Skip to main content

View the DLP audit trail

View the audit trail to track all administration actions performed on the DLP service. Each action — creation, modification, deletion of DLP rules, DLP policies, DLP detectors, ruleset publication and user management — is recorded with the user, timestamp and action details.

Permissions

info

This action requires the following DLP (Data Loss Prevention) role:

  • viewer

Console

In the DLP console, click Audit Logs in the side menu.
  1. In the DLP console, click Audit Logs in the sidebar.

Filtering events

Use the available filters to refine the search:

  • Action: filter by action type — rule_create, rule_update, rule_delete, ruleset_publish, ruleset_rollback, detector_create, detector_update, detector_delete, policy_create, policy_update, policy_delete, user_create, user_update, user_delete, user_password_reset;
  • Time range: filter by time period.

Event details

Each event displays:

  • the user who performed the action;
  • the action type;
  • the action target (rule, detector, policy, user, ruleset);
  • the target name;
  • the action details;
  • the timestamp.