Action audit

Reading Time: < 1 minute

When to use

Audit Log is needed to control changes, check operator actions and post-incident analysis.

What the audit record contains

  • Event time.
  • Action type (action).
  • Performer (actorType, actorId).
  • Target resource (resourceType, resourceId).
  • IP address and metadata (when available).

Steps

  1. Open Audit within the desired cluster.
  2. View records by period and page.
  3. Map actions to incidents, alerts, and operational changes.

What to check

  • Critical actions (terminal, acknowledge, access changes) have a clear chain of responsibility.
  • There are no unexplained actions outside the agreed change windows.
  • The IP and context of the events are consistent with the access policy.
Scroll to Top