The audit log records who did what in your ShadowTrackr account: logins, changes to assets, reports, alerts, users and settings, exports, and more. You can read it on the
Audit log page under Settings, and collect it with the
audit log API.
The audit log is only available on Enterprise accounts and up: the Enterprise plan and the Reseller Enterprise plan. See
pricing.
Only administrators can open the audit log: users with the role
Organization administrator or
Organization administrator & contact (see
User Management). Regular users and read-only users don't see it.
Group administrators of a multi-tenant (reseller) account find it under
Group Settings. They see one log for the whole group: their own group-level actions, such as adding users or organizations, together with everything that happened in each of the group's organizations. An extra column shows which organization each line belongs to.
Every line records the time (UTC), the user, where the action came from (the web app, the mobile app, or the API), the IP address, a category, the event and a description. The categories are:
| Category | What it covers |
|---|
Category: Logins | What it covers: Successful logins (password, MFA, single sign-on, the app), failed logins, account lockouts, logouts, and accepted or rejected login IP addresses. |
Category: Own account | What it covers: Password changes and resets, MFA setup, and name or phone number changes. |
Category: User management | What it covers: Users added, deleted, blocked or unblocked, role and email address changes, MFA and password resets done by an administrator. |
Category: Assets | What it covers: Assets added, edited or deleted, including those added from suggestions, phishy urls and the API. |
Category: Scans | What it covers: Requested rescans of urls, domains, hosts, websites, certificates and subnets. |
Category: Ignored items | What it covers: Urls and hosts ignored or unignored, ignore filters, and CVEs marked as false positives. |
Category: Reports | What it covers: Reports created, edited or deleted, and recipients added or removed. |
Category: Alerts | What it covers: Alerts and canaries created, edited, enabled, disabled or deleted, and recipients added or removed. |
Category: Integrations and webhooks | What it covers: Changes to the Shodan, Censys and Shadowserver integrations, and to the webhook an alert posts to. |
Category: Settings | What it covers: Every saved settings change, showing the old and the new value. Secrets such as API keys are never shown, only that they changed. |
Category: API keys | What it covers: API key regeneration, and audit log keys created, replaced or revoked. |
Category: Single sign-on | What it covers: SSO configuration changes and organization mappings. |
Category: Billing | What it covers: Plan changes, cancellations and resumed subscriptions, and extra asset blocks. |
Category: Searches | What it covers: Searches in the app. |
Category: Exports and downloads | What it covers: Downloaded and emailed exports, reports, invoices, and audit log exports. |
Category: Data deletion | What it covers: "Delete all my data" (from the app or the API), refused API delete attempts, and organizations created or deleted. |
Actions done through the API have no user: the API key belongs to the organization, so these lines show
API as the user.
Searching and exporting
Filter the log by date range, user, category, or any text in the description. Newest entries come first; use
Older to page back.
Export CSV downloads the current filtered view (up to 50,000 lines). Downloading the audit log is itself recorded in the audit log.
The audit log is kept as long as the data retention of your plan: 3 years on Enterprise and Reseller Enterprise. Older lines are removed automatically.
When you delete a user, their audit history is kept. It shows as
deleted user with their user number, and the description still names the email address involved. When an organization is deleted, its audit log is deleted with it.
To send the audit log to a SIEM or log collector, create an
audit log key on the
Audit log page. This is a separate key: it can read the audit log and nothing else, so it can't add, change or delete anything in your account. It's not the same as your regular API key, and your regular API key can't read the audit log.
The key is shown only once, when you create it; ShadowTrackr stores only a hash of it. You can replace it at any time (the old key stops working immediately) or revoke it. Creating, replacing and revoking the key are recorded in the audit log.
See the
audit log endpoint in the API documentation for how to call it.