View audit logs
Itential Platform writes an audit log recording who performed create, update, delete, and similar actions against resources, and when.
The audit log records only that an action occurred and which resource it targeted. It doesn’t log the full resource body or which specific fields changed. For example, for workflows the log tells you that a workflow named restartNetworkDevices in project Network Control was updated by admin@itential at a given time, but not what changed inside the workflow.
Audit log format
Each line in the audit log is a compact JSON object:
Actions and resources logged
provenance identifies where an account, group, or role originates. For example Local AAA or the name of a connected identity provider such as Azure Entra ID.
What isn’t logged
- Full resource bodies - The audit log never includes the complete document for a resource, only its identifying details.
- Field-level changes - The log records that a resource was created, updated, or deleted, not which specific fields or values changed.
- Sensitive data - Passwords, tokens, and other credential material are never written to the audit log.
- Workflow execution - Running a workflow, providing manual task inputs, or reverting a workflow run are operator actions and aren’t captured here. The audit log tracks who built or changed a workflow, not who ran it.
Configuration
The audit log is written to its own file, separate from Platform’s general log and web server access log.
Log rotation for the audit log follows the same size- and count-based approach as Platform’s other logs. For more information, see Log rotation. When the current file reaches the configured maximum size, it rotates, and the oldest file is removed once the configured file count is exceeded.
Query audit logs
Because the audit log is JSON, one entry per line, you can search it the same way as other Platform logs. For example, to find every action a specific user took:
Or every delete action logged for a given resource type:
The format also works with third-party log aggregation and SIEM tools that support standard JSON logs.