Audit Logs

RudderStack's Audit Logs feature gives you complete transparency into the user activities happening within your RudderStack workspace. These activities include user actions related to creating and modifying sources, destinations, transformations, teams, and multi-factor authentication (MFA).

Audit Logs
Audit Logs is an enterprise-only feature. For more information on the features included in this plan, refer to the RudderStack pricing page.

Accessing the audit logs

The workspace-related audit logs can be accessed only by the users with admin or read/write access.

You can access the workspace-specific audit logs by clicking on the Audit Logs option in the left sidebar of the dashboard, as shown:

Click on the Audit Logs

For audit logs related to a specific source or destination, you can go to the source/destination details page and click on the Audit Logs option, as shown:

Click on the Audit Logs

Audit logs details

The audit logs capture the following information:

  • User: Name and email of the user who is a part of the RudderStack workspace.
  • Action: Corresponds to the user action performed on the entity.
  • Target: Corresponds to the entity name, i.e. name assigned to the source, destination, transformation, etc.
  • Type: Corresponds to the entity type, i.e. source, destination, transformation, teammate, etc.
  • When: The timestamp when the user action was performed.
Information captured by Audit Logs

The following sections detail the various user actions captured by the audit logs based on the target type, i.e. sources, destinations, transformations, teams, or MFA (multi-factor authentication).

Source audits

ActionDescription
CreatedUser created a source in the dashboard.
UpdatedUser updated the source settings in the dashboard.
Updated NameUser updated the source name in the dashboard.
DeletedUser deleted the source from the dashboard.

Destination audits

ActionDescription
CreatedUser created a destination in the dashboard.
UpdatedUser updated the destination settings in the dashboard.
Updated NameUser updated the destination name in the dashboard.
DeletedUser deleted the destination from the dashboard.
Connect SourceUser connected a source to the destination.
Disconnect SourceUser disconnected a source from the destination.
Added TransformationUser added a transformation to the destination.
Deleted TransformationUser removed/disconnected a transformation from the destination.

Transformation audits

ActionDescription
CreatedUser created a new transformation in the dashboard.
UpdatedUser updated the transformation.
DeletedUser deleted the transformation from the dashboard.
These audits apply to the transformation libraries as well.

Team audits

ActionDescription
InvitedUser invited a new user to join the current RudderStack workspace.
AcceptedThe new user accepted the invitation to join the workspace.
CancelledUser cancelled the invitation to join the workspace.
Changed PermissionUser changed the permissions for a specific user (identified by userId) in the workspace.
DeletedUser removed/deleted a user(identified by userId) from the workspace.

Multi-Factor Authentication(MFA) audits

ActionDescription
Enabled MFAUser enabled MFA for his account.
Disabled MFAUser disabled MFA for his account.
Updated PhonenumberUser updated their phone number used for MFA.

Contact us

For more information on this feature, you can contact us or start a conversation on our Slack channel.