View the audit log
You can use the audit log to view and export records of administrator actions in your organization.
Audit log entries are retained in the Aurora Endpoint Security console for one year before being deleted. To retain audit log entries for a longer period, export the records to a CSV file or forward events to a SIEM solution or syslog server. For more information, see Aurora Endpoint Security syslog forwarding.
Note:
You can export a maximum of 50,000 records at once.
- Sign in to the Aurora Endpoint Security console.
- Click .
- Optional: In the filter fields, specify your filter criteria.
- Optional: Export the results to a CSV file:
- Click
.
- Select the scope of the export.
- Click Export.
- Click