1. Docs
  2. Audit Log
  3. Search and export the audit log

Search and export the audit log

Search and filter audit events in the Developer Console, inspect related events, save a view, follow the feed live, and export a CSV.

Search and inspect events

In the Developer Console, Tenant → Audit Log has two tabs: Admin activity, what administrators did, and Identity activity, what end users did. Each row shows time, actor, action, resource, outcome, and severity.

Application
Developer Console
Path
TenantAudit Log
Opens with
  • audit.view Read the Account's audit log and export it.
Context
Account-wide. No Application or Environment selection applies.
Search and inspect events
Open Audit Log from the left nav under Tenant. Type in the search box to narrow the feed by actor, resource, or metadata; the URL gains the query so the view can be shared. Widen the date range or clear filters when the table reads No events match your filters.Click a row. The Audit event drawer opens on Overview, with Metadata and Related events tabs. Related events groups rows from the same request and from the same actor within an hour; clicking one opens it.Click Save view and name it to keep the current filters as a chip under the search bar; click the chip to re-apply it, and its × to delete it.Click Live tail to follow new events as they happen; its dot pulses while following. Click again to stop.

Export a CSV

Exports run in the background and capture whatever filters are active.

Export a CSV
Click Export CSV. A toast reads Export started. We'll let you know when it's ready.Click Exports. The panel lists recent jobs, newest first, each with a status from Pending through Processing to Ready, or Failed.When a job is Ready, click Download; a fresh signed link opens the CSV. The job's × removes it and its stored file.
If you don't see this

Each control on this page exists only for someone who may use it. When something described above is missing, one of these is why:

Audit Log is not in the left nav. Your administrator role does not carry audit.view. The seeded Developer role carries it; a custom role can withhold it.Older events are gone. The Account's plan sets how long events are kept; export before the retention window closes.Identity activity is empty. End-user events are recorded per Environment as people sign in and act; an Environment with no traffic has none.
Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.