Aurva

System Logs

View, filter, and export audit logs, system events, and API access logs from the Aurva platform.

System Logs provide a tamper-evident record of everything that happens on the Aurva platform -- administrative actions, system events, and API access.

Log Categories

CategoryWhat It Records
Audit LogsUser actions: login/logout, policy changes, finding resolution, role assignments
System EventsPlatform health: agent connectivity, scan completion, upgrade events, errors
API AccessAPI calls: endpoint, caller identity, request method, response status, timestamp

Viewing Logs

Navigate to Settings -> System Logs to access the log viewer. Use the filters to narrow results:

  • Category -- Audit, System, or API
  • Time range -- last hour, day, week, or custom
  • User -- filter by the actor who performed the action
  • Action type -- e.g. policy.created, user.login, scan.completed
  • Severity -- Info, Warning, Error

Log Details

Each log entry includes:

FieldDescription
TimestampUTC time of the event
CategoryAudit, System, or API
ActorUser email or system component
ActionMachine-readable action code
DescriptionHuman-readable summary
IP AddressSource IP (for user and API actions)
StatusSuccess or Failure

Retention

Logs are retained in the Aurva console for 90 days by default. To retain logs longer:

  • Export to Email & S3 using an alert route configured for audit events
  • Forward to your SIEM for long-term storage and correlation

Export

Click Export in the log viewer to download the current filtered view as CSV or JSON. For automated export, configure an S3 alert route and enable the System Logs event type.

For compliance audits, combine System Logs exports with Audit Trail data from DAM to provide a complete evidence package.