Platform administration
Review audit logs and security activity
Filter Secorvia audit logs by organization and action, and distinguish audit records from activity and security-event views.
Reviewed
Before you start
Use a platform administrator account with access to the records under review. Audit availability is limited to supported recorded events.
Set the organization scope
Open Audit Logs and use Filter by organization ID. Record the relevant tenant identifier when investigating an administrative change.
Narrow the action
Use All actions to choose the type of action under investigation. Clear filters if the expected entry is absent; an empty filtered list is not proof that no activity occurred.
Correlate the relevant records
Use the separate Activity and Security Events views when needed, keeping the organization, actor, and event time aligned. Finding-level operational actions such as assignment, suppression, and comments can also be reviewed in the finding’s Activity timeline.
Preserve context in your review
Record the relevant identifiers and timestamps through your approved investigation process. Avoid claiming every page view or possible action is audited; interpret only the event coverage actually provided by your deployment.
Where you are now
You can locate supported audit events in the right tenant and cross-check them with related operational records.
WHEN SOMETHING LOOKS OFF
A few things to check
No entries match the filters
Clear action and organization filters, then verify the event is one the deployment records.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.