Skip to main content
On this page

Activity Logs provide a searchable, tamper-resistant record of actions performed in DEUNA Admin. Use them to investigate changes, verify access, and prepare audit evidence without piecing together multiple tools.

Investigate activity#

In DEUNA Admin, open Logs to access Change history. Start with the incident window, narrow the results, and inspect only the events that explain the change.

01 · scope
Set the window
Choose a date range of up to 90 days and the merchant you need to investigate.
02 · filter
Find the activity
Search by user and filter by section, action, severity, or result.
03 · inspect
Verify the event
Open a row to review its actor, source, outcome, and sanitized metadata.
04 · retain
Export evidence
Download the minimum filtered record set required by your process.
Interactive exampleUses sample data and does not make API requests.
Production
Security and audit

Activity logs

Trace who changed what, when it happened, and whether it succeeded.

Sample events · UTC
4 sample eventsLatest event first
CreatedExecuted byActionSectionIP addressResult
maria@acme.comrouting.rule.updatedRouting190.12.44.18Success
diego@acme.comconnections.processor.updatedConnections181.54.20.91Success
sofia@acme.comusers.role_permissions.updatedUsers200.31.12.77Success
ana@acme.comsecurity.2fa_challenge.verifiedSecurity201.221.8.34Failure

The example uses fictional data. Search, switch sections, and select a row to see how an investigation moves from the activity list to a specific event.

Why use Activity Logs#

BenefitWhat it means for your team
Faster investigationsCompare an incident window with configuration, login, and operational activity.
AccountabilityIdentify the user, role, action, time, and result associated with each event.
Security visibilityReview authentication, 2FA, password reset, account lock, and access activity.
Compliance supportUse append-only records and exports as evidence. Activity Logs support your compliance program; they do not replace it.
Data protectionSensitive values such as card numbers, CVV, passwords, one-time passwords, and credentials are removed or masked before storage.
Tenant isolationMerchant users see only their merchant's records. Network users see records for merchants in their network, with merchant attribution preserved.

Before you begin#

Confirm that your role includes audit_log.view, plus audit_log.export if you need to generate or download files. You should also know the merchant and approximate date range associated with the activity. Users without view permission do not see Logs.

View activity records#

  1. Sign in to DEUNA Admin.
  2. Open Logs.
  3. Choose a date range. Each query can cover up to 90 days.
  4. Search for a user or apply filters to narrow the results.
  5. Select a row to inspect the event details.

Records appear with the most recent event first. New events typically become available within five minutes. Use Columns to select visible fields and Refresh to load the latest records.

FieldDescription
Creation dateWhen the event occurred. DEUNA stores UTC and displays your local time zone.
Executed byEmail address of the user who performed the action.
ActionHuman-readable action name, such as Routing rule viewed.
SectionDEUNA Admin area associated with the action, such as Configurations, Routing, or Connections.
IPSource IP address of the request.

Inspect an event#

Expand a record to see its complete context. Use Details for a formatted view or JSON for the raw event.

FieldDescription
merchantIdMerchant associated with the event.
userIdUser who performed the action.
actorRoleRole assigned to the actor at the time of the event.
eventSeverityImpact level: LOW, MEDIUM, HIGH, or CRITICAL.
eventResultOutcome: SUCCESS or FAILURE.
originUserAgentBrowser or client that sent the request.
originSessionIdSession in which the action occurred.
metadataApproved, sanitized event context, such as an affected resource identifier. Contents vary by event.

SUCCESS means the action completed as intended. FAILURE means it did not complete; metadata can include a sanitized failure reason.

Search and filter records#

  • Search by email or name to find activity associated with a user.
  • Filter by date with a required range of up to 90 days.
  • Add filter to refine by section, action, severity, result, or another available field.

Start with a narrow date range, then add section and action filters. This creates a reliable timeline before you broaden the search.

Export records#

  1. Apply the date range and filters you need.
  2. Select Export and confirm the request.
  3. Open Downloads.
  4. Wait until the file is ready, then download it.

Exports run asynchronously and contain the records that matched your filters when the export was requested.

ConstraintValue
Maximum date range90 days per export
Maximum records10,000 per export
Concurrent exports3 per merchant
File formatGzip-compressed UTF-8 CSV with semicolon (;) separators
File availability7 days after creation
Download link validity15 minutes

If a link expires, request a new one from Downloads. Export requests and downloads are also recorded as exports.requested and exports.downloaded events.

Permissions#

PermissionAllows
audit_log.viewOpen Logs, search and filter records, and inspect event details.
audit_log.exportRequest exports and download generated files.

Data protection and retention#

  • Append-only records: Activity records cannot be edited or deleted from DEUNA Admin or the API. A required redaction creates a new event that references the original.
  • Sensitive-data sanitization: PAN, CVV, track data, passwords, OTP codes, reset tokens, API keys, and secrets are masked or removed before storage.
  • Encryption: Data is protected in transit with TLS 1.2 or later and encrypted at rest.
  • Retention: Records are retained for 365 days and typically appear within five minutes.

