What is a cloud audit log?¶
A cloud audit log is a provider or organisation record of actions taken within a cloud account, service or tenant.
It may show users, administrators, applications and systems creating, accessing, changing or deleting resources.
What this means in practice¶
Audit coverage varies by service, subscription, configuration and event type. Some actions may be recorded in detail. Others may be absent, summarised or retained only briefly.
The wording is provider-specific. “Accessed”, “updated” or “created” may have a narrow technical meaning that needs clarification.
Also check whether logging was enabled at the relevant time and whether older records have expired.
What this may show¶
An audit event may include the account or application, action, target resource, time, IP address, session, device information, outcome and administrator role.
Investigators should preserve the raw event, event ID, file or resource ID, account identifier, tenant, time zone and any correlation or request identifiers.
Use audit logs to reconstruct a sequence, then corroborate the important actions with authentication, session, device and wider evidence.
Where several logs appear to describe the same action, preserve their event and correlation identifiers. These may allow the provider or a specialist to connect the records more reliably than timestamps alone.
What this does not show on its own¶
The dangerous assumption is that an audit log is a complete record of everything that happened.
What to do next¶
Check whether the activity came through a browser, API, application, service account or administrator.
Do not assume that the account named in the log identifies the person responsible. Shared access, compromise, delegation and automation remain possible.
Key takeaway
A cloud audit log records selected service actions, so understand its scope and event definitions before using it to reconstruct or attribute activity.