Every change, every access — in one place.
A live activity trail of every device added, every policy changed, every connection allowed or denied. Searchable, filterable, and exportable to CSV or JSON — so when the auditor or the on-call asks "what happened?", you have an answer in seconds.
- Live-tail activity feed, refreshed in near real-time
- Filter by actor, resource, action, or date
- Export the full trail to CSV or JSON
- Searchable history for security reviews and incident response
Three jobs, one log.
Built for the moments that matter — incident review, compliance evidence, and a live view of what's happening now.
Post-incident review
Filter to the window when the outage started and read every device, policy change, and access event with full actor and source context.
filter: time 14:30–14:45 · action: deny Compliance evidence
Pick the audit window, then export the trail as CSV or JSON. Hand auditors a complete record instead of hand-rolled spreadsheets.
GET /admin/activity/export?format=csv Live activity view
Watch the feed in near real-time as devices join, policies change, and auth succeeds or fails — sorted newest-first.
live-tail · newest first · filterable The record an auditor would ask for.
Identity, access, and configuration events — recorded by default.
Identity & access events
Every login, SSH session, policy decision, and certificate action — with the actor and source that triggered it. Failed-auth bursts surface immediately.
- Login / logout
- SSH session start / end
- Allow / deny verdict per rule
- Certificate issued / rotated / revoked
Configuration changes
Policy edits, group membership updates, and role assignments — recorded with the actor who made the change and where they made it from.
# Recorded automatically
- allow group:devs → prod-db :22
+ deny group:devs → prod-db :22
actor: [email protected] · web ui Export to CSV or JSON
Download the full, filtered trail as CSV or JSON — large exports stream so they never time out. Take your audit data anywhere; there's no lock-in on your own record.
Streaming export to your SIEM
Planned: push events continuously to your SIEM over syslog, to S3, or to any webhook as they happen. Today, export is pull-based (CSV / JSON download) — streaming integrations are on the roadmap.
Know exactly what happened.
Live audit trail with filter and CSV / JSON export — free while we're in beta. No credit card required.