Skip to main content

Exporting evidence

Export audit or lineage records when you need to share evidence in formal processes.

When to use this​

  • Use it in audits, access reviews, or investigations.
  • Use it when evidence has to be attached to a ticket or a report.
  • Use it when another area needs to validate actions taken in the Console.

Before you start​

  • Define the investigation's period and filters.
  • Confirm who may receive the evidence.
  • Check whether the export contains sensitive user or usage data.

Step by step​

  1. Open Audit Center or Lineage.
  2. Apply filters to reduce the export to what is needed.
  3. Review the results on screen.
  4. Use the export action.
  5. Save the file according to your organization's policy.
  6. Share it only with authorized people.

What happens next​

  • The evidence can be analyzed outside the Console.
  • The export has to be protected as sensitive information.
  • New events do not enter a file that has already been exported.

Common errors​

  • Exporting with no filters: it produces excess data and raises risk.
  • Sending evidence to an unauthorized recipient.
  • Using old evidence without checking whether there have been new actions.

Good practice​

  • Export the minimum needed for the purpose.
  • Include the period, the filters, and who exported it in the process.
  • Store evidence somewhere controlled.

Next steps​