Using Audit Logs
Audit Logs give you a record of activity on your Qevlar platform - who did what, when, from where, and the result. Use them for security reviews, investigations, and to support compliance requirements like SOC 2 and ISO 27001.
Who can access Audit Logs
Audit Logs are available to admins within your organization. You'll only see your own organization's activity. Your logs are private to your organization and are never visible to any other customer.
Where to find them
Go to Settings → Audit logs tab
Every entry captures:
- Time — when the action happened
- Actor — the user (name and email) or system that performed the action
- Action — what happened (e.g. a sign-in, a user change, a configuration update)
- Resource — what the action affected
- Outcome — success or failure, where recorded
- Source IP — where the action came from (for user actions)
For changes, the entry also records a before → after view so you can see exactly what was modified.
What activity is captured
Audit Logs currently record:
- Authentication — sign-ins, sign-outs, and failed sign-in attempts
- User & access management — users created or updated (including role and sign-in method changes) and invitations removed
- Data source / connector configuration — changes to your connected sources
- Investigation feedback — edits to analyst feedback, including the verdict and comment
Searching and filtering
- Search by actor, action, or resource using the search bar.
- Filter by outcome (success / failure), resource, and a custom date range.
- Filters combine, so you can narrow to, for example, all failed sign-ins in the last 7 days.
Viewing details of a change
Open any entry to see its full detail, including the before → after values. For example, a role change shows the previous and new role; a feedback edit shows the previous and new verdict and comment.
Exporting to CSV
Select your filters, then use the download button to export the current view as a CSV. The export includes the full set of fields for each entry, so you can archive it or load it into your own security tooling.