Exporting evidence
Export audit or lineage records when you need to share evidence in formal processes.
When to use this
- Use it in audits, access reviews, or investigations.
- Use it when evidence has to be attached to a ticket or a report.
- Use it when another area needs to validate actions taken in the Console.
Before you start
- Define the investigation's period and filters.
- Confirm who may receive the evidence.
- Check whether the export contains sensitive user or usage data.
Step by step
- Open Audit Center or Lineage.
- Apply filters to reduce the export to what is needed.
- Review the results on screen.
- Use the export action.
- Save the file according to your organization's policy.
- Share it only with authorized people.
What happens next
- The evidence can be analyzed outside the Console.
- The export has to be protected as sensitive information.
- New events do not enter a file that has already been exported.
Common errors
- Exporting with no filters: it produces excess data and raises risk.
- Sending evidence to an unauthorized recipient.
- Using old evidence without checking whether there have been new actions.
Good practice
- Export the minimum needed for the purpose.
- Include the period, the filters, and who exported it in the process.
- Store evidence somewhere controlled.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.