Audit Log
Monitor, filter, investigate, and export activity across your SikkerKey vault.
The Audit Log gives you a live, searchable history of activity in your vault. Use it to follow secret access, review security changes, investigate authentication events, and prepare records for compliance or incident review.
The dashboard updates the Audit Log as new events arrive, so your current view stays aligned with recent vault activity.
#What the Audit Log records
SikkerKey records events across secrets, machines, projects and applications, authentication, sessions, organization membership and SSO, AI agents, billing, webhooks, IP allowlists, integrations, temporary secrets, and automated vault activity.
Each event is added to the vault’s chronological history with the information needed to understand what happened and where it came from.
Field | What it tells you |
|---|---|
Time | When the event occurred. The dashboard uses your local time; exported files use UTC. |
Severity | The importance of the event: Info, Low, Medium, High, or Critical. |
Action | The recorded activity, such as Secret Read, Machine Approve, Login Failed, or Project Freeze. |
Detail | A readable description with the relevant names, outcome, or reason. |
Actor | The user, machine, AI agent, or SikkerKey system process responsible for the activity. |
Source IP | The network address associated with the request or event. |
#Open and browse the Audit Log
Sign in to the SikkerKey dashboard and select Audit Log in the sidebar.
Review the newest events at the top of the table.
Use Prev and Next to move through the complete set of matching events.
Select the Time, Action, or Source IP column heading to change the sort order. Select the same heading again to switch between ascending and descending order.
#Understand severity
Severity | How to use it |
|---|---|
Info | Routine activity, including successful reads, logins, rotations, and everyday configuration changes. |
Low | Administrative or setup activity worth retaining as part of the vault history. |
Medium | Meaningful security, access, lifecycle, or configuration changes that may deserve review. |
High | Sensitive changes, denied operations, failed security checks, and destructive actions that deserve prompt attention. |
Critical | Highest-impact security and destruction events, including authentication failures, canary triggers, vault or project destruction, and account-protection events. |
#Filter and investigate events
Filters work together, making it easy to move from a broad review to a focused investigation.
Search details: enter a name, identifier, or phrase contained in the event detail.
Source IP: enter an IP address to show events from that exact address.
Action: select one or more recorded actions.
Severity: select one or more severity levels.
Time: choose Last hour, Last 24 hours, Last 7 days, or Last 30 days.
Actor: choose all users, machines, AI agents, or system activity, or search for a specific named actor.
Your active filters appear as chips above the table. Remove individual chips to broaden the results, or select Clear all to return to the full log.
#Review activity for a specific resource
You can open a focused activity history directly from the resource you are investigating. These views support action, severity, time, and detail filters.
Secrets: open a secret’s History view and select Audit to review reads, updates, rotations, renames, and lifecycle events for that secret.
Machines: open History for a machine and select Audit to review activity performed by or involving that machine.
AI agents: open History for an AI agent and select Audit to review its management activity and identity changes.
Organization members: open History from a member row to review that member’s activity in the organization.
#Export audit events
Export a complete filtered event set for analysis, reporting, evidence collection, or import into another security tool.
Select Export at the top of the Audit Log.
Choose CSV, JSON, or TXT.
Select a time period: 24 hours, 7 days, 30 days, 90 days, all time, or a custom date range.
Refine the export by action, actor, severity, source IP, or detail search.
Review the matching event count and sample output, then select Export.
Format | Best for |
|---|---|
CSV | Spreadsheets, reporting workflows, and security-tool imports. |
JSON | Structured processing and integrations. The file includes the export time, selected range, active filters, event count, and event records. |
TXT | A readable, line-oriented record with an export summary followed by each event. |
Each download contains every event that matches the selected range and filters, ordered from newest to oldest.
#Control who can view audit activity
Vault owners can review activity across the entire active vault. Organization members receive audit access through their vault role.
View audit log gives a member access to their own activity in the vault.
View others expands the log to activity from every actor in the vault.
Use the organization’s vault roles to assign the level of audit visibility each member needs. Resource-specific histories follow the member’s access to the corresponding secret, machine, AI agent, or organization member area.
#Retention
Your subscription plan sets the standard audit-retention period for the vault. High-severity events are retained for twice that period, and Critical events remain available as a long-term security record.