What is an activity log?¶
An activity log is a record or summary of events associated with a cloud account, user, application or resource.
It may include logins, file actions, sharing, settings changes, messages, application use and security events.
What this means in practice¶
Activity views are often designed for users or administrators rather than investigators. They may combine events, omit technical fields or show only recent activity.
The same provider may also maintain separate authentication, audit, administrator and API logs with more detail.
Investigators should identify who generated the activity log, its purpose, retention period and whether it is a summary or raw record.
An activity event may also be automated. Synchronisation, applications, service accounts and provider processes can create entries without direct human action.
Use the activity log to identify relevant events, then seek the underlying records where attribution or precision matters.
Where an activity view is exported by a user or administrator, record the export method and filters applied. A filtered view may appear complete while silently excluding other event categories or date ranges.
What this does not show on its own¶
The dangerous assumption is that an activity log is the same as a complete audit trail.
What to do next¶
Preserve event times, time zones, account IDs, resource IDs, application details and any event or correlation identifiers.
Do not assume that the user interface shows historical activity exactly as it was recorded at the time. Display names, locations and account labels may be resolved using current information.
Key takeaway
An activity log is often a useful summary of cloud events, but important conclusions should be checked against the underlying audit, session and authentication records.