Audit log
The record of who did what on the appliance, with filters and export.
On this page
The audit log with export is part of Pro. On Community and Lite the sidebar has no Audit entry, and the address shows Audit log is part of ONEP Pro.
The Audit page, titled Audit log, is the appliance's record of who did what and when. It is a page of its own in the sidebar, not a Settings tab, and like Settings it is for administrators. Settings › Config history is a link to it.
What an event holds#
The table has these columns: Time, Severity, Category, Event, Resource, User, Status and Description. The Event column reads as a sentence, for example Signed in, Environment created or User role changed. Times are local, in the form 7 Oct 2026, 03:24.
The categories are System, Authentication, Security, Environment, Node (devices), Network, Worker (background tasks), Resource, Storage and Error.
The severities are Info, Warning, Error, Critical and Audit. Audit marks a deliberate record of a significant action. Status reads Success or Failed.
Choose a row to expand it. The expanded row lists every field of the event, with the event code and event name. Details shows the full record as text.
Find and export#
- Search events… searches the text of events.
- All categories and All severities filter by category and severity.
- More filters adds Actor (user), Resource type, Resource ID, From and To. Clear all filters resets them.
- Show 20, 50, 100 or 200 sets the page size. Previous and Next move between pages. The page shows the range and the total number of events.
- Refresh reloads the list. The list also refreshes by itself about every 15 seconds.
- Export CSV and Export JSON download every event that matches the active filters, not just the page on screen, up to 50,000 events. The file is named
onep-auditfollowed by the filters and the time. Export is recorded in the log as Audit log exported.
Coverage#
The log records sign-in activity, the life of environments and devices, and changes made by administrators: users, roles, password resets, lockout clears, two-factor and API token changes, network settings, remote access, AI settings, license uploads and diagnostic bundles. License uploads, both accepted and refused, are recorded with the edition, seats and expiry but never the license file itself. Where a change has a before and after, the event records both.