Available events#

Event names follow <domain>.<resource>.<action>. For example, routing.rule.updated identifies the Routing domain, a routing rule, and an update. Availability depends on the DEUNA products and features enabled for the account.

Authentication2 events
EventDescription
auth.login.verifiedA user's login was verified and a session started.
auth.logout.verifiedA user logged out and the session ended.
Security16 events
EventDescription
security.2fa_policy.updatedThe merchant's two-factor authentication policy changed.
security.2fa_method.setupA user configured a two-factor authentication method.
security.2fa_method.disabledA user's two-factor authentication method was disabled.
security.2fa_challenge.viewedA two-factor authentication challenge was presented.
security.2fa_challenge.verifiedA user submitted a challenge. Check eventResult for the outcome.
security.2fa_backup_codes.generatedNew two-factor authentication backup codes were generated.
security.2fa_backup_codes.verifiedA user attempted to verify with a backup code.
security.account.lockedA user account was locked.
security.account.unlockedA locked user account was unlocked.
security.password.reset_requestedA password reset was requested.
security.password.reset_completedA password reset was completed.
security.block.appliedBrute-force protection applied an access block.
security.block.clearedAn access block was cleared.
security.user.overriddenA user security restriction was manually overridden.
security.user.status_updatedA user's status changed.
security.email.sentA security-related email was sent.
Users and roles6 events
EventDescription
users.user.createdA user was added to the merchant.
users.user.updatedA user's details were modified.
users.user.deactivatedA user was deactivated.
users.role.createdA role was created.
users.role.updatedA role was modified.
users.role_permissions.updatedPermissions assigned to a role changed.
Exports2 events
EventDescription
exports.requestedA user requested an Activity Log export.
exports.downloadedA user downloaded an export file.
Orders3 events
EventDescription
orders.capturedAn order payment was captured.
orders.refundedAn order payment was refunded.
orders.voidedAn order authorization was voided.
Merchant configuration11 events
EventDescription
configurations.merchant_policy.createdA merchant policy was created.
configurations.merchant_policy.updatedA merchant policy was modified.
configurations.merchant_policy.deletedA merchant policy was deleted.
configurations.merchant_policy.viewedA merchant policy was viewed.
configurations.merchant_profile.updatedThe merchant profile was modified.
configurations.merchant_profile.viewedThe merchant profile was viewed.
configurations.widget_3ds.updatedThe 3DS widget configuration was modified.
configurations.widget_3ds.viewedThe 3DS widget configuration was viewed.
configurations.order_config.updatedThe order configuration was modified.
configurations.payment_config.updatedThe payment configuration was modified.
configurations.payment_config.viewedThe payment configuration was viewed.
Routing6 events
EventDescription
routing.rule.createdA routing rule was created.
routing.rule.updatedA routing rule was modified.
routing.rule.enabledA routing rule was enabled.
routing.rule.disabledA routing rule was disabled.
routing.rule.reorderedThe priority order of routing rules changed.
routing.rule.viewedA routing rule was viewed.
Connections4 events
EventDescription
connections.processor.createdA processor connection was created.
connections.processor.updatedA processor connection was modified.
connections.processor.disabledA processor connection was disabled.
connections.processor.viewedA processor connection was viewed.
Installments3 events
EventDescription
installments.campaign.createdAn installment campaign was created.
installments.campaign.updatedAn installment campaign was modified.
installments.campaign.viewedAn installment campaign was viewed.
Error management4 events
EventDescription
error_management.processor_error.createdA processor error mapping was created.
error_management.processor_error.viewedA processor error mapping was viewed.
error_management.processor_error.updatedA processor error mapping was modified.
error_management.processor_error.deletedA processor error mapping was deleted.
Subscriptions6 events
EventDescription
subscriptions.subscription.createdA subscription was created.
subscriptions.subscription.updatedA subscription was modified.
subscriptions.subscription.viewedA subscription was viewed.
subscriptions.subscription.pausedA subscription was paused.
subscriptions.subscription.canceledA subscription was canceled.
subscriptions.subscription.reactivatedA paused or canceled subscription was reactivated.
Batch operations2 events
EventDescription
batch_operations.batch_job.createdA batch job was created.
batch_operations.batch_job.viewedA batch job was viewed.

Example: investigate an approval-rate change#

  1. Set the date range from the day before the drop through the affected day.
  2. Filter Section by Routing and Connections.
  3. Look for routing.rule.updated, routing.rule.disabled, routing.rule.reordered, or connections.processor.disabled.
  4. Open each relevant record and confirm the actor, time, IP, user agent, result, and affected resource in metadata.
  5. Export the filtered timeline only when it needs to be shared or retained outside DEUNA Admin.

Continue operating securely#