# Review a system's audit log

> Inspect a system's recorded activity, read event context, and narrow the timeline with search and filters.

Canonical URL: http://modelmonster.ai/docs/managing-systems/system-audit-log/

## Article Metadata

- Reading time: 3 min

When you review a system, you often need to know who or what acted, what happened, and when. The **System Audit Log** presents recorded events for one system in a readable timeline, giving you traceability for investigation, reporting, and oversight. Start with the **Recent activity** summary, then open the full history to inspect and filter its events.

## Before you begin

Sign in to Model Monster and open a system you can access. Audit history is available for systems with or without a released version.

## Open the system's audit history

1. Select **Systems**, then open the system you want to review.
2. Select **Overview** and find **Recent activity**.

![Recent activity on the SRE Agent Overview with several demo events, a total count, and Open full audit log](/media/original_images/visual-1-sre-agent-recent-activity.png)

**Recent activity** gives you a compact view of the latest recorded events. Use it to orient yourself before moving into the full history.

3. Select **Open full audit log**.

![Populated System Audit Log for SRE Agent with search, actor and action filters, result count, and demo event rows](/media/original_images/visual-2-sre-agent-audit-log.png)

The **System Audit Log** page shows search and filter controls, a count of matching events, and the timeline ordered with the newest event first.

> **Note:** **Recent activity** is the quick view of this system history. **System Audit Log** is the full inspection surface.

## Read an audit event

Each event is a readable summary of an action and its available context. Start at the top of the row, then work through its details.

![SRE Agent events showing labels, Marcellus actor details, revision and version context, badges, and timestamps](/media/original_images/visual-3-sre-agent-audit-event-source.png)

Context varies by event. Details generally include:

1. **Action and event.** An action badge such as **Updated** or **Created** tells you the general kind of change. The event label adds context, with examples such as **Policy Change**, **Review Submitted**, or **Review Cancelled**. Available labels depend on the events recorded for the system.
2. **Affected object.** The object type and summary describe what happened. **Target** identifies the policy, version, system, or other object involved.
3. **Actor.** **Actor** identifies the person associated with the event. When an event has no person to display, the actor can appear as **System**.
4. **System context.** The row includes the system name and its visible identifier, labeled **System UID**. It may also include **Revision** or **Version** when that context applies to the event.
5. **Timestamp.** Events show a timestamp in `YYYY-MM-DD HH:mm:ss` format. Use the displayed timestamp when comparing activity.

The **System** badge confirms that the event belongs to the current system's history. Together, these fields help you answer what changed, who or what acted, what was affected, and when it occurred.

## Narrow the timeline

Use search and filters to focus the timeline on the events relevant to your review question.

1. Enter a person, event, target, or summary term in **Search audit logs**.
2. To focus on one person, open **All actors** and select an actor. The available choices come from this system's event history.

![Open All actors selector showing All actors and the publication-safe Marcellus demo account](/media/original_images/visual-4-sre-agent-actor-filter.png)

3. To focus on a kind of action, open **All actions** and select an available action.

![Open All actions menu showing All actions and Updated from the SRE Agent demo history](/media/original_images/visual-5-sre-agent-action-filter.png)

Search, actor, and action controls work together. As you change them, the display updates to reflect the current result set.

![SRE Agent audit timeline with Policy in Search audit logs, Updated active, and Showing 2 of 20 system events](/media/original_images/visual-6-sre-agent-filtered-audit-log.png)

Select **Clear search audit logs** to remove the text query while keeping your actor and action choices. To restore the full timeline, return those selectors to **All actors** and **All actions**.

## Use the timeline for the right review question

Use the **System Audit Log** when your question concerns recorded system events: who or what acted, what happened, which target or version context was involved, and when. This focused history supports investigation, traceability, reporting, and oversight of supported system changes and governance actions.

For a version-focused question, use **System Versions** instead. The audit log presents recorded events, while System Versions tracks version status, metadata, and historical versions.

## Next steps

- Read [System Versioning Model](/docs/managing-systems/system-versioning-model/) when you need to review version lifecycle and historical versions.
- Read [Organization Audit Log](/docs/organization-and-administration/organization-audit-log/) for organization-wide history in **Overview → Audit Logs**.
