Skip to content

Audit log

The audit log answers "who changed this, and when?" for your whole account: changes made in the web portal, and sign-ins, PIN checks and commands at your on-site panels and WhiskerHMI PCs. Open it at Control Panel → Audit Log.

Note

The Audit Log tab is shown only to people in the View Audit Log role and to Account Admins (see Roles and permissions).

What is recorded

Only changes and security events are recorded. Looking at a page is not.

Recorded events include:

  • Sign-in and security: sign-ins and failed sign-ins at panels and PCs, PIN checks, PINs locked after too many attempts, sessions locked or timed out.
  • Equipment: commands, setpoint and mode changes sent from an HMI; device and gateway changes.
  • HMI design: HMIs created, edited or deleted; widgets added, edited or removed; background images and HMI roles changed.
  • Alerts: alerts created or edited; contacts added, edited or removed; schedule changes; alerts acknowledged or snoozed, and snoozes cancelled.
  • Account and people: account details, account role assignments, location roles, the HMI PIN policy, users created or edited, role memberships, password and PIN changes, PIN resets, roles created or renamed.
  • Locations, dashboards and reports: created, edited or deleted.

Every entry also records attempts that were refused because the person didn't hold the required role, so you can see who tried to do something they weren't allowed to.

Find events

The filters are at the top of the tab. Choose them, then click Apply.

Filter Options
Range Today, Last 24 hours, Last 7 days (the default), Last 30 days, or Custom… with From and To dates
User One person, or Any user
Source Where it happened: All panels, All PCs, Portal / cloud, or one panel or PC
Action One kind of event, or a whole group (for example user · (all))
Result OK, Denied or Failed
Search Text in the target, the value or the reason. Press Enter to apply
Denied only Only refused attempts
Security events only Only sign-in, PIN and other security events

Above the grid, a summary shows how many events, users, denied attempts and reporting sources the current filter covers.

Read the grid

Column Contents
When Date and time in your browser's time zone. Hover for the UTC time
Who The person, with a tag for how they were identified: Password, PIN, Offline PIN, API key, Kiosk, System or Portal. Nobody logged in means a panel in kiosk mode
Where The panel, PC or portal the event came from
Action What happened, for example Changed setpoint or Reset PIN
Target What it was done to
Change The old and new value, as old → new
Result OK (green), Denied (red) or Failed (orange). Hover for the reason
Location / Device The location, device and screen involved

The newest events are first. Click a column heading to sort, and use the pager at the bottom to see 50, 100 or 250 rows at a time. Click the arrow at the start of a row to see its full details.

Note

A red chain gap label means records from a panel or PC arrived out of sequence, so an event may be missing. If you see one, contact D6 Labs support.

Export

Click Export CSV to download the events that match the current filters as a spreadsheet file, for example for compliance records. Exporting is itself recorded in the audit log.

The location History tab

Each location also has a History tab, which lists activity at that location only. See Locations and HMIs. Use the audit log for account-wide changes, for panel and PC events, and for refused attempts.