System

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404

Audit Logs

Audit Logs capture WitnessAI object creations, deletions, updates, and User logins. Full details of “before” and “after” are included.
Audit logs can be viewed, searched, filtered, and exported in JSON format.
Only Users with “User Admin” roles and above can access Audit Logs. Currently this only applies to “User Admin” and “Super Admin” roles. Only “Super Admin” roles can view actions by “VIP” Users.

Navigation

Access the Audit Logs by clicking on the Settings menu or icon.
Audit Logs are below the System menu
notion image
 

Log Filters

Time Range Filter

  • Allows precise temporal scoping of log entries
  • Multiple selection methods:
    • Preset ranges (e.g., last 3 days)
    • Custom date and time range selection
  • Interactive update button to apply selected time range
  • Supports granular filtering down to specific hours and dates
  • Critical for narrowing down log investigations to specific time periods
notion image

User Filter

  • Filter by user email
  • Display user details including:
    • Name
    • Role (e.g., Super Admin)
    • Email address
notion image

Action Type Filters

Action Type filter restricts view to only the action type chosen.
  • Created
  • Deleted
  • Login
  • Updated
notion image

Object Type Filters

Object Types filter restricts view to only the object type chosen.
  • Catalog items
  • Lists
  • Policies
  • Orders
  • User changes
  • Groups
notion image

Viewing Audit Logs

Columns

  • User action
  • Action type
    • Created
    • Deleted
    • Login
    • Updated
  • Object modified
  • Object type
  • Status (success/failure)
  • Timestamp
  • Note: Columns are currently not sortable

Detail View

  • Displays detailed change information
  • Change visualization:
    • Minus (-) indicates old value
    • Plus (+) indicates new value
  • Shows version numbers for tracked changes

Pagination

  • Page size options: 25, 50, 100 items
  • Total action count display
  • Navigation controls between pages

Exporting Audit Logs

Selecting Logs for Export

Exporting all logs in your filtered view
Exporting individual records
Exporting multiple records
Selection state persists across pages
Exporting all records on current page
Exporting all records on selected pages

Sending Audit Logs to SIEMs

The Audit Logs feature supports forwarding to Security Information and Event Management (SIEM) systems, enabling comprehensive security monitoring and compliance reporting.
Configure Audit Log forwarding in the SIEM Settings, by clicking the checkbox next to “Include Audit Logs”.
notion image