Skip to content

Audit log

Every configuration change is recorded: what changed, which account changed it, and when.

The audit logFiltering and paging really run - over nine rows.DemoNothing you change here is saved

Audit Log

Events, last 24h
4
2 distinct actors
Resource kinds touched
3
In the last 24 hours
Events recorded
9
Matching the current filters
Activity, last 24 hours
Activity, last 24 hours
TimeUserResourceEvent
avery
proxy_hostupdate
Enabled the WAF on grafana.example.com
avery
waf_rulewaf.rule_suppressed
Suppressed rule 942100 for grafana.example.com
sam
proxy_hostupdate
Added upstream http://app-2:8080 to app.example.com
sam
l4_proxy_hostcreate
Created L4 proxy host postgres (5432/tcp)
avery
client_certificatecreate
Issued client certificate backup-runner

Creating, editing, enabling, disabling and deleting proxy hosts, L4 hosts, certificates, access lists, users, groups, WAF presets, CRS plugins and OAuth providers - the operations that alter what the proxy does - plus sign-ins, forward-auth logins and denials, password changes, two-factor turned on, off or reset, backups made and restored, certificate renewals asked for and private keys downloaded, and an administrator starting and ending View as. Settings applies are recorded in Settings → History instead, with their diffs. Reads are not logged, key and backup downloads aside; the log exists to answer “why is this host configured like this”, not to track browsing.

The page opens with the last 24 hours at a glance: an hourly activity strip with the busiest hour marked, and how many accounts and kinds of resource were touched. Each row then names the resource and the action alongside the account and the summary. The strip ignores the search, so it stays the context for whatever you are looking through.

Server-side filtering and pagination. Type to search the summary, action and resource, or pick a field - User, Resource or Action - to narrow on it exactly. Filters combine, so “every certificate change Avery made” is two tokens rather than a scroll. The filters live in the address bar, so a filtered view can be bookmarked or linked.

Changes made through the API are attributed to the token’s owner, so an automated change is traceable to the person whose token made it rather than appearing anonymous.

Admin-only, alongside analytics and the API docs.