Moorfox

Documentation

The activity log and audit trail

Quick answer

Activity in the sidebar is the organisation's audit trail: what changed, who changed it, on which machine, and how they were connected when they did it.

It is append-only. There are no edit or delete controls, and not because they are hidden from you: the API does not offer them to anyone, admins included. A trail somebody could tidy up would not be worth reading.

The Moorfox activity log showing when, user, activity, device, category and via columns, with category filter badges and a search box above
The log, newest first. The badges filter by category; the search box matches across summaries, users, devices and details.

What each column tells you

ColumnWhat it holds
WhenToday's entries as a time, older ones with the date, because a trail is mostly read as \u201cwhat happened on Tuesday\u201d. The exact timestamp is in the tooltip.
UserWho did it. Entries the agent raised on its own say agent.
ActivityWhat happened, with the specifics listed underneath where there are any.
DeviceThe machine it happened to, linked. A device that has since been forgotten shows its raw ID instead: the log outlives the devices it mentions, and an entry losing its subject would be worse than an unlinked identifier.
CategoryWhich of the five kinds of activity this is.
ViaHow the action reached us, which is how a dashboard click is told apart from an API call.

The five categories

CategoryWhat lands in it
AdministrationChanges to the organisation itself: users, roles, settings, groups, tags, alert rules.
Remote managementGetting onto machines: remote desktop sessions, terminal, file transfers, process and service actions.
Device managementChanges to devices: enrolment, renaming, grouping, tagging, archiving, agent updates and rollbacks.
AuthenticationSign-ins, sign-outs, and invitations being redeemed.
AutomationSaved commands and flows running, and what they did. See automation.

Reading it

The badges above the table narrow it to one category, which is usually the fastest route to an answer: Authentication for "who signed in", Remote management for "who was on that machine", Administration for "who changed that setting".

The search box filters what is loaded across summaries, user, device and the detail lines together, so a hostname, an address or a fragment of a command all find their entries.

The log loads a hundred entries at a time, with Load older entries at the bottom for the rest.

The search box filters the entries already loaded, not the whole history. If you are hunting something old, page back with Load older entries first, or narrow by category and then search.

What it is good for

Three questions, mostly. Who touched this machine? Filter to Remote management and read the device column. Why did this setting change? Filter to Administration and find the entry, which names the user. Did that automation actually run? Filter to Automation.

It is also the answer to the audit question a customer or an insurer eventually asks, which is not "do you have logs" but "can anyone edit them". Here, no.

Moorfox is remote monitoring and management without the enterprise tax.

One agent, one dashboard, remote desktop and a real terminal on every machine you look after.

Start free