Skip to main content

Reading the Audit Trail

The trail is read from two places, depending on the question you are asking.

The audit trail queried in Usage Statistics, one row per recorded action

QuestionWhere
What did this person do?Session History on their user record
Who did this, across everybody?Usage Statistics
Who can do what, as a document?The Security and Access Report

Starting from a person​

Most investigations start with somebody. Find them in the user list and open Session History — every sign-in, how long they stayed, how the session ended, and the audited actions within it.

This is the fastest route when you have a name, which you usually do.

Starting from an action or a period​

When the question is "who did this?" rather than "what did they do?", the Usage Statistics module queries the same records across all users, with the full query builder behind it — so you can filter by action type, period and user, and aggregate to find patterns.

Knowing what to search for​

This is where the Audit Catalog earns its place. Descriptions follow a fixed form, so searching is precise once you know the wording:

Looking forSearch on
Camera viewingCAMERA '
A specific cameraCAMERA 'North Entrance'
Alerts ignoredALERT IGNORED
Periods of mutingALERTS MUTED
Query exportsQUERY EXPORT
Face searchesSEARCHED FOR FACE

Check the catalog before searching rather than guessing at phrasing — it lists the exact template each action writes.

Reading time correctly​

Timestamps display in the time zone on your profile, while the records store real instants.

When comparing an eConnect record against an external one — a door system, a till, a statement — confirm which zone each is quoting. This is a common and consequential source of confusion, particularly around shift boundaries and midnight.

Duration tells you more than access​

Several actions record how long something was looked at, not merely that it was opened:

This action is recorded in the audit trail.

That distinction matters. "Opened the camera" and "watched it for twelve minutes" answer different questions, and only the second supports a claim that footage was actually reviewed.

What the trail can and cannot establish​

It can establish that an account performed an action, when, from where, and — for some actions — for how long.

It cannot establish that a particular person was at the keyboard. Shared credentials and unattended signed-in workstations both undermine attribution, which is the practical reason to discourage Save Password and Auto Login on shared machines. See Signing In.

Absence of evidence​

If an action is not in the trail, check the Audit Catalog before concluding it did not happen. Some things are recorded by the server rather than the client, and some reads are not audited at all — the catalog says which.

For a formal record​

For an access review, an audit or anything that needs filing, use The Security and Access Report. It produces a point-in-time PDF rather than a screen you would have to screenshot.

Audit record​

What eConnect writes to the audit trail for the actions on this page.

Close Cameratype 401CloseCamera
  • CAMERA '{camera name}' REVIEWED FOR {elapsed}