Skip to navigation

View audit logs

Platform 6.6.0+

Itential Platform writes an audit log recording who performed create, update, delete, and similar actions against resources, and when.

The audit log records only that an action occurred and which resource it targeted. It doesn’t log the full resource body or which specific fields changed. For example, for workflows the log tells you that a workflow named restartNetworkDevices in project Network Control was updated by admin@itential at a given time, but not what changed inside the workflow.

Audit log format

Each line in the audit log is a compact JSON object:

{
"username": "admin",
"time": "2026-09-22T17:32:04.252Z",
"action": "update",
"resource": "workflow",
"identifier": { "id": "074bb62e-8021-4dfe-96e9-0265295f228e", "name": "parent", "project": "Network Control" },
"source": "WorkflowBuilder:1a1e40bf…"
}
FieldDescription
usernameThe authenticated user who performed the action
timeThe event timestamp, in ISO 8601 format
actionOne of create, import, update, delete, stop, start, or restart
resourceThe type of resource acted on, such as workflow or group
identifierThe resource’s human-readable identifying details. Includes name and, where applicable, additional context such as its project

Actions and resources logged

ResourceActions loggedAdditional identifying details logged
Workflow (workflow)create, update, deleteName, project
Account (account)import, updateUsername, provenance
Group (group)create, import, update, deleteName, provenance
Role (role)create, update, deleteName, provenance
Group mapping (groupMapping)create, update, deleteExternal group name, provenance
SSO configuration (ssoConfig)create, update, deleteName
Profile (iapProfile)create, update, deleteProfile ID
Service instance for an adapter or application (service)start, stop, restartName, model, type
Integration model (integrationModel)import, deleteModel name and version
OAuth client (oauthClient)create, update, deleteName

provenance identifies where an account, group, or role originates. For example Local AAA or the name of a connected identity provider such as Azure Entra ID.

What isn’t logged

  • Full resource bodies - The audit log never includes the complete document for a resource, only its identifying details.
  • Field-level changes - The log records that a resource was created, updated, or deleted, not which specific fields or values changed.
  • Sensitive data - Passwords, tokens, and other credential material are never written to the audit log.
  • Workflow execution - Running a workflow, providing manual task inputs, or reverting a workflow run are operator actions and aren’t captured here. The audit log tracks who built or changed a workflow, not who ran it.

Configuration

The audit log is written to its own file, separate from Platform’s general log and web server access log.

Log rotation for the audit log follows the same size- and count-based approach as Platform’s other logs. For more information, see Log rotation. When the current file reaches the configured maximum size, it rotates, and the oldest file is removed once the configured file count is exceeded.

Query audit logs

Because the audit log is JSON, one entry per line, you can search it the same way as other Platform logs. For example, to find every action a specific user took:

grep '"username":"admin@itential"' audit.log

Or every delete action logged for a given resource type:

grep '"resource":"workflow"' audit.log | grep '"action":"delete"'

The format also works with third-party log aggregation and SIEM tools that support standard JSON logs.