Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a database audit log?

A database audit log records configured database activity such as connections, queries, changes, deletion, permissions and administration. Coverage and account architecture determine what it proves.

Database identity may stop at the application

Entries can include database account, client, application, command, object, result, session and time. Many users may share one application database account, while jobs, stored procedures, replication and maintenance generate activity automatically. Detailed auditing may be disabled for performance or storage.

Connect query to end user and data effect

Establish enabled features and exclusions, whether access was direct or application-mediated, schema and transaction IDs. Preserve source and surrounding activity.

For material changes compare before-and-after data, transaction history, backups and application audit. Use specialist help where architecture or query semantics affect interpretation.

The point to remember

A database log records configured data operations; application and session evidence may still be needed to identify the end user.

Reference: LOG-029Logs, Records & Provider Evidence