Skip to main content

Audit logs

Cloud Intelligence provides audit logs to help you respond to security events, internal investigations, and compliance obligations. Audit logs are a chronological record of events across all areas of Cloud Intelligence, capturing the who, what, when, where, and why of each recorded action.

Audit logs are retained indefinitely. The audit data trail remains accessible within Cloud Intelligence as long as your organization remains a customer.

Note

Actions performed through the DoiT API and the DoiT CLI are recorded. Actions performed in the Console are recorded only when they're handled by a backend service that emits audit events, and coverage of Console actions isn't yet complete. For example, deleting a Cloud Analytics alert in the Console is recorded, but creating one is not.

When you investigate an incident, treat the absence of an audit event as inconclusive: it doesn't prove that the action didn't take place.

Required permissions​

To access audit logs, your DoiT account must have the Admin role.

Access audit logs​

To access audit logs, sign in to the DoiT console, select the gear icon () from the top navigation bar, and select Audit logs.

Audit logs menu option

By default, the audit log displays the events from the last 7 days, sorted by time from newest to oldest. The following information is displayed for each event.

FieldDescription
TimeThe date and time the action occurred. The timestamp is in ISO 8601 format (UTC). Hover over the event ID to view the full identifier. Use the Copy icon to copy it to your clipboard.
Event nameA descriptive label for the specific event that occurred, such as Cloud Analytics/Report/Create. Use this field to differentiate between event types that occur with the same area and share the same action.
ActorThe actor represents the entity that performed the action. For actions performed by a user, a username is displayed (as defined in Cloud Intelligence). For system or service-account actions, the actor displays the name or identifier of the system component or service account. Hover over a non-user actor to see whether the action was performed by a service account or by the system. If no identifying information is available for a non-user actor, the label DCI is displayed.
DCI AreaThe area of Cloud Intelligence where the event occurred, for example, Alerts, Anomalies, CloudFlow, Cloud Diagrams, Commitment Manager, and so on.
TargetThe human-readable resource name where the event took place.
Target IDThe unique identifier of the target resource. Together with Target, it identifies exactly which resource was changed (for example, a specific budget, alert, or dashboard). You can filter by Target ID to see all events for that resource.
ActionThe action that occurred. Values are either Create, Update, or Delete.

View audit event details​

To view an audit event's details, expand the event whose details you want to view. The event details are generated in a comparison window that displays a before and after snapshot, allowing you to see the exact changes made during the event.

Audit log comparison window

Filter audit logs​

Instead of searching through audit logs, you can use filters, enabling you to quickly and easily focus on the events you are interested in. You can filter audit logs:

  • Based on a time range. You can choose a predefined range or specify a custom one. Setting the time range to Default restores the default setting.

Filter audit logs by time range

  • By fields: event name, DCI area, action, actor, target, and target ID. You can use regular expressions for pattern-based searches across all fields. Filtering by target ID is useful to trace all events for a specific resource.

  • Add individual events to a filter to build a custom search based on specific event criteria. Hover over the event and select + to add the event to the filter.

For example, you might want to see all Delete actions performed by a specific actor over the last 7 days.

Filter example

Allocation events​

When you create, update, or delete an allocation, Cloud Intelligence logs an audit event under the Cloud Analytics DCI area.

The following event names are logged:

Event nameDescription
cloud-analytics-allocation.createdAn allocation was created.
cloud-analytics-allocation.updatedAn existing allocation was updated.
cloud-analytics-allocation.deletedAn allocation was deleted.

When you expand an allocation event, the before-and-after comparison shows the changed fields, such as the allocation name, description, type, formula, filters, and member rules.

Sharing an allocation is tracked under a separate permissions.updated event, not the allocation events listed above.

Cloud Analytics report events​

When you create, update, or delete a Cloud Analytics report, Cloud Intelligence logs an audit event under the Cloud Analytics DCI area. These events are recorded for actions performed in the Console, through the DoiT API, and through the DoiT CLI.

The following event names are logged:

Event nameDescription
cloud-analytics-report.createdA report was created.
cloud-analytics-report.updatedAn existing report was updated.
cloud-analytics-report.deletedA report was deleted.

When you expand a report event, the before-and-after comparison shows the changed fields, such as the report name, description, draft status, folder, and configuration.

Commitment Manager events​

When you delete a commitment, change its adjustments, or close one of its periods, Cloud Intelligence logs an audit event under the Commitment Manager DCI area. Deleting a commitment is logged with a Delete action. Adjustment changes and period closes are logged with an Update action, because each change is an update to the parent commitment resource.

The following event names are logged:

Event nameDescription
commitment.deletedA commitment was deleted.
commitment.adjustment.addedA new adjustment was added to a commitment period.
commitment.adjustment.modifiedAn existing adjustment in a commitment period was changed.
commitment.adjustment.removedAn adjustment was removed from a commitment period.
commitment.period.closedA commitment period was closed, either manually or automatically 30 days after it ended.

When you expand an adjustment event, the before-and-after comparison labels each changed field with a path in the form adjustments[period][position].field. For both numbers, counting starts at 0, not 1. For example, adjustments[0][1].amount means the amount on the second adjustment in the first commitment period. If the before value is -245000 and the after value is -240000, that adjustment's dollar amount was updated from −$245,000 to −$240,000.