Help Center/ KooDrive/ User Guide/ Auditing/ Querying Audit Logs
Updated on 2025-08-28 GMT+08:00

Querying Audit Logs

The system administrator can check Management and Operation Logs and Sign-In and Sign-Out Logs on the management console. All human-machine and machine-machine operations on tenant resources, including adding, deleting, or modifying tenant resources, will be recorded in audit logs regardless of whether they are successful.

Constraints

Only the system administrator can check audit logs. For details about system roles, see Table 1.

Checking Management and Operation Logs

  1. Sign in to the KooDrive service plane as a system administrator.
  2. Click Console on the top of the page.

  3. In the navigation pane on the left, choose Audit Logs > Management and Operation Logs.
  4. Filter logs. You can specify a time range or enter an operator name to search for logs. To clear filter criteria, click .

    Figure 1 Management and operation logs

    Table 1 Log parameters

    Parameter

    Description

    Time

    Time when the operation was recorded.

    Operator

    Name of the user who performed the operation.

    Event Type

    Type of an event, except sign-in and sign-out.

    Operation Object

    Operation object, which varies according to the event. For example, the GetUser event records the tenant ID.

    Operation Result

    Successful or failed. If the operation failed, View Cause is displayed. You can hover the cursor over it to view details.

    IP Address

    Identifier of a device or service on the network.

Checking Sign-In and Sign-Out Logs

  1. Sign in to the KooDrive service plane as a system administrator.
  2. Click Console on the top of the page.

  3. In the navigation pane on the left, choose Audit Logs > Sign-In and Sign-Out Logs.
  4. Filter logs. You can specify a time range or enter an operator name to search for logs. To clear filter criteria, click .

    Figure 2 Sign-in and sign-out logs
    Table 2 Log parameters

    Parameter

    Description

    Time

    Time when an operation was performed.

    Operator

    Name of the user who performed the operation.

    Device Type

    Type of the device used, for example, web.

    Operation Type

    Operation type. Options:

    • CreateSession: login.
    • LogOut: proactive logout.
    • Timeout-LogOut: logout upon timeout.

    IP Address

    Identifier of a device or service on the network.