History & Audit Trail

SysWard history / audit trail

SysWard keeps an audit trail of what happened across your fleet — the jobs that ran, the events detected, and who initiated each one. History is available at three levels:

Each entry shows:

  • Type — the kind of event (for example a detected CVE, an upgrade, or a check-in)
  • Description — what happened
  • Date — when it happened
  • User — who performed it

Who performed an action

The User column attributes each action:

  • a user’s email — for actions a person initiated from the dashboard
  • System — for automated actions taken by the agent or SysWard itself
  • Unknown — when the action references a user who no longer exists

Edit this page on GitHub