Skip to main content
Staff only

Reading one audit event

Everything recorded about one event sits in the detail drawer. Read it top to bottom, and use the severity summary above the table for scale.

What you'll need
  • The Audit Logs module visible in your left-hand navigation.
  • A staff sign-in, and a tenant and a service chosen on Audit Logs.

If Audit Logs isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.

Steps

  1. Five tiles — CRITICAL, HIGH, MEDIUM, LOW, INFO — sit between the filter bar and the table, over a line giving the total. They count every event for the chosen tenant and service, ignoring your filters; a severity with none shows 0. Select a tile to filter by it, and again to clear.

  2. Select View details, the eye button at the end of the row. The drawer opens on the right, titled with the event’s plain-language action.

  3. The badge row carries the event’s severity, category and outcome, then its change status if present. Occurred is the event’s own clock; Recorded is the trail’s, shown when it has one, so relay delay stays visible. Hover either for the exact instant.

  4. Who gives Type, Identity and Name — the last reads Not sent (kept at the source service) for anything a service relayed. What gives the Action as a sentence over its raw event token, the Resource, and a Reason when one was recorded.

  5. Open the collapsed section for Service, Correlation ID, Log ID, Chain position and Chain hash.

What success looks like

  • The badge row, When, Who, What and Technical details are on every event; Recorded, Reason, IP address, Schema version, What changed and Details only when that event carries them.
  • Anything the producing service did not send reads .
  • A copy icon beside an id turns into a tick once that value is copied.

What a semantic diff shows

What changed names each changed field rather than printing two payloads. An id list shows green + chips for additions, struck-through red chips for removals, and a note such as 3 kept — or Order changed only when items only reordered. A single value shows the old struck through, an arrow, then the new one, with (not set) or (removed) for a missing side. A footer such as 4 field(s) unchanged counts the rest; identical sides read No visible difference.

If something goes wrong

SymptomLikely causeWhat to do
No What changed section.Only changes worth diffing — visibility, enable and disable — record a before and after.Read Details instead.
Chain position and Chain hash read .The event came from a pipeline worker, which publishes with no chain proof.Expect chain values only from IntELIEDocs, Documents and Audit (its own reads).
Processing step failed does not name the step.Failure events keep their own label, not a stage sentence.Read the stage row in Details, and note the service you chose.
This event could not be loaded.The link names an event outside the tenant and service it selects.Check both, then search for the event again.

Next

Steps verified against elie-staff-ui @ origin/dev 2026-08-04 on . Something wrong with this page?