Skip to content
All articles
Governance

Advanced auditing · filtering, summarizing and exporting the trail

The same audit screen offers filters by user, action, object type, date range and free text, a summary by user, action and object, a team adoption panel and a CSV export of whatever is currently filtered.

Reading the audit trail line by line works for checking a one-off suspicion. To answer a real question, such as what happened to this database between the 3rd and the 7th, or who exported data last quarter, you need to filter, summarize and take the result out with you. That is what this screen does.

Open Settings and click Audit. The filters sit just below the log configuration block.

The filters

  • User: narrows to one person's actions. The All users option returns to normal.
  • Action: narrows to one kind of action, for example Data export or Deleted.
  • Object type: narrows to one object, for example Company or Opportunity.
  • From and To: the date window. The end date covers the whole day.
  • Search: free text that matches the action, the object type or the details stored on the event.
  • Company: appears only for organizations running multiple companies, and filters by the company in whose context the action happened.

Summary

The Summary card shows, for the current filter, the total number of events and three lists: By user, By action and By object. It is there to spot the pattern before you look at the rows, for example noticing that ninety percent of the period's deletions came from a single account.

Team adoption

The Team adoption card shows, per person, how many audited actions they performed in the last thirty days and when their last activity was. It reads product usage, not sales performance: it counts recorded actions, so a log category that is turned off lowers everyone's count.

Exporting to CSV

  1. Adjust the filters until the table shows exactly what you need.
  2. Click Export CSV at the top of the screen.
  3. The file downloads with the same events currently on display.
Example: A company gets a request from legal about the contact database. The person in charge filters the Data export action, the range from June 1 to June 30, and leaves the user on All. The Summary shows 12 events, 9 from one person and 3 from another. She clicks Export CSV and attaches the file to the formal reply, with the date, time, author and record of each export.

Limits worth knowing

  • The listing and the export work against a cap on events per query. For very busy periods, break the investigation into smaller date windows instead of trying to pull everything at once.
  • The summary and the CSV reflect exactly the filter applied, not the entire trail.
  • Only the categories that were on when an event happened exist in the trail. The Security category is always on.

Who can do this

Filtering, summarizing and exporting require permission to manage settings. Isolation by organization applies: no query reaches another organization's events, not even through free text search.

💡 For a security-oriented read, with categories such as login, export, role changes and deletions already separated out, use the Security events tab under Settings, Advanced security. It reads the same trail, organized through a different lens.

Open this article inside the system

Read it and want to see it working?

The account is free and the whole manual is available inside the system, with an assistant that answers from this very content.

Create free account
Advanced auditing · filtering, summarizing and exporting the trail · Sellio