Advanced auditing · filtering, summarizing and exporting the trail
The same audit screen offers filters by user, action, object type, date range and free text, a summary by user, action and object, a team adoption panel and a CSV export of whatever is currently filtered.
Reading the audit trail line by line works for checking a one-off suspicion. To answer a real question, such as what happened to this database between the 3rd and the 7th, or who exported data last quarter, you need to filter, summarize and take the result out with you. That is what this screen does.
Open Settings and click Audit. The filters sit just below the log configuration block.
The filters
- User: narrows to one person's actions. The All users option returns to normal.
- Action: narrows to one kind of action, for example Data export or Deleted.
- Object type: narrows to one object, for example Company or Opportunity.
- From and To: the date window. The end date covers the whole day.
- Search: free text that matches the action, the object type or the details stored on the event.
- Company: appears only for organizations running multiple companies, and filters by the company in whose context the action happened.
Summary
The Summary card shows, for the current filter, the total number of events and three lists: By user, By action and By object. It is there to spot the pattern before you look at the rows, for example noticing that ninety percent of the period's deletions came from a single account.
Team adoption
The Team adoption card shows, per person, how many audited actions they performed in the last thirty days and when their last activity was. It reads product usage, not sales performance: it counts recorded actions, so a log category that is turned off lowers everyone's count.
Exporting to CSV
- Adjust the filters until the table shows exactly what you need.
- Click Export CSV at the top of the screen.
- The file downloads with the same events currently on display.
Limits worth knowing
- The listing and the export work against a cap on events per query. For very busy periods, break the investigation into smaller date windows instead of trying to pull everything at once.
- The summary and the CSV reflect exactly the filter applied, not the entire trail.
- Only the categories that were on when an event happened exist in the trail. The Security category is always on.
Who can do this
Filtering, summarizing and exporting require permission to manage settings. Isolation by organization applies: no query reaches another organization's events, not even through free text search.