Skip to content

Audit Log ​

The audit log records who signed in, who changed what, and who revealed secrets, downloaded or restored backups, from which address and browser.

The Audit Log Tab ​

Open Users & Groups → Audit log. It needs the audit:read permission.

The strip above the list covers the last 30 days:

CellCounts
EntriesEverything written, and how many days the log keeps
Sign-insSign-ins, by how many people, and how many came from a new place
ChangesRecords created, changed or deleted, and the areas changed most
SensitiveRevealed secrets and keys, downloads and restores
Failed sign-insTurned down passwords, with the address of the last one

Every entry shows as a sentence, like "Changed the group Operators", with who did it, the area, and the browser and address the request came from. A second line says what changed, like "Backups See to Use". A sign-in from a network the person never signed in from before is marked New place.

Filters ​

  • Search finds names inside the entries, like a job or a file, people, email addresses and IP addresses.
  • Who filters by person or API key. A person means what they did themselves, their API keys are listed on their own.
  • Area and Action pick one or several values, each counted under the other filters.
  • The period reaches back 24 hours, 7, 30 or 90 days, or over everything the log keeps.
  • All, Changes, Sign-ins and Sensitive are quick filters. Sensitive is marked amber while it holds entries.

An Entry Opened ​

A click opens the entry in a panel:

  • What changed lists every field before and after. A group or an API key shows the level of each area with the permissions it added or removed. A secret shows that it changed, never its value.
  • Who names the person with the sign-in the change came from, or the API key and its owner.
  • Earlier entries of this record lists what happened to the same record before, and Every entry of this record narrows the list to it.
  • A sign-in shows its address, its browser, when the session ended and everything the person did until then. Sign out everywhere ends every session of that person, for someone who may manage users. A SuperAdmin is signed out only by a SuperAdmin, so anyone else gets no button on their sign-ins.
  • Stored details shows the entry as it was written.

The Timeline ​

The view switch shows the timeline above the list: a row per person and API key, a column per day, as many days as fit. A bar shows how many entries someone wrote that day, its amber part the sensitive ones. Failed sign-ins have a row of their own. A click on a person, a day or a bar shows those entries in the list, and the arrows and the date button move through the days. A phone always gets the list as cards.

Export ​

Export CSV downloads the entries the filters keep, at most 50,000, newest first. The export itself is written to the audit log.

What Is Recorded ​

AreaEntries
Sign-inSign-ins with a password, a passkey, a second factor or single sign-on, sign-ups through a sign-in provider, sign-outs, failed password sign-ins, linked and unlinked sign-in accounts, sign-in providers
ConnectionsCreated, changed, cloned and deleted connections, storage alerts
JobsCreated, changed, cloned and deleted jobs, runs started by hand or through the API, cancelled runs
BackupsDownloads, download links, restores, restored files, locked and deleted backups
VaultEncryption keys, revealed keys and secrets, recovery kits, credential profiles
TemplatesCreated, changed and deleted templates
Users, Groups, API keysEvery change, set passwords, reset second factors, ended sessions, rotated keys
SettingsEvery settings page, system tasks, the configuration backup and its restore, the database download

A change keeps what it changed from and to. An entry keeps the name of the person who wrote it, so it still names them after the person is deleted. A request made with an API key names the key and its owner.

TIP

The address comes from the X-Forwarded-For or X-Real-IP header of the reverse proxy in front of DBackup. Without one, every entry shows the address of the proxy.

How Long Entries Stay ​

The log keeps 90 days by default. Change it under Settings → Data retention, see Data Retention.

Next Steps ​

Released under the GNU General Public License. | Privacy · Legal Notice