ObsidianDocumentation Sign in

Audit log

Manage › Audit log records who did what: every sign-in, release, deletion, download and configuration change, with the source IP.

Using it

Search matches the actor, action or target. Entries for message actions link to the message. Organization administrators see their organization's entries; MSP administrators see everything. Entries are kept for at least a year.

Action names

ActionRecorded when
setup.superadminThe first administrator was created.
login.password, login.password+totp, login.sso, login.magic, login.failed, logoutSign-ins by method, failures, sign-outs.
quarantine.release, quarantine.deleteMail released or deleted (by an admin, the user, a digest link digest:<address> or the API api:<token name>). Automatic releases after an AI hold are shown on the message instead (released by ai).
report.spam, report.hamTraining reports.
message.clawback, message.downloadClawback from mailboxes (actor ai when an async AI review triggered it); raw message downloaded.
list.allow, list.block, list.deleteAllow / block list changes.
org.create, org.update, org.deleteOrganization changes.
domain.add, domain.update, domain.delete, domain.dkim_generate, domain.relay_keyDomain changes.
connector.add, connector.update, connector.deleteConnector changes (secrets are never logged).
user.create, user.update, user.password_change, user.mfa_enable, user.mfa_disableAccount changes.
policy.save, policy.delete, policy.default.updatePolicy changes.
settings.updateA Settings section was saved (lists the keys).
token.create, token.revokeAPI tokens.
tls.requestA Let's Encrypt certificate request was started (names and method).