Viewing the Audit Log
In the top menu bar, click Audit Log. To view the details for a given message, click the Expand button > at the end of the row.
To copy a message to the clipboard, click it and use Ctrl+C on Windows or Command+C on the Mac. If you want to copy multiple rows, click the Multi-Select button and then left-click on the rows you want to select. If you want to export the entire audit log in CSV or XML format, see Exporting the Audit Log.
You can filter the audit log messages displayed using one or more text searches forming an AND search string. The webGUI displays the selected filters below the field. To remove a particular filter, click the X following the filter name.
All searches are partial word and case-insensitve. So "cre" would match "Create" and "Secret".
You cannot use regular expressions and you cannot specify a NOT condition in the search string. Complex searches can only be done through the API.
To filter the message list:
- In the Filter drop-down list, select the field you want to filter on.
- Enter the filter text in the text box.
- Click the Plus (+) sign at the end of the field to add the filter.
- Repeat this process to add additional filters and further refine the display.

- Category—Common categories are Security and Clusters.
- Message—Searches the text displayed in the Message column.
- Date—Filters the list based on the date the log entry was created. You can only select one day per filter. KeyControl does not support searching on a range of dates.
- Group—The name of the associated group, such as KeyControl Admin Group and Cloud Admin Group.
- Host—The hostname of the server where the activity took place. In general this will be one of the KeyControl nodes.
- ID—The message ID. For example, if you want to see all messages where a Cloud VM Set was created, you would enter "12" in the filter field.
- User—Searches the text shown in the User column. For a user-defined webGUI account, this will be the Full Name specified for the account. For security reasons, the user login ID is not saved in the Audit Log.
KeyControl Audit Messages