Audit log
See who backed up, downloaded, restored, reverted and deployed what, and export the history.
The audit log records the actions TenuVault performs for a tenant: backups, downloads, drift checks, restores, reverts and baseline deployments. Each entry names the admin who was signed in, what was done, and whether it worked. The log is stored with the tenant’s backups, in your own storage.
What is recorded
Section titled “What is recorded”| Action | Event type | Recorded when |
|---|---|---|
| Start backup | BACKUP STARTED | You start a backup from the app, including Backup Selected |
| Scheduled backup | BACKUP COMPLETED or BACKUP FAILED | An automatic backup, or a backup started with Back up all tenants now, ends |
| Download backup | BACKUP DOWNLOADED | You download a backup as a ZIP file |
| Detect drifts | POLICY DRIFT DETECTED | Drift detection runs, including Check all on the Tenants page |
| Restore backup as policy copies | RESTORE COMPLETED or RESTORE FAILED | A restore with Create copies ends |
| Restore backup in place | RESTORE COMPLETED or RESTORE FAILED | A restore with Replace in place ends |
| Revert policy to the backed-up version in place | POLICY REVERTED | Revert or Recreate on the Drift Detection page |
| Restore policy as an unassigned copy | POLICY RESTORED | Restore as copy or Restore previous version as copy on the Drift Detection page |
| Create unassigned baseline policy | POLICY CREATED | A policy is created from Framework coverage, one entry per policy |
| Deploy OpenIntuneBaseline Quick Start | POLICY CREATED | A Quick Start deployment ends, with the counts of created, skipped and failed policies |
| Undo OpenIntuneBaseline Quick Start | POLICY REVERTED | A Quick Start deployment is undone |
Each entry has a result: SUCCESS, FAILURE, or PARTIAL when a restore or deployment worked for some items and not for others. It also has a severity: INFO for success, WARNING for partial results and ERROR for failures.
The user is the admin signed in to the tenant when the action ran.
Where the log is stored
Section titled “Where the log is stored”The audit log lives in the tenant’s backup storage, in a container named audit-logs, with one file per event grouped by day:
- This device: encrypted like the backups.
- Your Azure storage account: stored as plain JSON. Anyone with read access to the container can read it.
Audit events are recorded for every plan. Viewing and exporting them needs Pro or MSP.
Backup retention does not delete audit events. If you change where a tenant’s backups go, the audit log shown is the one in the newly selected storage.
Entries for policies created from Framework coverage are written to the audit log on this device, even when the tenant’s backups go to Azure.
Events that could not be saved yet
Section titled “Events that could not be saved yet”If TenuVault cannot write an event, for example because the storage is unreachable, it keeps the event and tries again each time the audit log is loaded, for example when you refresh the Audit Log page, up to 100 events at a time. The page then shows how many events remain unsaved:
- If they “are kept encrypted on this device”, keep this installation until they are saved.
- If they “are held in memory for this session”, keep TenuVault open until they are saved.
View the audit log
Section titled “View the audit log”- Select the tenant in the tenant switcher.
- Open Audit Log in the sidebar.
The page shows, for the selected dates:
| Card | What it shows |
|---|---|
| Total Events | Number of events |
| Success Rate | Share of events with the result SUCCESS |
| Critical Events | Reserved for critical events. No current action records one, so it shows 0 |
| Security Alerts | Reserved for security and critical events. No current action records one, so it stays empty |
Below the cards, the table lists the events, newest first, with Timestamp, Event (type icon and severity), User, Action, Resource and Result. The table shows 50 events per page; use Previous and Next, or type a page number.
Auto-refresh is on by default and reloads the page every 30 seconds; the time of the last reload is shown next to it. Refresh reloads right away.
Find events
Section titled “Find events”- Search: type in Search by user, action, or resource… and click Search. The search also looks in each event’s details.
- From: and To:: the date range. The default is the last 7 days.
- Filters: choose one or more values in Event Type, Severity and Result.
The cards, table and exports all follow the date range and filters.
Export the audit log
Section titled “Export the audit log”- Set the date range, search and filters you want.
- Click Export and choose Export as JSON or Export as CSV.
The export holds every matching event, not just the current page. The file is named audit-logs- followed by the date.
- CSV columns: Timestamp, Event Type, Severity, User Email, User Name, Action, Resource Type, Resource Name, Result, IP Address, Duration (ms) and Details.
- JSON contains the export date, the filter used and every event with its details.
Plan requirements
Section titled “Plan requirements”| Feature | Community | Pro | MSP |
|---|---|---|---|
| Events are recorded | Yes | Yes | Yes |
| View, search and export the audit log | No | Yes | Yes |
On Community, the Audit Log page shows “The audit log: included in TenuVault Pro and MSP. Upgrade on the License page.” with See plans.