Skip to content

Audit log

See who backed up, downloaded, restored, reverted and deployed what, and export the history.

The audit log records the actions TenuVault performs for a tenant: backups, downloads, drift checks, restores, reverts and baseline deployments. Each entry names the admin who was signed in, what was done, and whether it worked. The log is stored with the tenant’s backups, in your own storage.

ActionEvent typeRecorded when
Start backupBACKUP STARTEDYou start a backup from the app, including Backup Selected
Scheduled backupBACKUP COMPLETED or BACKUP FAILEDAn automatic backup, or a backup started with Back up all tenants now, ends
Download backupBACKUP DOWNLOADEDYou download a backup as a ZIP file
Detect driftsPOLICY DRIFT DETECTEDDrift detection runs, including Check all on the Tenants page
Restore backup as policy copiesRESTORE COMPLETED or RESTORE FAILEDA restore with Create copies ends
Restore backup in placeRESTORE COMPLETED or RESTORE FAILEDA restore with Replace in place ends
Revert policy to the backed-up version in placePOLICY REVERTEDRevert or Recreate on the Drift Detection page
Restore policy as an unassigned copyPOLICY RESTOREDRestore as copy or Restore previous version as copy on the Drift Detection page
Create unassigned baseline policyPOLICY CREATEDA policy is created from Framework coverage, one entry per policy
Deploy OpenIntuneBaseline Quick StartPOLICY CREATEDA Quick Start deployment ends, with the counts of created, skipped and failed policies
Undo OpenIntuneBaseline Quick StartPOLICY REVERTEDA Quick Start deployment is undone

Each entry has a result: SUCCESS, FAILURE, or PARTIAL when a restore or deployment worked for some items and not for others. It also has a severity: INFO for success, WARNING for partial results and ERROR for failures.

The user is the admin signed in to the tenant when the action ran.

The audit log lives in the tenant’s backup storage, in a container named audit-logs, with one file per event grouped by day:

  • This device: encrypted like the backups.
  • Your Azure storage account: stored as plain JSON. Anyone with read access to the container can read it.

Audit events are recorded for every plan. Viewing and exporting them needs Pro or MSP.

Backup retention does not delete audit events. If you change where a tenant’s backups go, the audit log shown is the one in the newly selected storage.

Entries for policies created from Framework coverage are written to the audit log on this device, even when the tenant’s backups go to Azure.

If TenuVault cannot write an event, for example because the storage is unreachable, it keeps the event and tries again each time the audit log is loaded, for example when you refresh the Audit Log page, up to 100 events at a time. The page then shows how many events remain unsaved:

  • If they “are kept encrypted on this device”, keep this installation until they are saved.
  • If they “are held in memory for this session”, keep TenuVault open until they are saved.
  1. Select the tenant in the tenant switcher.
  2. Open Audit Log in the sidebar.

The page shows, for the selected dates:

CardWhat it shows
Total EventsNumber of events
Success RateShare of events with the result SUCCESS
Critical EventsReserved for critical events. No current action records one, so it shows 0
Security AlertsReserved for security and critical events. No current action records one, so it stays empty

Below the cards, the table lists the events, newest first, with Timestamp, Event (type icon and severity), User, Action, Resource and Result. The table shows 50 events per page; use Previous and Next, or type a page number.

Auto-refresh is on by default and reloads the page every 30 seconds; the time of the last reload is shown next to it. Refresh reloads right away.

  • Search: type in Search by user, action, or resource… and click Search. The search also looks in each event’s details.
  • From: and To:: the date range. The default is the last 7 days.
  • Filters: choose one or more values in Event Type, Severity and Result.

The cards, table and exports all follow the date range and filters.

  1. Set the date range, search and filters you want.
  2. Click Export and choose Export as JSON or Export as CSV.

The export holds every matching event, not just the current page. The file is named audit-logs- followed by the date.

  • CSV columns: Timestamp, Event Type, Severity, User Email, User Name, Action, Resource Type, Resource Name, Result, IP Address, Duration (ms) and Details.
  • JSON contains the export date, the filter used and every event with its details.
FeatureCommunityProMSP
Events are recordedYesYesYes
View, search and export the audit logNoYesYes

On Community, the Audit Log page shows “The audit log: included in TenuVault Pro and MSP. Upgrade on the License page.” with See plans.