Appearance
Audit log Optional feature
Records important user operations and system events. You can view it from global nav > Workspace settings > Audit log, and from each resource's change log. Only a Workspace Owner can view it (Workspace permissions).
TIP
This is an optional feature. Depending on your contract, it might not be available.
Information shown on screen
The audit log screen has the following columns.
| Column | Content |
|---|---|
| Time | When the operation occurred |
| Status | Success / Error / Deny |
| IP | The IP address the operation came from (only on the workspace settings audit log screen; not shown in each resource's change log) |
| Log | The operation described in natural-language text, including the actor (user, API key, and so on) and the target resource |
- Log text is recorded in English.
- Email addresses are partially masked.
- Content such as notebook body text isn't recorded.
Search
- Open global nav > Workspace settings > Audit log.
- In the search field, choose a user, group, or API key, or enter a keyword.
- Select Search.
- There's no filtering by category or operation type.
- Keywords do a partial match against the log text. Prefix a word with
-to exclude logs containing it. - Select Refresh logs to get the latest list.
Relationship with change logs
| Entry point | Scope |
|---|---|
| Workspace settings > Audit log | The entire workspace |
| Each screen's Change log / History | Limited to operations related to that resource (users, groups, API keys, PATs, teamspaces, connection permissions, additional notebook permissions, reports, public links, and more) |
Using an API key or PAT (token use) is included in the workspace-wide audit log. It's excluded from each key's management change log.
Recorded operations
Examples of operations recorded for audit purposes.
| Category | Examples |
|---|---|
| Workspace | Creation, renaming, deletion, icon and setting changes |
| Users / invitations | Sending, accepting, and declining invitations, role changes, removal, joining via domain match or invite link |
| Group | Creation, renaming, deletion, member joining and leaving, owner and permission changes |
| Teamspace / folder | Creation, renaming, deletion, moving, owner changes |
| Notebook | Creation, deletion, renaming, moving, duplicating, restoring, opening, updates (metadata), additional permission changes |
| Version | Creation, renaming, deletion, opening |
| Report / public link / signed embed | Publishing, publishing changes, deletion, settings, tags, sharing, token issuance, and more |
| Connection | Creation, deletion, access level changes, owner changes, running/getting results/cancelling SQL jobs, and more |
| Catalog-related | Creating, updating, and deleting tags, updating table annotations |
| API key / PAT | Creation, updates, deletion, secret operations, usage |
| Workflow | Creation, duplication, updates, deletion, running and cancelling jobs |
| Theme | Adding, updating, deleting, and setting the default notebook theme (color palette) |
Retention and export
- The retention period is 1 year (Fixed limits and constraints).
- There's currently no export feature on the screen. If you need to export data, contact Codatum support.