Viewing the audit log

Plan requirement

Subscription Suite Professional or higher, Support Professional or higher
Access Admin

Who changed what, and when. The first place to look when something behaves differently and nobody knows why.

Read it

  1. Open Admin Center, then Account, then Logs, then Audit log.
  2. Filter by date, by person, or by what changed.
  3. Read the entries around when the behaviour changed.

Start from the date

"It started behaving oddly last Tuesday" is enough. Filter to that day and read what was changed; the answer is usually visible in a minute.

Far quicker than reading configuration, and it names the person who can explain it.

What it records

Changes to settings, roles, users, triggers and other configuration, with who made them. Administrative actions rather than ticket work.

What it does not

What agents did to tickets. That lives in the ticket's own history, which is a different place and a different question.

Three good uses

  • Diagnosis. What changed before this started.
  • Access review. Who has been granted what, and by whom.
  • Answering an auditor, where somebody needs evidence that changes are tracked.

It only helps if it goes back far enough

Retention is limited. For anything you may need to prove later, export it rather than relying on it still being there.

Read it after any incident

Before investigating the product. A surprising share of unexplained behaviour is a colleague's change that was never mentioned, and the log finds it without anybody having to admit anything.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.