Reference

Operational logs and audit records

Understand the different questions answered by logs and audit records.

What these concepts mean

An operational log records service and request events. Use it to understand what happened while work ran or failed.

An audit record describes an important security, access, or administration event. Use it to understand who changed an important item and whether the action succeeded.

Operational log records after a search
The result shows the time, severity, service, message, and HTTP information together. Earlier development interface, captured 22 August 2026. Follow the current text for RC1. Open the full image.

Why they matter

The two records answer different questions. A log may show why a request failed. An audit record may show the earlier access or setting change that affected it.

Request, run, job, case, and item IDs can connect related records.

How they work together

  1. Start with the person, tenant, time, message, and best available ID.
  2. Find the work state in Operations.
  3. Read the matching log events in time order.
  4. Check audit history when an administration change may be involved.
  5. Compare the first failure with the change time.
Audit history with successful administration changes
Each row shows who acted, what changed, and whether it succeeded. Earlier development interface, captured 22 August 2026. Follow the current text for RC1. Open the full image.

Who manages them

Operators search operational logs. Auditors and authorised administrators review audit records. Access rules decide who may view each record type.

Both record types may contain personal or security information. Protect exports under your organisation's rules.

Return to the glossary.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot