Docs

Review and export audit activity

Open Audit log. Each row shows When, Action (for example auth.login.success, campaign.launch), Performed by, Target, IP, and a view link for the full details.

Open Audit log. Each row shows When, Action (for example auth.login.success, campaign.launch), Performed by, Target, IP, and a view link for the full details.

  1. Use the Action contains filter (for example campaign.launch) and click Filter to narrow the list.
  2. Click view on a row to see its full details. Useful when investigating a specific change or sign-in.
  3. Review events after changes to users, sender profiles, domains, campaigns, integrations, or API keys, especially around incidents.
  4. Export the current view as CSV or JSON with the buttons above the table, to share with people who do not have Phishtime access.

Set how long these entries are kept under Settings → Access & security → Event log retention. See Audit log and data retention.