Reviewing audit logs
In the last recipe, we covered auditing actions taken directly on devices, which, while they can have a high impact, are on an individual device level, so less likely to cause significant issues. If, however, policies are amended, deleted, or created, there is a far greater chance of issues at a larger level. To monitor for such changes, we need to delve into the audit logs.
Getting ready
To access audit logs, click on Tenant administration | Audit logs.
How to do it...
Once you are on the Audit logs page, you will be presented with a familiar report-type screen. Again, there is a powerful filter option at the top, including the ability to filter on the activity. Be warned, however, that this is a long list and does not have any search functionality built in, so make sure you are selecting the correct option when using it.
The search box allows you to find the person who made the change and you can also sort by date and activity (but not the other...