CUSTODY / GUIDE
УКР

Audit log

Inspect recorded events and their actors.

Step by step

  1. Open the log and apply the available filters.
  2. Check time, action type, resource identifier and actual actor.
  3. Open an available event detail and retain its reference for investigation.
  4. Continue to later pages if the event is not in the current set.
  5. With security-audit permission, choose List audit IP addresses. New since filters addresses first seen in retained history at or after the chosen UTC time.
  6. Copy an exact IP address into List actions from an IP address to investigate it. Refine the time, actor and action filters as needed.
  7. Audit retention shows the current policy version and latest cleanup batch. If Change audit retention is available, enter that version and 1–3650 days, review the values and confirm with your security key.

Related reading

Custody Platform · User documentation2026-09-22

Search documentation

Search stays within this guide. It does not request console data.