Audit Log Tool

The Audit Log Tool lets you search, filter, and export a record of actions taken on reports, cases, incidents, and other items in Axon Records and Axon Standards. If your organization is configured for both products, the Audit Log Tool shows actions taken in both products. You can open the tool from either the Axon Records or Axon Standards Administrator Console.

Generate audit logs

To generate an audit log, take these steps:

  1. Open the Administrator Console and select Audit Log Tool.
  2. Enter a date range in the Date Range filter.
    • You can search a single day or a range of up to one year.
  3. Set at least one additional filter. You can't generate an audit log using a date range alone:
    • Actors: Filter by one or more users whose actions you want to audit.
      • Search for a user by name, username, or badge ID, then select Apply. Repeat to add more actors.
    • Targets: Filter by one or more target types. Options include Report, Case, Investigation, Event, Standards Case, Incident, Location, Person, Property, Vehicle, User, Analytics, and Privilege.
      • After selecting a target type, enter a specific ID for that item (e.g., Report ID), and select Apply. Repeat to add more targets.
    • Event Types: Filter by one or more event types.
    • Audit Types: Search by one or more audit types. Options include:
      • Print: The audit log includes all print-related events (printing of activity logs, reports, profiles, etc.).
      • Datastore Access Control: The audit log includes all events related to DataStore settings and access control.
    • After setting at least two filters, you can select Reset to remove all filters.
  4. Once your filters are set, choose one of the following:
    • Search: Run your query and display the results in the tool. You can export results after the preview.
    • Export CSV/PDF: Export your results without previewing them first.
  5. If your filters include too many results to be displayed or exported, an error displays. Add additional filters or shorten your date range to reduce the number of results and select Search or Export again.

Audit log columns

The columns included in the Audit Log Tool preview and in audit log CSV exports include:

  • Event: The event that occurred
  • ID: The ID generated for the event
  • Occurred on: The date and time the event occurred, including hundredths of a second
  • Source: Whether the event originated in Axon Records, Axon Standards, or an integrated source
  • IP address: The IP address of the actor who performed the action
  • Device Name: The browser and operating system associated with the action
    • Because Axon Records and Axon Standards are browser based, this reflects browser and OS information rather than physical device information.
  • Actors: The user or integration that performed the action
  • Details: Additional information about the event
    • Details vary depending on the event type.
  • Targets: The item type the action was taken on

Audit log PDF exports include fewer columns with the above information combined in the columns as follows:

  • Occurred on
  • Activity: Includes Details, IP address, and device name
  • Targets

Multi-target events

Some actions affect more than one target at once. For example, when you add a person to a report, an event is logged both for the person and the report. As a result, the event appears when you generate an audit log for the report and the person.

Open and View events

The audit log distinguishes between when a user views a document, a Records incident, or a Standards event in search results or in a task inbox and when they actually open the item. View events indicate that the item was viewed in a list. Open events indicate the item was actually opened and its full contents were accessed. The search keywords the user entered are also included in the log. For example, the following audit log entries indicate that the user:

  1. Ran a search for "202607".
  2. Viewed a list of 3 incidents in the search results
  3. Opened incident ID 20260715 but did not open any of the other incidents.
Event Details

Search Incidents

Shaw, Lyvia (LShaw001) searched Records incidents. Keyword: "202607". Results: 3

View Incident

Shaw, Lyvia (LShaw001) viewed Incident ID 20260715

View Incident

Shaw, Lyvia (LShaw001) viewed Incident ID 20260714

View Incident

Shaw, Lyvia (LShaw001) viewed Incident ID 20260713

Open Incident

Shaw, Lyvia (LShaw001) opened Incident ID 20260715

Axon Records integration View events

The audit log includes automated retrievals of documents. These events appear in the log as "Axon Records Integrations viewed Document ID". These events do NOT indicate that a human viewed the listed document. Instead, this event can be triggered by integrations with third-party systems, or other automated retrievals.

Common causes of this event include:

  • Call for Service (CFS) re-import / CAD lookback: This is one of the most common reasons the Integrations Viewed event occurs.
  • Report import duplication checks
  • NIBRS / IBR submission
  • Adding supplements
  • Adding evidence to a report
  • Query incident: For example, as a result of an integration with a crash reporting system, an incident is searched for in Axon Records so information from the external system can be attached to it.

The name shown in the audit log may vary depending on the integration or system that triggered it (e.g., Axon Records, AxonDataPlatform, etc.). You can check the list of integrations that have been created for your organization by logging in to Axon Evidence and selecting Admin in the main navigation menu. In the Organization settings section, select Integrations and switch to the API clients tab. Look in the Client name column for the name that matches the name listed in the audit log.