List view
Quick Start
Quick Start
User Guide
User Guide
Policies & GuardRails
Policies & GuardRails
Witness Anywhere: Remote Device Security
Witness Anywhere: Remote Device Security
Witness Attack
Witness Attack
Administrator Guide
Administrator Guide
Audit Logs
Audit Logs capture WitnessAI object creations, deletions, updates, and User logins. Full details of “before” and “after” are included.
Audit logs can be viewed, searched, filtered, and exported in JSON format.
Only Users with “User Admin” roles and above can access Audit Logs. Currently this only applies to “User Admin” and “Super Admin” roles. Only “Super Admin” roles can view actions by “VIP” Users.
Navigation
Access the Audit Logs by clicking on the Settings menu or icon.
Audit Logs are below the System menu
Log Filters
Time Range Filter
- Allows precise temporal scoping of log entries
- Multiple selection methods:
- Preset ranges (e.g., last 3 days)
- Custom date and time range selection
- Interactive update button to apply selected time range
- Supports granular filtering down to specific hours and dates
- Critical for narrowing down log investigations to specific time periods
User Filter
- Filter by user email
- Display user details including:
- Name
- Role (e.g., Super Admin)
- Email address
Action Type Filters
Action Type filter restricts view to only the action type chosen.
- Created
- Deleted
- Login
- Updated
Object Type Filters
Object Types filter restricts view to only the object type chosen.
- Catalog items
- Lists
- Policies
- Orders
- User changes
- Groups
Viewing Audit Logs
Columns
- User action
- Action type
- Created
- Deleted
- Login
- Updated
- Object modified
- Object type
- Status (success/failure)
- Timestamp
- Note: Columns are currently not sortable
Detail View
- Displays detailed change information
- Change visualization:
- Minus (-) indicates old value
- Plus (+) indicates new value
- Shows version numbers for tracked changes
Pagination
- Page size options: 25, 50, 100 items
- Total action count display
- Navigation controls between pages
Exporting Audit Logs
Selecting Logs for Export
Exporting all logs in your filtered view
Exporting individual records
Exporting multiple records
Selection state persists across pages
Exporting all records on current page
Exporting all records on selected pages
Sending Audit Logs to SIEMs
The Audit Logs feature supports forwarding to Security Information and Event Management (SIEM) systems, enabling comprehensive security monitoring and compliance reporting.
Configure Audit Log forwarding in the SIEM Settings, by clicking the checkbox next to “Include Audit Logs”.