Activity and event logs

Prev Next

This article describes how to use the activity and event logs in your Secure Edge Portal account.

Activity logs

Activity logs record user-initiated actions that modify resources in the Secure Edge Portal, such as organization settings, user accounts, roles, nodes, network services, and more. They provide detailed information on who modified resources, what was changed, and when. Activity logs are retained for one year.

Logged activities

The activity log captures the following actions:

Activity typeActivity logged

Organization

Organization create, update, and delete
Session, password, tokens (verify email, forgot password temp tokens), service, network, and firewall policy updates
VLAN enable and disable
Standalone mode enable and disable
Two-factor authentication enable and disable
API access enable and disable
Node upgrade configuration stable, alpha, beta, off
Branding update
Branding enable and disable
Webhook access enable and disable
Service listener enable and disable
Child organization enable and disable
Support capability enable and disable
Hardware monitoring enable and disable

User

User login and logout
User forgot password (requesting a link to change password)
Email verified
Change or reset password
User two-factor authentication login enable and disable
User alert create, update, and delete
User webhook create, verified, update, and delete

User Role

User role create, update, and delete

User Account

User account locked or unlocked

Node

Node create, update, delete, and reboot
Node diagnostic data initiated and canceled
Node statistics config update
Node upgrade config update
CLI node timeserver set and unset
CLI node nameserver set and unset
CLI node WAN IP set and unset
CLI node WAN VLAN set and unset
CLI node MGMT IP set and unset
Set node resource limit
Download default SSH
Hardware monitoring config update
Duplicate address detection config update

Node Network

Node network create, update, delete, marked for delete, connect, disconnect
Node network firewall update
Node network enable and disable discovery
Node network firewall counter reset

Custom Security Policy

Security policy create, update, and delete

Service

Service create, update, delete, marked for delete, and restart
Service listener create, update, delete

Service Secret

Secret create, update, and delete

Serial number

Serial number create, delete, and move

SSH Key

SSH key create and delete

API Access Key

API access key create and delete

Event Log Download

Event download request, deleted, and done

Activity Log Download

Activity download request, deleted, and done

Viewing activity

If you have an Admin role in your company’s account, you can see the Recent Activity panel on the portal dashboard, which displays the 25 most recent activities.

Select More Activity to open the Activity page, where you can filter by activity and date.

Download an activity log

Admin users can download a historical activity log. Follow these steps to request the activity report and download it:

  1. From the bottom of the Secure Edge Portal left menu, select download icon > Download Activity.
  2. The Download Activity page opens. Use the filters to specify the report scope. If you don’t specify an org, the default is your organization and child organizations. If you don’t specify a start and end date, the default date range is the past 180 days, with a maximum of 10,000 records.
  3. After setting the report scope, select the Request Report icon. You can request up to 10 reports per day.
    The status will be PENDING until the request has been completed.
  4. When the activity report request is ready, the status changes to COMPLETED. Select the download icon to retrieve the report. Reports are automatically deleted after 24 hours.

Event logs

Event logs capture system-generated events related to node operations, network connections, services, and webhooks. Event logs are retained for 90 days.

Logged events

The events log captures the following events:

Event TypeEvents Logged

Node

Node status ALIVE, UNREACHABLE, and REBOOT
Node IP address change PUBLIC IP and PRIVATE IP
Node upgrade status SUCCESSFUL, FAILED, ENABLED, and DISABLED
Node metrics for CPU, memory, or file system usage rises above 80%

Node network

Remote network connection status CONNECTED and TERMINATED

Service

Service status HEALTHY, UNHEALTHY, and TERMINATED

Webhook

Webhook notification status FAILING, RECOVERED, FAILED

Viewing events

Admin users can access events logs from the Events option in the Secure Edge Portal left menu.  Use the filter options at the top of the screen to filter events by organization, node, source, or date.

Download an event log

You must have an Admin role in your company's Secure Edge Portal account to download a historical event log. Follow these steps to request the event report and download it:

  1. On the bottom of Secure Edge Portal left menu, select the download icon > Download Events.
  2. The Download Events page opens. Use the filters to specify the report scope. If you don’t specify the source, the default is all nodes, networks, services, and webhooks. If you don’t specify an org, the default is your organization and child organizations. If you don’t specify a start and end date, the default date range is the past 90 days, with a maximum of 10,000 records.

  3. After setting the report scope, select the Request Report icon. You can request up to 10 reports per day.
    The status will be PENDING until the request has been completed.
  4. When the event report request is ready, the status changes to COMPLETED. Select the download icon to retrieve the report. Reports are automatically deleted after 24 hours.