Activity log

What the Activity page records, what each column means, how to filter it and load older entries, and how long entries are kept.

What the activity log is

The activity log is the audit trail of your own account: sign-ins, changes to machines and settings, API key changes and every request made with your API key, each with when it happened, where it came from and whether it worked. Open it from Activity in the left sidebar.

It is read-only, and it shows only your own account. Use it to review what was done and to spot anything you do not recognize. What EyalSec detected in your programs is on the Events page and the Dashboard, not here.

Columns

The log is a table with one row per action, newest first. It has six columns: Time, Action, Target, IP, Auth and Outcome.

Time

Time is when the action happened, with the date, a 24-hour time to the second, and a short time zone label. It is shown in your display time zone.

Action

Action describes what was done, in words, for example Logged in, Created machine prod-web-1, Set socket taint to on or API request: GET /api/get_all_machines/.

Target

Target is what the action applied to, when there is one: usually a machine's name, or a machine's public ID (a long identifier such as 0f6c...) for actions like renaming or deleting. For an API request it is the method and path that was called. It is empty for actions that have no target, such as a successful sign-in; a failed sign-in shows the username that was tried.

IP

IP is the network address the request came from. An address you do not recognize, especially on a sign-in or an API request, is worth looking into.

Auth

Auth says how the request was authenticated: session means someone signed in to the dashboard (you, in a browser), and apikey means a request made with your API key, typically a script or an integration. It tells apart what you did by hand from what your automation did.

Outcome

Outcome is success or failure, shown as a colored badge. Most rows are successes; failures are mainly failed sign-ins and API requests that were refused. Several failure rows in a row, such as repeated failed logins, can be an early warning sign.

Filters

Two dropdowns above the table narrow the log. Pick a value and the table reloads straight away; set a dropdown back to All actions or All outcomes to clear it.

Action filter

The action dropdown shows only one kind of action. It offers:

Group Choices
API API requests
Machines Machine created, Machine renamed, Machine deleted, Machine reinstalled, Machine OS changed, Machine rule created, Machine rule updated, Machine rule deleted, Machine taint changed
Rule templates Rule template created, Rule template updated, Rule template deleted, Rule template applied
Sign-in Login, Failed login, Logout
Account Password change, Email change, 2FA enabled, 2FA disabled, Backup codes regenerated
API key API key generated, API key regenerated, API key revoked

Some recorded actions have no entry in this list, so you only see them with All actions. They include generating an install or uninstall command (Attested authorized use; generated install token, Generated uninstall command), which is also how a reinstall is recorded; turning email sign-in codes on or off; requesting and confirming a recovery email change; changing your session timeout or time zone; setting the unique event definition; and verifying your email.

Machine reinstalled currently matches nothing, because a reinstall is recorded as generating an install command. Email change matches removing your recovery email; requesting and confirming a new one are recorded separately.

Outcome filter

The outcome dropdown shows only Success or only Failure entries. Combine it with the action filter, for example Failed login with Failure, or API requests with Failure to find calls your scripts made that were refused.

Load more

The log shows 50 entries at a time. When there are older entries, a Load more button appears under the table; each click adds the next 50, keeping the filters you have set.

If nothing matches, the page says "No activity recorded yet." If the log cannot be loaded, it says "Could not load activity. Please retry."; reload the page.

What is recorded

Every request made with your API key is recorded as an API request, whether it read or changed something. Dashboard use in the browser is recorded only for actions that change something (and for signing in and out); simply viewing pages is not recorded.

Each row is written within a second or so of the action. The log is also available through the API: see Account API.

Retention

The activity log keeps the last 30 days. Older entries are deleted automatically, so it is a record of recent activity, not a permanent archive. If you need a longer record, for example for compliance or an investigation, copy out what you need (or collect it regularly through the API) before it ages out.

If something looks wrong

If you see a sign-in, an API request or a change you did not make, act straight away. Change your password, turn on two-factor authentication, and revoke your API key if API requests you do not recognize appear.

Then contact support@eyalsec.com with the time, IP and action of the rows in question. See Getting help.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo