Getting Started

Endpoints

Patch Management

Vulnerability Management

Software Deployment & IT Assets

Automation & Remote Desktop

Real-Time Reports & Alerts

Account Access & Management

SSO Authentication

Security Concerns

Need Help?

Action1 5 Documentation 5 Audit Trail

Audit Trail

The Audit Trail view allows you to track how the product is being utilized in your organization, including user activities and configuration changes.

NOTE: To work with the audit trail, Action1 users need a role with at least the View Audit Trail permission.

For example, you can identify who viewed reports, when a new user was added to an organization, get information about downloaded agents, remote desktop sessions, created and removed packages, and other operations. The ability to export the audit trail can help if you need this data for compliance review.

NOTE: Currently, only Export to CSV file is supported. The file is named using the current date/timestamp.

Audit Trail view with Export button.

You can:

  • Use Search to locate the required records.
  • Use filters to examine only specific events and users (by default, all users and all events except GET are included).
Default Audit Trail Events filter settings exclude GET events.
  • Retrieve the records for a certain period of time:
Date and Time filter for the Audit Trail view.

Besides, you can work with the Audit Trail using the API requests.

Example

To export the whole audit trail (including GET operations) for the past month:

  1. Use the Date/Time filter to select the required start and end date/time for the records.
  2. Use the Events filter to select all event records, including GET.
  3. With the User filter, select the records related to the required Action1 users.
  4. Review the resulting record set and then click Export.

Alternatively, you can use this API request.

Agent Log Files

The Action1 agent log files are located:

  • on Windows endpoints – under C:\Windows\Action1\logs\
  • on Mac endpoints – under /var/log/action1/
  • on Linux endpoints – under /var/log/action1/

They are named with the timestamps.