Activity Logs

Track who performed an action, what changed, when it happened, where it originated, and whether it succeeded in DEUNA Admin.

Activity Logs provide a searchable, tamper-resistant record of actions performed in DEUNA Admin. Use them to identify who performed an action, what changed, when it happened, where the request originated, and whether it succeeded.

In DEUNA Admin, open Logs to access the Change history page.

📘

Activity Logs are an observability and audit feature. Recording an event does not affect payment authorization, checkout, or order processing. Activity Logs are not supported in the sandbox environment.

Why use Activity Logs

Configuration changes can affect approval rates, processing costs, account access, and security. Activity Logs centralize the information your team needs to investigate those changes.

BenefitWhat it means for your team
Faster investigationsCompare an incident window with configuration, login, and operational activity.
AccountabilityIdentify the user, role, action, time, and result associated with each event.
Security visibilityReview authentication, 2FA, password reset, account lock, and access activity.
Compliance supportUse append-only records and exports as evidence for internal audits and compliance processes. Activity Logs support your compliance program; they do not replace it.
Data protectionSensitive values such as card numbers, CVV, passwords, one-time passwords, and credentials are removed or masked before an event is stored.
Tenant isolationMerchant users see only their merchant's records. Network users see records for merchants in their network, with merchant attribution preserved.

Common use cases

  • Investigate an approval-rate change: Review Routing and Connections events around the time the rate changed.
  • Review a permission issue: Search by user and inspect role and permission updates.
  • Investigate suspicious access: Review authentication and security events together with their IP address and user agent.
  • Prepare audit evidence: Export the relevant date range and filters to CSV.
  • Confirm a planned change: Verify what changed, who applied it, and whether the action succeeded.

Prerequisites

Before using Activity Logs, confirm that:

  • Your role includes permission to view Activity Logs.
  • Your role includes export permission if you need to generate or download files.
  • You know the merchant and approximate date range associated with the activity you want to review.

Users without view permission do not see the Logs section.

View activity records

  1. Sign in to DEUNA Admin.
  2. Open Logs from the navigation menu.
  3. Choose a date range. Each query can cover up to 90 days.
  4. Search for a user or apply filters to narrow the results.
  5. Select a row to inspect the event details.

Records appear with the most recent event first. New events typically become available within five minutes.

Record list fields

FieldDescription
Creation dateDate and time when the event occurred. DEUNA stores the time in UTC and displays it in your local time zone.
Executed byEmail address of the user who performed the action.
ActionHuman-readable action name, such as Routing rule viewed.
SectionArea of DEUNA Admin associated with the action, such as Configurations, Routing, or Connections.
IPSource IP address of the request.

Use Columns to select the visible fields. Select Refresh to load the latest records.

Inspect an event

Expand a record to see its complete context. Use the Details tab for a formatted view or the JSON tab for the raw event.

FieldDescription
merchantIdIdentifier of the merchant associated with the event.
userIdIdentifier of the user who performed the action.
actorRoleRole assigned to the actor at the time of the event.
eventSeverityEvent impact level: LOW, MEDIUM, HIGH, or CRITICAL.
eventResultEvent outcome: SUCCESS or FAILURE.
originUserAgentBrowser or client that sent the request.
originSessionIdIdentifier of the session in which the action occurred.
metadataApproved, sanitized context specific to the event, such as the affected resource identifier. Contents vary by event.

Severity levels

SeverityMeaningExamples
LOWRoutine, expected activity.Successful login or viewing a configuration.
MEDIUMModerate-impact activity.Updating a role or requesting an export.
HIGHHigh-impact or sensitive activity.Disabling routing or updating credentials.
CRITICALSecurity or business-critical risk.Account lockout, disabling 2FA, or repeated authentication failures.

Result values

  • SUCCESS: The action completed as intended.
  • FAILURE: The action did not complete. The metadata object may include a sanitized failure reason.

Search and filter records

Use the available controls to focus your investigation:

  • Search by email or name: Find activity associated with a specific user.
  • Filter by date: Select a required date range of up to 90 days.
  • Add filter: Refine the results by section, action, severity, result, or another available field.

Start with a narrow date range, then add section and action filters. This makes it easier to establish a timeline before expanding the search.

Export records

  1. Apply the date range and filters you need.
  2. Select Export.
  3. Confirm the export request.
  4. Open the Downloads tab.
  5. Wait until the file is ready, then download it.

Exports run asynchronously and include the records that match your filters.

ConstraintValue
Maximum date range90 days per export
Maximum number of records10,000 per export
Concurrent exports3 per merchant
File formatGzip-compressed, UTF-8 CSV with semicolon (;) separators
File availability7 days after creation
Download link validity15 minutes

If a link expires, request a new one from Downloads. Export requests and downloads are also recorded as exports.requested and exports.downloaded events.

Permissions

Activity Log access is controlled through Roles and permissions.

PermissionAllows
audit_log.viewOpen Logs, search and filter records, and inspect event details.
audit_log.exportRequest exports and download generated files.
🔐

Apply the principle of least privilege. Grant export access only to users who need to retrieve audit evidence outside DEUNA Admin.

Data protection and retention

  • Append-only records: Activity records cannot be edited or deleted from DEUNA Admin or the API. If a record must be redacted, DEUNA creates a new event that references the original.
  • Sensitive-data sanitization: PAN, CVV, track data, passwords, OTP codes, reset tokens, API keys, and secrets are masked or removed before storage.
  • Encryption: Data is encrypted in transit using TLS 1.2 or later and encrypted at rest.
  • Retention: Records are retained for 365 days.
  • Availability: New events typically appear within five minutes.

