> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Audit Log

Administrators can view the HiddenLayer Console audit log to see user activity in the Console.

Information gathered includes: the event timestamp, the user’s email address, the user’s assigned role, and a description of the activity (examples: Logged in, Created model, Updated user).

![Admin Audit Log](/_fern-img/d9ae019c66a0a55586d581ac3f03926595509b77ae0e5af25651905037e4d22e.webp)

1. In the Console, go to **Settings > Audit Log**.

2. Select a start date and end date to display audit log activity that occurred within the selected dates.

   ![Start and End Dates](/_fern-img/5e31829b0053caa73f95b01814bf9c54b4d650b0241638369236a56f6803b6d5.webp)

3. Select a role to display audit log activity based on a user’s assigned role.

   ![Select a Role](/_fern-img/87c6657988adfdcf9d1a84bc74bb638c1e96d8a5e4341f4b280e8312c69515a9.webp)

4. Use the search field to display audit log activity based on the user’s email address.

   ![Select a Role](/_fern-img/b71a9912acf35772768e4ab796254939814bb229d3430d1f40f7d7831bd82c3d.webp)

> **Email Search**
>
> You must enter the full username in the email address. If the user’s email address is `username@email.com`, then use username to search by the email address.

> **Data Retention**
>
> Audit log entries are retained for 365 days.

## Audit Log Descriptions

The following are audit log description categories and the associated log entries.

| Category               | Log Entry                                                                                                               |
| ---------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| API Key Management     | * Created API key
* Deleted API key
* Expired API key
* Credential name                                                 |
| Databricks Integration | - Created Databricks configuration
- Deleted Databricks configuration
- Updated Databricks configuration                |
| EULA                   | * Submitted EULA response                                                                                               |
| Incident               | - Updated incident                                                                                                      |
| Model                  | * Completed model upload
* Created model
* Deleted model
* Model name
* Model ID
* Started model upload
* Updated model |
| Sentinel Integration   | - Created Sentinel configuration
- Deleted Sentinel configuration
- Updated Sentinel configuration                      |
| Splunk Integration     | * Created Splunk configuration
* Deleted Splunk configuration
* Updated Splunk configuration                            |
| SSO Integration        | - Created SSO configuration
- Deleted SSO configuration
- Updated SSO configuration                                     |
| User                   | * Created user
* Deleted user
* Logged in
* User reset password
* Updated user                                          |
| Webhook Integration    | - Created custom webhook
- Deleted custom webhook
- Updated custom webhook                                              |