📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Activity Log

See who did what in your Lavawall console, and prove to an auditor that the record has not been altered.

Where to find it
Logs & monitoring › Lavawall® Log
Who can use it
Administrators. Other users see "Admin access required to view activity logs." Mark reviewed appears only for people allowed to sign off reviews.
Plan
Included
For
Everyone

What the page is for

The Activity Log records actions taken in the Lavawall console and by its components: sign-ins, changes to users, devices, software packages, scripts, remote sessions, consent and more. Each entry shows when it happened, what the action was, who did it, what it affected, which company it belongs to and the IP address it came from.

The log is tamper-evident. It is sealed automatically once a day, and the Integrity bar shows whether the log still matches its last seal. You can re-run that check at any time, export the log for an auditor with what they need to verify it, and record that you reviewed a range of entries.

What you see

The Activity Log page, with the integrity bar, filters, results, log table and log entry detail numbered 1 to 5.
The Activity Log page. Numbers match the list below.
  1. Integrity bar: the seal status, when it was last sealed and last reviewed, with Re-verify, Export for auditor, Export evidence and Mark reviewed.
  2. Filters: Search, Action, Actor, Target, IP, From and To, with search and clear buttons.
  3. Results: a count and Previous / Next paging.
  4. Log table: Time, Action, Actor, Target, Company, IP, Details and Protected.
  5. Log Entry Detail: the full entry, including exact time, integrity status, actor and target companies and details.

How to use Activity Log

How to find an action

  1. Enter words in Search, or pick an Action.
  2. Start typing a name or email in Actor, or a user, computer or mailbox in Target, and choose a match from the list for an exact filter.
  3. Set From and To dates, then click the search button.
  4. Click a row to open Log Entry Detail.

How to follow a trail

  1. Click an IP address in the table to show all activity from that address.
  2. Click the filter icon next to a computer to show all activity for it, or the computer name to open its detail page.
  3. Click the clear button to reset the filters.

How to check the log has not been altered

  1. Look at the Integrity badge: Verified or Protected is expected.
  2. Click Re-verify to check the log against its seal again.

How to give an auditor the log

  1. Set From and To (and optionally Action).
  2. Click Export for auditor and Download CSV for a spreadsheet with what the auditor needs to check it, or Export evidence and Download JSON for the full evidence package, including each seal and a fresh check.
  3. Each export is itself recorded in the log.

How to sign off a log review

  1. Filter and page to the entries you reviewed.
  2. Click Mark reviewed.
  3. Optionally type Findings, such as "no anomalies", and click Sign off. The Integrity bar then shows when the last review was done and by whom.

Tips

  • Action badges are colour-coded by type, for example sign-in activity, device actions, packages, user management, remote sessions, consent and scripts.
  • Times are shown in your local time to hundredths of a second; the detail view also shows the stored UTC time.
  • In the Protected column, a shield means the entry is covered by the seal. ok or fail shows the stated outcome. A dash means the entry was recorded before tamper protection started.
  • Sign off reviews on a regular schedule so your compliance evidence shows continuous monitoring.

Troubleshooting

  • "Admin access required to view activity logs." Ask an administrator in your organization for access.
  • "Not sealed yet". The log is sealed automatically once a day. Check again tomorrow.
  • "Altered", "Does not match seal" or "Seal invalid". The check found a mismatch. Contact Lavawall support.
  • "Nothing to review". Load some entries first; a review records the range you actually looked at.
  • "No matching operators" in Actor. Only people who have acted in the console appear. Check the spelling or search by email.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.