Skip to main content
The Audit Log records every meaningful action across your Protect tenant. This page is the structured catalogue of events — useful for SIEM mapping, audit deliverables, and alert design.
Protect records each audit event as an Action Title × Platform Section pair. Common events include: Connected System, Created Saved View Action, Created Shared Device Saved View, Created Team Device Saved View, Created User, Enabled Vitals, Registered Multi-Tenant Integration, Saved Dynamic Column, and Saved Logic Engine Configuration. The other categories below are grouped by the platform area that produces them; exact Action Title strings can vary by release.
For the page that surfaces these events in the product, columns, filtering, and retention behaviour, see Settings → Audit Log.

How to read this page

Each event in the live Audit Log has: The categories below correspond to the Platform Section column.

Authentication

User session and credential events.

User management

Changes to platform users, roles, and teams. Platform Section: User Management. Verified live (Action Title strings as displayed in the Audit Log):

Settings

Tenant-wide configuration changes. Multiple Platform Sections capture different setting areas: Verified live (Action Title × Platform Section pairs as displayed in the Audit Log): Other events in this area:

Integrations & Vitals

Lifecycle and configuration of connected tools. Platform Sections: Integrations and Vitals. Verified live (Action Title × Platform Section pairs as displayed in the Audit Log): Other events in this area:

Actions & automations

Action Center lifecycle. Platform Section: Saved View Actions (the underlying name reflects Actions being scoped to saved views). Verified live: Other events in this area: Automation executions (each fire of an email / ticket / webhook) appear primarily in the per-Action Automation Log (right panel of Action Center), not the global Audit Log. The Audit Log captures Action lifecycle events; the Automation Log captures fire events.

Saved views & exports

Platform Section: Saved Views. Protect distinguishes Shared, Team, and Private saved views via separate Action Titles: Other events in this area:

Devices & inventory

Devices themselves are largely managed via integrations; operational events on devices are sparse.

API & access

Reporting

Events from the Reporting surface.

Filtering and export

The Audit Log grid uses plain-text search across visible columns — it is not the query language used elsewhere. For structured filtering, export the log and process externally, or pull via the API. For SIEM ingest workflows, see Settings → Audit Log → Export.

Cross-references

Settings → Audit Log

The live audit log surface

Access Control

Who sees the audit log

Role Permissions

Audit Log permission by role

Error Codes

Errors that surface in the log

Webhook Payload

Automation fired — webhook

API Reference

Programmatic audit log access