Reading the audit log
Quick answer
Go to Developers → Audit Log. Every entry shows Time, User, Action, Resource, and Details, and you can filter by action (for example vm.create or kubernetes.*). It's the place to check who did what, and when, across your organisation.
Once more than one person has access to an account, "who changed that firewall rule" or "who deleted that VPS" stops being a question you can answer from memory. The audit log exists for exactly that: a chronological record of actions taken on your account, by user.
What's in a row
- Time: when the action happened.
- User: who did it. Shows System when an action wasn't triggered by a specific person's email, for example an automated process.
- Action: the action identifier, such as
vm.create. - Resource: which specific resource was affected.
- Details: whatever additional context that action carries.
Filtering
Use the action filter to narrow the log down, for example to everything under a resource family. A wildcard pattern like kubernetes.* matches every Kubernetes-related action, while vm.create matches one specific action exactly.
portal.worldstream.com/dashboard
Audit Log
Filter by action, e.g. vm.create
| Time | User | Action | Resource |
|---|---|---|---|
| 14:02 | owner@example.com | vm.create | my-web-server |
| 13:55 | System | backup.run | my-web-server |
Was this article helpful?