Viewing audit information

Audit events are recorded for security and compliance purposes. You can view audit events in the built-in log viewer.

About this task

App Connect can generate audit events for actions and when changes are made to your service instance so that you can see who did what and when on your system. The following table lists the actions that trigger audit events.
Table 1. Actions that trigger audit events
Task Actions that trigger audit events
Developing an event-driven flow
  • Creating, updating, and deleting an integration flow
  • Starting and stopping an integration flow
  • Creating, updating, and deleting an account to connect to an application
Importing or exporting a flow
  • Importing and exporting an integration flow
  • Updating and deleting an integration flow
  • Creating or deleting an account to connect to an application
Creating an integration runtime
  • Creating (importing) and deleting a BAR file
  • Creating, updating, and deleting an integration runtime
  • Creating, updating, and deleting a configuration
Creating or updating a service instance
  • Creating and updating a service instance

Procedure

  1. To view audit events, open the Logs tab Icon that represents the Logs tab.
    The built-in log viewer lists information and audit messages.
  2. To filter messages for audit events only, click Filter Filter icon on the log viewer toolbar on the log viewer toolbar, then build a query that says log level equals audit.
    Screenshot of the build a query dialog box that shows a query of log level equals audit
  3. To show the most recent audit events, select an appropriate value from the list on the log viewer toolbar.
    Screenshot shows that Last 24 hours is selected from the drop-down menu on the log viewer toolbar
    Alternatively, you can show events for a particular time period by using a filter. In the following example, the query shows all events between 9am and 5pm on a particular day.
    Screenshot shows a filter query with two conditions. The first condition sets event time after 9am on 8 December, and the second condition sets the event time before 5pm on 8 December.
    By default, timestamps are shown in Coordinated Universal Time (UTC). To set timestamps to your local time, click Change log settings Change log settings iconon the log viewer toolbar, then select Browser local time.
    Screenshot that shows the values for the Change log settings icon. A display time of UTC is selected.
  4. To search the logs that are visible on the page, click Search Search icon on the log viewer toolbar, then enter the value that you want to search for.
    The events are filtered as you type in the search field.
  5. To download the filtered logs as a JSON file, click Download Download logs icon on the log viewer toolbar.