Spinner logo QXQA

Did You Know?

Home / Security and Architecture / Security Log Tracker & Live Security Monitoring

Security Log Tracker & Live Security Monitoring

The AXQA Security Log Tracker provides a centralized view of security-related platform activity.
It combines threat-level classification, user and IP information, filtering, live refresh, searching, and export tools to support security monitoring and investigation.


Why it matters

  • Gives administrators visibility into security-relevant activity.
  • Helps identify repeated denied requests and suspicious patterns.
  • Provides traceability for protected platform operations.
  • Makes security investigations faster by keeping relevant events searchable.

When to use it

  • When investigating unusual activity.
  • When reviewing unauthorized-access attempts.
  • When checking security-related configuration changes.
  • When monitoring the workspace during sensitive operations.
  • When preparing security evidence for an internal review.

Core concepts

  • Security Event – A security-relevant action or platform event recorded by AXQA.
  • Threat Level – Classification applied to the recorded event.
  • Section – The AXQA area associated with the event.
  • Logged By – The authenticated user or system identity associated with the event.
  • IP Address – The client IP associated with the recorded request or event.
  • Live Mode – Automatic refreshing of the Security Log Tracker.

How it works

  1. Security-relevant platform activity is detected.
  2. AXQA records the corresponding security event.
  3. The event is classified with a security or threat level.
  4. User, IP, timestamp, section, and event information are stored where available.
  5. The Security Log Tracker displays the newest events first.
  6. Administrators can search, filter, copy, or export the visible information.
  7. Live Mode periodically refreshes the log view.

How to use it

Step 1: Open the Security Log Tracker

Open:

Security → Security Log Tracker

The page displays security events associated with the workspace.


Step 2: Review the available information

The log table includes:

  • ID
  • Threat Level
  • Section
  • Date
  • Message
  • Logged By
  • IP Address

Use these fields together when investigating an event.


Step 3: Understand Threat Levels

AXQA can display security classifications including:

  • Critical
  • High
  • Medium
  • Low
  • Security
  • Error
  • Warn
  • