Searching audit logs

Audit logs record all user activity in the system. They provide essential information for security audits, troubleshooting, and regulatory compliance.

To search audit logs

  1. On the Home page, click Audit log.
  2. In the Audit log panel, select filters to refine the search.
    Note: By default, each filter includes all conditions.
    • Search bar: Enter keywords such as username, action, description, or client information. Partial matches are supported.
    • Date and time: Click the date filter to open the date selection panel. Set the start and end date/time range, then click .
      • Options include the entire period or recent intervals based on the current time: 1 hour, 12 hours, 24 hours, or 7 days.
    • Event action: Click the event action filter to view available event actions. Select the desired actions and click .
      • Device configuration
        • Add device: Adds a device to the system.
        • Delete device: Removes a device from the system.
        • Edit recording settings: Changes the recording settings of a device.
        • Enable license: Activates the device license.
        • Disable license: Deactivates the device license.
        • Edit PTZ settings: Changes PTZ (pan/tilt/zoom) settings.
        • Restart device: Restarts the device.
        • Reset device: Restores the device to factory default settings.
      • Server settings
        • Add server: Adds a server to the system.
        • Detach server: Removes a server from the system.
        • Edit time settings: Modifies the server time configuration.
        • Edit storage settings: Changes the storage configuration.
        • Format storage: Formats the storage (BLAZE Appliance only).
        • Edit failover settings: Changes the failover configuration.
        • Edit network settings: Changes the network configuration (BLAZE Appliance only).
        • Edit PoE settings: Changes PoE (Power over Ethernet) settings (BLAZE Appliance only).
        • Restart server: Restarts the server (BLAZE Appliance only).
        • Shut down server: Shuts down the server (BLAZE Appliance only).
        • Reset server: Resets the server to factory defaults (BLAZE Appliance only).
        • Start backup: Initiates backup.
        • Start restore: Initiates a restore from a backup file.
        • Edit recording video backup settings: Edits recording video backup settings (BLAZE Appliance only).
        • Create RAID: Creates a new RAID volume. (BLAZE Appliance only.)
        • Delete RAID: Deletes an existing RAID volume configuration. (BLAZE Appliance only.)
        • Rebuild RAID: Rebuilds a RAID volume after a disk replacement or similar event. (BLAZE Appliance only.)
      • Cloud
        • Edit cloud settings: Edits cloud settings.
      • User configuration
        • Add user: Adds a new user.
        • Delete user: Deletes a user.
        • Edit user: Edits user information.
        • Add role: Adds a new role.
        • Delete role: Deletes a role.
        • Edit role: Edits role information.
      • User operations
        • Login: Logs into the system.
        • Logout: Logs out of the system.
        • Failed login attempts: Indicates unsuccessful login attempts.
        • Lock account: Indicates that a user account has been locked.
      • Video
        • View live: Views live video streams.
        • View archive: Views archived video streams.
        • Export video: Exports archived video recordings.
        • Control PTZ: Controls PTZ cameras.
        • Delete bookmark: Deletes a bookmark.
        • Edit bookmark: Edits a bookmark.
      • Device operation
        • Move device: Transfers a device to another server.
        • Control alarm output: Changes the alarm output status.
      • Software update
        • Update software: Updates the software.
      • License
        • Add license: Adds a license.
        • Extend license: Extends the license usage period.
        • Deactivate license: Deactivates a license.
      • Archive
        • Start reindex archive: Starts reindexing between the index file and the actual stored data.
        • Cancel reindex archive: Cancels reindexing between the index file and the actual stored data.
      • Event rule
        • Edit rule: Changes the Trigger or Action settings of an event rule. A log is recorded even if the same values are saved. However, no log is recorded if only the event rule name is changed.
        • Enable rule: Enables an event rule.
        • Disable rule: Disables an event rule.
        • Delete rule: Deletes an event rule.
        Note: Creating an event rule is not recorded in the audit log.
    • Users: Click the user filter to display a list of users. Select a user and click .
      • For details on users, see Users.
    • Devices: Click the devices filter to display a list of devices. Select the device and click Select.
      • Click All devices to select all devices connected to BLAZE.
      • Use the search bar to find devices by name.
  3. Logs matching the selected filters appear in the results list.
    • Time: Displays when the event occurred, based on the system time zone.
    • User: Displays the name of the user who performed the action.
    • Action: Displays the recorded action type.
    • Description: Additional information about the event. The description for each action is shown in the table below.
      Action Description
      Add device
      • Source: {Device model name}
      • Mac: {Device Mac address}
      • Server: {Server name}
      Delete device
      • Source: {Device model name}
      • Mac: {Device Mac address}
      • Server: {Server name}
      Edit recording settings
      • Source: {Channel name}
      • Recording: Recording mode
      Add license
      • Source: {Channel name}
      Deactivate license
      • Source: {Channel name}
      Edit PTZ settings
      • PTZ: {PTZ settings}
      • Source: {Channel name}
      Restart device
      • Source: {Device model name}
      Reset device
      • Source: {Device model name}
      Add server
      • Source: {Server name}
      Detach server
      • Source: {Server name}
      Edit time settings
      • Source: {Server name}
      Edit storage settings
      • Storage: Drive
      • Source: {Server name}
      Format storage
      • Storage: HDD drive
      • Source: {Server name}
      Edit failover settings
      • Source: {Server name}
      Edit network settings
      • When the server network is set to IP and multiple network settings are changed
        • Change: IP/Port
        • Source: {Server name}
        • Network: Network number
        • Address: Server IP address:Server port number
      • When the server network is set to DHCP and a single network setting is changed
        • Change: DHCP
        • Source: {Server name}
        • Network: Network number
        • Address: Server IP address:Server port number
      • When the server network is set to DHCP and multiple network settings are changed
        • Change: DHCP
        • Source: {Server name}
        • Network: Network number
        • Address: Server IP address:Server port number
        • Network: Network number
        • Address: Server IP address:Server port number
      Edit PoE settings
      • Port: Port number
      • Source: {Server name}
      Restart server
      • Source: {Server name}
      Shut down server
      • Source: {Server name}
      Reset server
      • Reset to factory defaults
        • Reset type: Reset to factory defaults
        • Source: {Server name}
      • Reset to factory defaults except the network parameters
        • Reset type: Reset to factory defaults (except network settings)
        • Source: {Server name}
      • Reset to factory defaults and delete all stored data
        • Reset type: Reset to factory defaults (including stored data)
        • Source: {Server name}
      Start backup
      • Backup: {manual backup file name}
      Start restore
      • Restore: {restore file name}
      Create RAID / Delete RAID / Rebuild RAID
      • {Volume index and configured disk numbers for the created, deleted, or rebuilt volume} (e.g., Volume 1 (disk 1, 2, 3, 4))
      • Source: {Server name}
      Note:

