity above the table. While the check runs, the button changes to a counter such as Verifying… 336 events checked. The result replaces the button:- A green Chains verified · 336 events banner means every record matches its hash and the sequence has no gaps.
- A red Integrity issue · tenant seq 812 (prevHash) banner names the first record that fails, and the kind of break. The kind is
gap,prevHash,rowHash, orhead. - No hash-chained events yet appears in a new organization with no events.
- Verification failed to run appears above the button when the check itself fails. Run it again.
