> For the complete documentation index, see [llms.txt](https://docs.thousandeyes.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.thousandeyes.com/product-documentation/user-management/user-activity/working-with-cisco-account-audit-log.md).

# Working with the Cisco Account Audit Log

The Cisco Account audit log provides a history of identity and access events for your organization, such as login attempts and other authentication activity. Use the audit log to investigate access events, verify user activity, and generate reports for security or compliance review.

You view Cisco Account audit log events in the Cisco Identity portal, the admin portal used to manage Cisco Account identity settings. Use the [ThousandEyes activity log](https://docs.thousandeyes.com/product-documentation/user-management/user-activity/working-with-the-activity-log) for user and system actions in the ThousandEyes platform, such as test changes, account group changes, and other platform activity.

## Viewing the Audit Log

1. In ThousandEyes, go to **Manage > Account Settings > Organization Settings**.
2. In the **Single Sign-On (SSO)** section, select **Go to admin portal**.
3. In the Cisco Identity portal, select **Audit** from the left navigation.

![Cisco Account audit log table in the Cisco Identity portal](/files/oEfCqLFX5g4AE6zcywQH)

The audit log shows identity events in a table. The main components in this screen are:

* [Audit Log Table](#audit-log-table)
* [Time Range Selector](#time-range-selector)
* [Search and Filters](#search-and-filters)
* [Generating a Report](#generating-a-report)

### Audit Log Table

For each event, the audit log shows:

* **Date & time**: The timestamp for the event.
* **Performed by**: The user or account associated with the event.
* **Status**: The result of the event, such as **Success**.
* **Category**: The event category, such as **Sign-in**.
* **Summary**: A short description of the event.

### Time Range Selector

Use the time range selector to choose the period of events shown in the table. For example, select **Last 24 hours** to show recent activity.

### Search and Filters

Use **Search** to find matching audit log entries. Use **Category**, **Status**, and **Filters** to narrow the events shown in the table.

### Generating a Report

Select **Generate report** to create an audit report from the Cisco Identity portal. The report is generated as a CSV file for you to download.

## Related Information

* [Working with the Activity Log](https://docs.thousandeyes.com/product-documentation/user-management/user-activity/working-with-the-activity-log)
* [Configure SSO with Cisco Account](https://docs.thousandeyes.com/product-documentation/user-management/authentication/configure-sso-with-cisco-account)
* [How Long is my Data Accessible via ThousandEyes?](https://docs.thousandeyes.com/product-documentation/user-management/user-activity/how-long-is-data-accessible)