      For RAID formatting details, the volume index and disk information are recorded in the "Format storage" log.

      Edit cloud settings
      • Action: {Cloud action}
      Add user
      • User: {User name}
      • Role: {Role name}
      Delete user
      • User: {User name}
      • Role: {Role name}
      Edit user
      • User: {User name}
      • Role: {Role name}
      Add role
      • Role: {Role name}
      Delete role
      • Role: {Role name}
      Edit role
      • Role: {Role name}
      Log in
      Log out
      Lock account
      • Number of login failures: {Failed login attempts}
      Lock account
      • Account locked for: {time} seconds
      View live
      • Source: {Channel name}
      • Duration: {Time} seconds/minutes/hours/days
      • Time range: {Time range}
      View archive
      • Source: {Channel name}
      • Duration: {Time} seconds/minutes/hours/days
      • Time range: {Time range}
      Export video
      • Source: {Channel name}
      • Time range: {Time range}
      Control PTZ
      • PTZ camera motion recording
        • Source: {Channel name}
        • Duration: {Time} seconds/minutes/hours/days
        • Command: {Command type}
      • Preset PTZ camera motion recording
        • Source: {Channel name}
        • Command: {Command type}
      Delete bookmark
      • Bookmark: {Bookmark name}
      • Source: {Channel name}
      Edit bookmark
      • Bookmark: {Bookmark name}
      • Source: {Channel name}
      Move device
      • Source: {Device model name}
      • From: {Original server name}
      • To: {New server name}
      Alarm output control
      • Source: {Alarm output name + device name}
      • Command: Activated, Deactivated

      The alarm name is displayed in the audit log even if the device has been deleted.

      Update software
      • Status: {Action}
      • Source: {Server name}
      • Original: {Original version}
      • To: {New version}
      Add license
      • License type: Free, Trial, Premium
      • License key: {License key number}
      • Source: {Server name}
      Extend license
      • License type: Premium
      • License key: {License key number}
      • Source: {Server name}
      Deactivate license
      • License type: Premium
      • License key: {License key number}
      Edit event rule
      • Event rule: {Event rule name}
      • If only the trigger (WHEN) is changed
        • Trigger: {First trigger name} and N more
      • If only the action (DO) is changed
        • Action: {First action name} and N more
      • If both the trigger and action are changed
        • Trigger: {First trigger name} and N more
        • Action: {First action name} and N more
      • No change (saved with the same values): No change
      Enable/Disable event rule
      • Event rule: {Event rule name}
      Delete event rule
      • Event rule: {Event rule name}
      • Displays the name of the first trigger (When) and action (Do) at the time of deletion.
      Start reindex archive
      • Source: {System name}
      Cancel reindex archive
      • Source: {System name}
    • Source IP: Displays the IP address of the source where the event occurred.
    • Client: Displays the system or device where the event occurred. Values include:
      • Desktop client (Windows), Desktop client (macOS), Desktop client (Linux)
      • Mobile client (Android), Mobile client (iOS)
    • Client IP: Displays the IP address of the client.
    • : Saves the audit log search results as a CSV file. The CSV file is saved in the Media folder in the path set in Client settings.
    • : Refreshes the audit log search results.
  4. Click an item in the results panel to open a detailed view of the selected event. For View live and View archive actions, buttons are provided to play the recorded video at the time the event occurred.

Audit log retention

Audit log data is retained for 90 days by default. The retention period can be configured in Audit log retention under Settings > General.