> This page is for Itential Platform On-Prem, version 6 (default).
> For other versions, use one of these documentation indexes:
> - 6 (default): https://docs.itential.com/itential-platform/6/llms.txt
> - 2023.2: https://docs.itential.com/itential-platform/2023-2/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# View audit logs

> Understand the audit log format, what actions are captured, and how to configure and query Platform's audit log.

Platform 6.6.0+

Itential Platform writes an audit log recording who performed create, update, delete, and similar actions against resources, and when.

The audit log records only that an action occurred and which resource it targeted. It doesn't log the full resource body or which specific fields changed. For example, for workflows the log tells you that a workflow named `restartNetworkDevices` in project `Network Control` was updated by `admin@itential` at a given time, but not what changed inside the workflow.

## Audit log format

Each line in the audit log is a compact JSON object:

```json
{
  "username": "admin",
  "time": "2026-09-22T17:32:04.252Z",
  "action": "update",
  "resource": "workflow",
  "identifier": { "id": "074bb62e-8021-4dfe-96e9-0265295f228e", "name": "parent", "project": "Network Control" },
  "source": "WorkflowBuilder:1a1e40bf…"
}
```

| Field        | Description                                                                                                                        |
| ------------ | ---------------------------------------------------------------------------------------------------------------------------------- |
| `username`   | The authenticated user who performed the action                                                                                    |
| `time`       | The event timestamp, in ISO 8601 format                                                                                            |
| `action`     | One of `create`, `import`, `update`, `delete`, `stop`, `start`, or `restart`                                                       |
| `resource`   | The type of resource acted on, such as `workflow` or `group`                                                                       |
| `identifier` | The resource's human-readable identifying details. Includes `name` and, where applicable, additional context such as its `project` |

## Actions and resources logged

| Resource                                                   | Actions logged                         | Additional identifying details logged |
| ---------------------------------------------------------- | -------------------------------------- | ------------------------------------- |
| Workflow (`workflow`)                                      | `create`, `update`, `delete`           | Name, project                         |
| Account (`account`)                                        | `import`, `update`                     | Username, provenance                  |
| Group (`group`)                                            | `create`, `import`, `update`, `delete` | Name, provenance                      |
| Role (`role`)                                              | `create`, `update`, `delete`           | Name, provenance                      |
| Group mapping (`groupMapping`)                             | `create`, `update`, `delete`           | External group name, provenance       |
| SSO configuration (`ssoConfig`)                            | `create`, `update`, `delete`           | Name                                  |
| Profile (`iapProfile`)                                     | `create`, `update`, `delete`           | Profile ID                            |
| Service instance for an adapter or application (`service`) | `start`, `stop`, `restart`             | Name, model, type                     |
| Integration model (`integrationModel`)                     | `import`, `delete`                     | Model name and version                |
| OAuth client (`oauthClient`)                               | `create`, `update`, `delete`           | Name                                  |

`provenance` identifies where an account, group, or role originates. For example `Local AAA` or the name of a connected identity provider such as Azure Entra ID.

## What isn't logged

* **Full resource bodies** - The audit log never includes the complete document for a resource, only its identifying details.
* **Field-level changes** - The log records that a resource was created, updated, or deleted, not which specific fields or values changed.
* **Sensitive data** - Passwords, tokens, and other credential material are never written to the audit log.
* **Workflow execution** - Running a workflow, providing manual task inputs, or reverting a workflow run are operator actions and aren't captured here. The audit log tracks who built or changed a workflow, not who ran it.

## Configuration

The audit log is written to its own file, separate from Platform's [general log](/itential-platform/monitor/log/overview) and [web server access log](/itential-platform/monitor/log/view-web-server-access-logs).

Log rotation for the audit log follows the same size- and count-based approach as Platform's other logs. For more information, see [Log rotation](/itential-platform/monitor/log/overview#log-rotation). When the current file reaches the configured maximum size, it rotates, and the oldest file is removed once the configured file count is exceeded.

## Query audit logs

Because the audit log is JSON, one entry per line, you can search it the same way as other Platform logs. For example, to find every action a specific user took:

```bash
grep '"username":"admin@itential"' audit.log
```

Or every delete action logged for a given resource type:

```bash
grep '"resource":"workflow"' audit.log | grep '"action":"delete"'
```

The format also works with third-party log aggregation and SIEM tools that support standard JSON logs.