Activity Logs
Track who performed an action, what changed, when it happened, where it originated, and whether it succeeded in DEUNA Admin.
Activity Logs provide a searchable, tamper-resistant record of actions performed in DEUNA Admin. Use them to identify who performed an action, what changed, when it happened, where the request originated, and whether it succeeded.
In DEUNA Admin, open Logs to access the Change history page.
Activity Logs are an observability and audit feature. Recording an event does not affect payment authorization, checkout, or order processing. Activity Logs are not supported in the sandbox environment.
Why use Activity Logs
Configuration changes can affect approval rates, processing costs, account access, and security. Activity Logs centralize the information your team needs to investigate those changes.
| Benefit | What it means for your team |
|---|---|
| Faster investigations | Compare an incident window with configuration, login, and operational activity. |
| Accountability | Identify the user, role, action, time, and result associated with each event. |
| Security visibility | Review authentication, 2FA, password reset, account lock, and access activity. |
| Compliance support | Use append-only records and exports as evidence for internal audits and compliance processes. Activity Logs support your compliance program; they do not replace it. |
| Data protection | Sensitive values such as card numbers, CVV, passwords, one-time passwords, and credentials are removed or masked before an event is stored. |
| Tenant isolation | Merchant users see only their merchant's records. Network users see records for merchants in their network, with merchant attribution preserved. |
Common use cases
- Investigate an approval-rate change: Review Routing and Connections events around the time the rate changed.
- Review a permission issue: Search by user and inspect role and permission updates.
- Investigate suspicious access: Review authentication and security events together with their IP address and user agent.
- Prepare audit evidence: Export the relevant date range and filters to CSV.
- Confirm a planned change: Verify what changed, who applied it, and whether the action succeeded.
Prerequisites
Before using Activity Logs, confirm that:
- Your role includes permission to view Activity Logs.
- Your role includes export permission if you need to generate or download files.
- You know the merchant and approximate date range associated with the activity you want to review.
Users without view permission do not see the Logs section.
View activity records
- Sign in to DEUNA Admin.
- Open Logs from the navigation menu.
- Choose a date range. Each query can cover up to 90 days.
- Search for a user or apply filters to narrow the results.
- Select a row to inspect the event details.
Records appear with the most recent event first. New events typically become available within five minutes.
Record list fields
| Field | Description |
|---|---|
| Creation date | Date and time when the event occurred. DEUNA stores the time in UTC and displays it in your local time zone. |
| Executed by | Email address of the user who performed the action. |
| Action | Human-readable action name, such as Routing rule viewed. |
| Section | Area of DEUNA Admin associated with the action, such as Configurations, Routing, or Connections. |
| IP | Source IP address of the request. |
Use Columns to select the visible fields. Select Refresh to load the latest records.
Inspect an event
Expand a record to see its complete context. Use the Details tab for a formatted view or the JSON tab for the raw event.
| Field | Description |
|---|---|
merchantId | Identifier of the merchant associated with the event. |
userId | Identifier of the user who performed the action. |
actorRole | Role assigned to the actor at the time of the event. |
eventSeverity | Event impact level: LOW, MEDIUM, HIGH, or CRITICAL. |
eventResult | Event outcome: SUCCESS or FAILURE. |
originUserAgent | Browser or client that sent the request. |
originSessionId | Identifier of the session in which the action occurred. |
metadata | Approved, sanitized context specific to the event, such as the affected resource identifier. Contents vary by event. |
Severity levels
| Severity | Meaning | Examples |
|---|---|---|
LOW | Routine, expected activity. | Successful login or viewing a configuration. |
MEDIUM | Moderate-impact activity. | Updating a role or requesting an export. |
HIGH | High-impact or sensitive activity. | Disabling routing or updating credentials. |
CRITICAL | Security or business-critical risk. | Account lockout, disabling 2FA, or repeated authentication failures. |
Result values
SUCCESS: The action completed as intended.FAILURE: The action did not complete. Themetadataobject may include a sanitized failure reason.
Search and filter records
Use the available controls to focus your investigation:
- Search by email or name: Find activity associated with a specific user.
- Filter by date: Select a required date range of up to 90 days.
- Add filter: Refine the results by section, action, severity, result, or another available field.
Start with a narrow date range, then add section and action filters. This makes it easier to establish a timeline before expanding the search.
Export records
- Apply the date range and filters you need.
- Select Export.
- Confirm the export request.
- Open the Downloads tab.
- Wait until the file is ready, then download it.
Exports run asynchronously and include the records that match your filters.
| Constraint | Value |
|---|---|
| Maximum date range | 90 days per export |
| Maximum number of records | 10,000 per export |
| Concurrent exports | 3 per merchant |
| File format | Gzip-compressed, UTF-8 CSV with semicolon (;) separators |
| File availability | 7 days after creation |
| Download link validity | 15 minutes |
If a link expires, request a new one from Downloads. Export requests and downloads are also recorded as exports.requested and exports.downloaded events.
Permissions
Activity Log access is controlled through Roles and permissions.
| Permission | Allows |
|---|---|
audit_log.view | Open Logs, search and filter records, and inspect event details. |
audit_log.export | Request exports and download generated files. |
Apply the principle of least privilege. Grant export access only to users who need to retrieve audit evidence outside DEUNA Admin.
Data protection and retention
- Append-only records: Activity records cannot be edited or deleted from DEUNA Admin or the API. If a record must be redacted, DEUNA creates a new event that references the original.
- Sensitive-data sanitization: PAN, CVV, track data, passwords, OTP codes, reset tokens, API keys, and secrets are masked or removed before storage.
- Encryption: Data is encrypted in transit using TLS 1.2 or later and encrypted at rest.
- Retention: Records are retained for 365 days.
- Availability: New events typically appear within five minutes.
