products:cockpit:1.0:userguide:settings:changesaudit
Table of Contents
Changes audit
Purpose
The changes audit keeps track of who changed what in the configuration of the tenant.
Every create, update, delete, clone, activation or customization done from the Cockpit produces one entry, with the state of the object before and after the change.
By example, you can answer the following:
- Who disabled this connector last week
- What was changed on the alarm rules yesterday
- Which monitors were customized on a profile and with which values
- Which collectors were assigned to a group or an organization
- How many objects each user created, changed or deleted in a month, per organization
Configuration
Activation
- The tracking is enabled per tenant in Administration > Settings, section Retention
- Changes retention switch: enables or disables the recording of changes
- Changes retention (days): how long the entries are kept, from 7 days to 1 year, 6 months by default
- Older entries are purged automatically once an hour
Warning:
- When the tracking is disabled, nothing is recorded, there is no way to rebuild the history afterwards
Access
- The page is available in Settings > Changes Audit
- A tenant administrator always sees it
- Other users need the Audit changes access authorization, section Settings of their application authorization profile
Changes list
- Entries are listed from the most recent one, with the timestamp, the object type, the user, the operation and a summary
- The summary names the object and, for a single change, the changed field with its old and new value
- Filters: date range (last 24 hours, 7 days, 30 days, full history or a custom period), user, object type, operation, organization
- Limit: number of entries loaded, 500 by default, 2000 at most
- Open an entry to see the details, or use the copy menu to copy the change ID, the object ID, the summary or the raw JSON
Change details
- Summary and Information: user, object type, object ID, organization, change ID
- Changes: one line per changed field with the value before and after
- References are shown by name (group, system, user, profile, monitor…)
- Elements added to or removed from a list are shown one by one
- Passwords, API keys and tokens are always masked
- Raw changes: the JSON of the object before and after, with a field filter and a Show changed only switch
- A Customize entry on a monitor job opens the job view instead: schedule, timeout, parameters and tables are displayed side by side, changed values are struck and replaced, added and removed rows are marked in place
Report
- Press Changes report to get a summary of the activity over a period, the last N days or the last month
- One table lists the changes per organization and per user, with one column per object type
- A second table, Non organization changes, lists the changes on objects that do not belong to an organization: users, teams, authorizations, plugins, alarm rules, collectors, dashboards…
- Each cell shows the created / changed / deleted counts, created includes clones
- Export CSV exports both tables
Export
- Export all exports the entries matching the current filters, Export selected changes exports the checked rows
- The export is a JSON file with the full entries, including the before and after state of each object
- An export is limited to 5000 entries, narrow the filters for larger histories
Tracked objects
| Area | Objects | Operations |
|---|---|---|
| Monitoring | Organizations, groups, systems, connectors, user profiles, profiles, crons | Create, Update, Delete, Clone (profiles, user profiles), Status (connectors) |
| Monitors | Job customizations on a profile or a connector | Customize |
| Alerting | Alarm rules, alarm rule engine switch, plugins | Create, Update, Delete, Clone (plugins), Status |
| Maintenance | Maintenances | Create, Update, Delete, Status |
| Administration | Users, teams, application and device authorization profiles, device tags, tenant settings, LDAP configuration | Create, Update, Delete |
| Collectors | Collectors, collector groups, collector profiles, collector settings, groups and organizations assigned to a collector, collectors assigned to a group or an organization | Create, Update, Delete, Status (collectors) |
| Dashboards | Custom dashboards and their permissions | Create, Update, Delete |
| Inventory | Devices, reports | Delete |
Notes:
- A bulk action produces one entry per object, the entries share the same batch
- A change is recorded only when the request succeeds, a failed save leaves no entry
- The audit never blocks an operation, if an entry cannot be built the change is applied anyway and a warning is logged
- Data pushed by the collectors (metrics, alarms, device metadata) is not configuration and is not tracked
products/cockpit/1.0/userguide/settings/changesaudit.txt · Last modified: by rbariou




