What is an audit log?¶
An audit log is designed to record significant accountable actions in a system. The label does not guarantee complete coverage, immutability or personal attribution.
Audit scope is product-specific¶
Entries may show actor account or service, target object, action, result, address, request or session and time for access, permission, configuration or deletion. Administrators can act for users, automation can change objects and compromised accounts can populate actor fields.
Establish coverage and integrity¶
Determine which events were configured, whether logging was enabled, retention, filters and who could disable, alter or delete records. Preserve source data, configuration, fields and surrounding sequence.
Correlate significant actions with authentication, application, change tickets, communications and endpoints. Report the recorded actor separately from a proven person.
The point to remember
Audit logs can strongly structure activity, but their completeness, integrity and human actor must be demonstrated.