Protect records each audit event as an Action Title × Platform Section pair. Common events include: Connected System, Created Saved View Action, Created Shared Device Saved View, Created Team Device Saved View, Created User, Enabled Vitals, Registered Multi-Tenant Integration, Saved Dynamic Column, and Saved Logic Engine Configuration. The other categories below are grouped by the platform area that produces them; exact Action Title strings can vary by release.
How to read this page
Each event in the live Audit Log has:
The categories below correspond to the Platform Section column.
Authentication
User session and credential events.User management
Changes to platform users, roles, and teams. Platform Section:User Management.
Verified live (Action Title strings as displayed in the Audit Log):
Settings
Tenant-wide configuration changes. Multiple Platform Sections capture different setting areas: Verified live (Action Title × Platform Section pairs as displayed in the Audit Log):
Other events in this area:
Integrations & Vitals
Lifecycle and configuration of connected tools. Platform Sections:Integrations and Vitals.
Verified live (Action Title × Platform Section pairs as displayed in the Audit Log):
Other events in this area:
Actions & automations
Action Center lifecycle. Platform Section:Saved View Actions (the underlying name reflects Actions being scoped to saved views).
Verified live:
Other events in this area:
Automation executions (each fire of an email / ticket / webhook) appear primarily in the per-Action Automation Log (right panel of Action Center), not the global Audit Log. The Audit Log captures Action lifecycle events; the Automation Log captures fire events.
Saved views & exports
Platform Section:Saved Views.
Protect distinguishes Shared, Team, and Private saved views via separate Action Titles:
Other events in this area:
Devices & inventory
Devices themselves are largely managed via integrations; operational events on devices are sparse.API & access
Reporting
Events from the Reporting surface.Filtering and export
The Audit Log grid uses plain-text search across visible columns — it is not the query language used elsewhere. For structured filtering, export the log and process externally, or pull via the API. For SIEM ingest workflows, see Settings → Audit Log → Export.Cross-references
Settings → Audit Log
The live audit log surface
Access Control
Who sees the audit log
Role Permissions
Audit Log permission by role
Error Codes
Errors that surface in the log
Webhook Payload
Automation fired — webhook
API Reference
Programmatic audit log access