Audit Log page

Prev Next

Find and view actions taken by all users.

Option definitions

Option

Definition

Purge

Removes entries from the Audit Log based on user-specified age. This action deletes all Audit Log entries older than the specified age.

Show/Hide Filter

Shows or hides the filter options.

Preset

The Preset drop-down list allows you to filter which Audit Log entries to display based on predefined criteria, including:

  • Failed — Displays only failed actions recorded in the Audit Log.

  • Last Hour — Displays all actions recorded in the last hour.

  • Last day— Displays all actions recorded in the last day.

  • Last week — Displays all actions recorded in the last week.

  • Last month — Displays all actions recorded in the last month.

  • Last quarter — Displays all actions recorded in the last quarter.

  • Last year — Displays all actions recorded in the last year.

  • No Filter — Displays all actions recorded since the last time the Audit Log was purged.

Quick find

Enter a search term to filter the log entries by the search results. Click Apply to perform the search.

Clear

Deselects the Quick find text entry box.

Actions

Specifies the actions that you can perform on the Audit Log, including:

  • Choose Columns — Opens the Select the Columns to Display page. Use this option to select the columns of data to be displayed on the Audit Log page.

  • Export — Opens the Export page. Use this option to specify the format and the package of the files to be exported. You can save or email the exported Audit Log.



Column header definitions

Use these column headers to filter the Audit Log.

Column header

Definition

Action

Specifies the action the user attempted to take.

Completion Time

Specifies the time (on the ePO - On-prem server) the action was completed.

Details

Specifies further information about the action, if available.

Priority

Specifies the importance of the action determined by Trellix.

Start Time

Specifies the time (on the ePO - On-prem server) that the action began.

Success

Specifies whether the action succeeded.

User Name

Specifies the ePO - On-prem user name of the account that attempted to take the action. The user name is unavailable for some actions, for example, failed logon attempts.