Loading...

Review a System's Audit Log

Inspect a system's recorded activity, read event context, and narrow the timeline with search and filters.

On this page
  1. Before you begin
  2. Open the system's audit history
  3. Read an audit event
  4. Narrow the timeline
  5. Use the timeline for the right review question
  6. Next steps

When you review a system, you often need to know who or what acted, what happened, and when. The System Audit Log presents recorded events for one system in a readable timeline, giving you traceability for investigation, reporting, and oversight. Start with the Recent activity summary, then open the full history to inspect and filter its events.

Before you begin

Sign in to Model Monster and open a system you can access. Audit history is available for systems with or without a released version.

Open the system's audit history

  1. Select Systems, then open the system you want to review.
  2. Select Overview and find Recent activity.

Recent activity on the SRE Agent Overview with several demo events, a total count, and Open full audit log

Recent activity gives you a compact view of the latest recorded events. Use it to orient yourself before moving into the full history.

  1. Select Open full audit log.

Populated System Audit Log for SRE Agent with search, actor and action filters, result count, and demo event rows

The System Audit Log page shows search and filter controls, a count of matching events, and the timeline ordered with the newest event first.

Read an audit event

Each event is a readable summary of an action and its available context. Start at the top of the row, then work through its details.

SRE Agent events showing labels, Marcellus actor details, revision and version context, badges, and timestamps

Context varies by event. Details generally include:

  1. Action and event. An action badge such as Updated or Created tells you the general kind of change. The event label adds context, with examples such as Policy Change, Review Submitted, or Review Cancelled. Available labels depend on the events recorded for the system.
  2. Affected object. The object type and summary describe what happened. Target identifies the policy, version, system, or other object involved.
  3. Actor. Actor identifies the person associated with the event. When an event has no person to display, the actor can appear as System.
  4. System context. The row includes the system name and its visible identifier, labeled System UID. It may also include Revision or Version when that context applies to the event.
  5. Timestamp. Events show a timestamp in YYYY-MM-DD HH:mm:ss format. Use the displayed timestamp when comparing activity.

The System badge confirms that the event belongs to the current system's history. Together, these fields help you answer what changed, who or what acted, what was affected, and when it occurred.

Narrow the timeline

Use search and filters to focus the timeline on the events relevant to your review question.

  1. Enter a person, event, target, or summary term in Search audit logs.
  2. To focus on one person, open All actors and select an actor. The available choices come from this system's event history.

Open All actors selector showing All actors and the publication-safe Marcellus demo account

  1. To focus on a kind of action, open All actions and select an available action.

Open All actions menu showing All actions and Updated from the SRE Agent demo history

Search, actor, and action controls work together. As you change them, the display updates to reflect the current result set.

SRE Agent audit timeline with Policy in Search audit logs, Updated active, and Showing 2 of 20 system events

Select Clear search audit logs to remove the text query while keeping your actor and action choices. To restore the full timeline, return those selectors to All actors and All actions.

Use the timeline for the right review question

Use the System Audit Log when your question concerns recorded system events: who or what acted, what happened, which target or version context was involved, and when. This focused history supports investigation, traceability, reporting, and oversight of supported system changes and governance actions.

For a version-focused question, use System Versions instead. The audit log presents recorded events, while System Versions tracks version status, metadata, and historical versions.

Next steps