ShadowTrackr

Audit Log

The audit log records who did what in your ShadowTrackr account: logins, changes to assets, reports, alerts, users and settings, exports, and more. You can read it on the Audit log page under Settings, and collect it with the audit log API.

The audit log is only available on Enterprise accounts and up: the Enterprise plan and the Reseller Enterprise plan. See pricing.

Who can see the audit log

Only administrators can open the audit log: users with the role Organization administrator or Organization administrator & contact (see User Management). Regular users and read-only users don't see it.

Group administrators of a multi-tenant (reseller) account find it under Group Settings. They see one log for the whole group: their own group-level actions, such as adding users or organizations, together with everything that happened in each of the group's organizations. An extra column shows which organization each line belongs to.

What is logged

Every line records the time (UTC), the user, where the action came from (the web app, the mobile app, or the API), the IP address, a category, the event and a description. The categories are:

CategoryWhat it covers
Category:
Logins
What it covers:
Successful logins (password, MFA, single sign-on, the app), failed logins, account lockouts, logouts, and accepted or rejected login IP addresses.
Category:
Own account
What it covers:
Password changes and resets, MFA setup, and name or phone number changes.
Category:
User management
What it covers:
Users added, deleted, blocked or unblocked, role and email address changes, MFA and password resets done by an administrator.
Category:
Assets
What it covers:
Assets added, edited or deleted, including those added from suggestions, phishy urls and the API.
Category:
Scans
What it covers:
Requested rescans of urls, domains, hosts, websites, certificates and subnets.
Category:
Ignored items
What it covers:
Urls and hosts ignored or unignored, ignore filters, and CVEs marked as false positives.
Category:
Reports
What it covers:
Reports created, edited or deleted, and recipients added or removed.
Category:
Alerts
What it covers:
Alerts and canaries created, edited, enabled, disabled or deleted, and recipients added or removed.
Category:
Integrations and webhooks
What it covers:
Changes to the Shodan, Censys and Shadowserver integrations, and to the webhook an alert posts to.
Category:
Settings
What it covers:
Every saved settings change, showing the old and the new value. Secrets such as API keys are never shown, only that they changed.
Category:
API keys
What it covers:
API key regeneration, and audit log keys created, replaced or revoked.
Category:
Single sign-on
What it covers:
SSO configuration changes and organization mappings.
Category:
Billing
What it covers:
Plan changes, cancellations and resumed subscriptions, and extra asset blocks.
Category:
Searches
What it covers:
Searches in the app.
Category:
Exports and downloads
What it covers:
Downloaded and emailed exports, reports, invoices, and audit log exports.
Category:
Data deletion
What it covers:
"Delete all my data" (from the app or the API), refused API delete attempts, and organizations created or deleted.

Actions done through the API have no user: the API key belongs to the organization, so these lines show API as the user.

Searching and exporting

Filter the log by date range, user, category, or any text in the description. Newest entries come first; use Older to page back. Export CSV downloads the current filtered view (up to 50,000 lines). Downloading the audit log is itself recorded in the audit log.

Retention

The audit log is kept as long as the data retention of your plan: 3 years on Enterprise and Reseller Enterprise. Older lines are removed automatically.

When you delete a user, their audit history is kept. It shows as deleted user with their user number, and the description still names the email address involved. When an organization is deleted, its audit log is deleted with it.

Collecting the audit log with the API

To send the audit log to a SIEM or log collector, create an audit log key on the Audit log page. This is a separate key: it can read the audit log and nothing else, so it can't add, change or delete anything in your account. It's not the same as your regular API key, and your regular API key can't read the audit log.

The key is shown only once, when you create it; ShadowTrackr stores only a hash of it. You can replace it at any time (the old key stops working immediately) or revoke it. Creating, replacing and revoking the key are recorded in the audit log.

See the audit log endpoint in the API documentation for how to call it.