Available events

Event names follow the <domain>.<resource>.<action> convention. For example, routing.rule.updated identifies the Routing domain, a routing rule resource, and an update action.

The events available to your account can depend on enabled DEUNA products and features.

Authentication

EventDescription
auth.login.verifiedA user's login was verified and a session started.
auth.logout.verifiedA user logged out and the session ended.

Security

EventDescription
security.2fa_policy.updatedThe two-factor authentication policy for the merchant was changed.
security.2fa_method.setupA user configured a two-factor authentication method.
security.2fa_method.disabledA user's two-factor authentication method was disabled.
security.2fa_challenge.viewedA two-factor authentication challenge was presented to a user.
security.2fa_challenge.verifiedA user submitted a two-factor authentication challenge. Check eventResult for the outcome.
security.2fa_backup_codes.generatedA new set of two-factor authentication backup codes was generated for a user.
security.2fa_backup_codes.verifiedA user attempted to verify with a two-factor authentication backup code. Check eventResult for the outcome.
security.account.lockedA user account was locked, for example, after repeated failed sign-in attempts.
security.account.unlockedA locked user account was unlocked.
security.password.reset_requestedA password reset was requested for a user.
security.password.reset_completedA password reset was completed.
security.block.appliedAn access block was applied by the platform's brute-force protection.
security.block.clearedAn access block was cleared.
security.user.overriddenA security restriction on a user was manually overridden.
security.user.status_updatedA user's status, such as active or blocked, was changed.
security.email.sentA security-related email was sent to a user.

Users and roles

EventDescription
users.user.createdA new user was added to the merchant.
users.user.updatedA user's details were modified.
users.user.deactivatedA user was deactivated and can no longer access DEUNA Admin.
users.role.createdA new role was created.
users.role.updatedA role was modified.
users.role_permissions.updatedThe permissions assigned to a role were changed.

Exports

EventDescription
exports.requestedA user requested an export of Activity Log records.
exports.downloadedA user downloaded an export file.

Orders

EventDescription
orders.capturedAn order payment was captured.
orders.refundedAn order payment was refunded.
orders.voidedAn order authorization was voided.

Merchant configuration

EventDescription
configurations.merchant_policy.createdA merchant policy was created.
configurations.merchant_policy.updatedA merchant policy was modified.
configurations.merchant_policy.deletedA merchant policy was deleted.
configurations.merchant_policy.viewedA merchant policy was viewed.
configurations.merchant_profile.updatedThe merchant profile was modified.
configurations.merchant_profile.viewedThe merchant profile was viewed.
configurations.widget_3ds.updatedThe 3DS widget configuration was modified.
configurations.widget_3ds.viewedThe 3DS widget configuration was viewed.
configurations.order_config.updatedThe order configuration was modified.
configurations.payment_config.updatedThe payment configuration was modified.
configurations.payment_config.viewedThe payment configuration was viewed.

Routing

EventDescription
routing.rule.createdA routing rule was created.
routing.rule.updatedA routing rule was modified.
routing.rule.enabledA routing rule was enabled.
routing.rule.disabledA routing rule was disabled.
routing.rule.reorderedThe priority order of routing rules was changed.
routing.rule.viewedA routing rule was viewed.

Connections

EventDescription
connections.processor.createdA processor connection was created.
connections.processor.updatedA processor connection was modified.
connections.processor.disabledA processor connection was disabled.
connections.processor.viewedA processor connection was viewed.

Installments

EventDescription
installments.campaign.createdAn installment campaign was created.
installments.campaign.updatedAn installment campaign was modified.
installments.campaign.viewedAn installment campaign was viewed.

Payment links

EventDescription
payment_links.payment_link.createdA payment link was created.
payment_links.payment_link.viewedA payment link was viewed.
payment_links.payment_link.deactivatedA payment link was deactivated.

Error management

EventDescription
error_management.processor_error.createdA processor error mapping was created.
error_management.processor_error.viewedA processor error mapping was viewed.
error_management.processor_error.updatedA processor error mapping was modified.
error_management.processor_error.deletedA processor error mapping was deleted.

Subscriptions

EventDescription
subscriptions.subscription.createdA subscription was created.
subscriptions.subscription.updatedA subscription was modified.
subscriptions.subscription.viewedA subscription was viewed.
subscriptions.subscription.pausedA subscription was paused.
subscriptions.subscription.canceledA subscription was canceled.
subscriptions.subscription.reactivatedA paused or canceled subscription was reactivated.

Batch operations

EventDescription
batch_operations.batch_job.createdA batch job was created.
batch_operations.batch_job.viewedA batch job was viewed.

Example: investigate an approval-rate change

A merchant notices that its approval rate dropped on a specific day.

  1. Open Logs and set the date range to the day before the drop through the end of the affected day.
  2. Filter Section by Routing and Connections.
  3. Look for events such as routing.rule.updated, routing.rule.disabled, routing.rule.reordered, or connections.processor.disabled.
  4. Expand each relevant record.
  5. Confirm who made the change, when it occurred, its source IP and user agent, the result, and the affected resource in metadata.
  6. Export the filtered records if you need to share the investigation timeline.

Next steps

  • Review Roles and Permissions to control access to Activity Logs.
  • Use Activity Logs during incident reviews and planned configuration changes.
  • Export only the minimum date range and fields needed for your investigation or audit.

Did this page help you?