Available events
Event names follow the <domain>.<resource>.<action> convention. For example, routing.rule.updated identifies the Routing domain, a routing rule resource, and an update action.
The events available to your account can depend on enabled DEUNA products and features.
Authentication
| Event | Description |
|---|---|
auth.login.verified | A user's login was verified and a session started. |
auth.logout.verified | A user logged out and the session ended. |
Security
| Event | Description |
|---|---|
security.2fa_policy.updated | The two-factor authentication policy for the merchant was changed. |
security.2fa_method.setup | A user configured a two-factor authentication method. |
security.2fa_method.disabled | A user's two-factor authentication method was disabled. |
security.2fa_challenge.viewed | A two-factor authentication challenge was presented to a user. |
security.2fa_challenge.verified | A user submitted a two-factor authentication challenge. Check eventResult for the outcome. |
security.2fa_backup_codes.generated | A new set of two-factor authentication backup codes was generated for a user. |
security.2fa_backup_codes.verified | A user attempted to verify with a two-factor authentication backup code. Check eventResult for the outcome. |
security.account.locked | A user account was locked, for example, after repeated failed sign-in attempts. |
security.account.unlocked | A locked user account was unlocked. |
security.password.reset_requested | A password reset was requested for a user. |
security.password.reset_completed | A password reset was completed. |
security.block.applied | An access block was applied by the platform's brute-force protection. |
security.block.cleared | An access block was cleared. |
security.user.overridden | A security restriction on a user was manually overridden. |
security.user.status_updated | A user's status, such as active or blocked, was changed. |
security.email.sent | A security-related email was sent to a user. |
Users and roles
| Event | Description |
|---|---|
users.user.created | A new user was added to the merchant. |
users.user.updated | A user's details were modified. |
users.user.deactivated | A user was deactivated and can no longer access DEUNA Admin. |
users.role.created | A new role was created. |
users.role.updated | A role was modified. |
users.role_permissions.updated | The permissions assigned to a role were changed. |
Exports
| Event | Description |
|---|---|
exports.requested | A user requested an export of Activity Log records. |
exports.downloaded | A user downloaded an export file. |
Orders
| Event | Description |
|---|---|
orders.captured | An order payment was captured. |
orders.refunded | An order payment was refunded. |
orders.voided | An order authorization was voided. |
Merchant configuration
| Event | Description |
|---|---|
configurations.merchant_policy.created | A merchant policy was created. |
configurations.merchant_policy.updated | A merchant policy was modified. |
configurations.merchant_policy.deleted | A merchant policy was deleted. |
configurations.merchant_policy.viewed | A merchant policy was viewed. |
configurations.merchant_profile.updated | The merchant profile was modified. |
configurations.merchant_profile.viewed | The merchant profile was viewed. |
configurations.widget_3ds.updated | The 3DS widget configuration was modified. |
configurations.widget_3ds.viewed | The 3DS widget configuration was viewed. |
configurations.order_config.updated | The order configuration was modified. |
configurations.payment_config.updated | The payment configuration was modified. |
configurations.payment_config.viewed | The payment configuration was viewed. |
Routing
| Event | Description |
|---|---|
routing.rule.created | A routing rule was created. |
routing.rule.updated | A routing rule was modified. |
routing.rule.enabled | A routing rule was enabled. |
routing.rule.disabled | A routing rule was disabled. |
routing.rule.reordered | The priority order of routing rules was changed. |
routing.rule.viewed | A routing rule was viewed. |
Connections
| Event | Description |
|---|---|
connections.processor.created | A processor connection was created. |
connections.processor.updated | A processor connection was modified. |
connections.processor.disabled | A processor connection was disabled. |
connections.processor.viewed | A processor connection was viewed. |
Installments
| Event | Description |
|---|---|
installments.campaign.created | An installment campaign was created. |
installments.campaign.updated | An installment campaign was modified. |
installments.campaign.viewed | An installment campaign was viewed. |
Payment links
| Event | Description |
|---|---|
payment_links.payment_link.created | A payment link was created. |
payment_links.payment_link.viewed | A payment link was viewed. |
payment_links.payment_link.deactivated | A payment link was deactivated. |
Error management
| Event | Description |
|---|---|
error_management.processor_error.created | A processor error mapping was created. |
error_management.processor_error.viewed | A processor error mapping was viewed. |
error_management.processor_error.updated | A processor error mapping was modified. |
error_management.processor_error.deleted | A processor error mapping was deleted. |
Subscriptions
| Event | Description |
|---|---|
subscriptions.subscription.created | A subscription was created. |
subscriptions.subscription.updated | A subscription was modified. |
subscriptions.subscription.viewed | A subscription was viewed. |
subscriptions.subscription.paused | A subscription was paused. |
subscriptions.subscription.canceled | A subscription was canceled. |
subscriptions.subscription.reactivated | A paused or canceled subscription was reactivated. |
Batch operations
| Event | Description |
|---|---|
batch_operations.batch_job.created | A batch job was created. |
batch_operations.batch_job.viewed | A batch job was viewed. |
Example: investigate an approval-rate change
A merchant notices that its approval rate dropped on a specific day.
- Open Logs and set the date range to the day before the drop through the end of the affected day.
- Filter Section by Routing and Connections.
- Look for events such as
routing.rule.updated,routing.rule.disabled,routing.rule.reordered, orconnections.processor.disabled. - Expand each relevant record.
- Confirm who made the change, when it occurred, its source IP and user agent, the result, and the affected resource in
metadata. - Export the filtered records if you need to share the investigation timeline.
Next steps
- Review Roles and Permissions to control access to Activity Logs.
- Use Activity Logs during incident reviews and planned configuration changes.
- Export only the minimum date range and fields needed for your investigation or audit.
Updated about 3 hours ago