Platform administration

Review audit logs and security activity

Filter Secorvia audit logs by organization and action, and distinguish audit records from activity and security-event views.

Reviewed

Before you start

Use a platform administrator account with access to the records under review. Audit availability is limited to supported recorded events.

Set the organization scope

Open Audit Logs and use Filter by organization ID. Record the relevant tenant identifier when investigating an administrative change.

Narrow the action

Use All actions to choose the type of action under investigation. Clear filters if the expected entry is absent; an empty filtered list is not proof that no activity occurred.

Correlate the relevant records

Use the separate Activity and Security Events views when needed, keeping the organization, actor, and event time aligned. Finding-level operational actions such as assignment, suppression, and comments can also be reviewed in the finding’s Activity timeline.

Preserve context in your review

Record the relevant identifiers and timestamps through your approved investigation process. Avoid claiming every page view or possible action is audited; interpret only the event coverage actually provided by your deployment.

Where you are now

You can locate supported audit events in the right tenant and cross-check them with related operational records.

WHEN SOMETHING LOOKS OFF

A few things to check

No entries match the filters

Clear action and organization filters, then verify the event is one the deployment records.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia