View the audit log

You can use the audit log to view and export records of administrator actions in your organization.

Audit log entries are retained in the Aurora Endpoint Security console for one year before being deleted. To retain audit log entries for a longer period, export the records to a CSV file or forward events to a SIEM solution or syslog server. For more information, see Aurora Endpoint Security syslog forwarding.
Note:

You can export a maximum of 50,000 records at once.

  1. Sign in to the Aurora Endpoint Security console.
  2. Click Profile icon > Audit Log.
  3. Optional: In the filter fields, specify your filter criteria.
  4. Optional: Export the results to a CSV file:
    1. Click Export icon.
    2. Select the scope of the export.
    3. Click Export.