Working with the Cisco Account Audit Log
Last updated
The Cisco Account audit log provides a history of identity and access events for your organization, such as login attempts and other authentication activity. Use the audit log to investigate access events, verify user activity, and generate reports for security or compliance review.
You view Cisco Account audit log events in the Cisco Identity portal, the admin portal used to manage Cisco Account identity settings. Use the ThousandEyes activity log for user and system actions in the ThousandEyes platform, such as test changes, account group changes, and other platform activity.
In ThousandEyes, go to Manage > Account Settings > Organization Settings.
In the Single Sign-On (SSO) section, select Go to admin portal.
In the Cisco Identity portal, select Audit from the left navigation.

The audit log shows identity events in a table. The main components in this screen are:
For each event, the audit log shows:
Date & time: The timestamp for the event.
Performed by: The user or account associated with the event.
Status: The result of the event, such as Success.
Category: The event category, such as Sign-in.
Summary: A short description of the event.
Use the time range selector to choose the period of events shown in the table. For example, select Last 24 hours to show recent activity.
Use Search to find matching audit log entries. Use Category, Status, and Filters to narrow the events shown in the table.
Select Generate report to create an audit report from the Cisco Identity portal. The report is generated as a CSV file for you to download.
Last updated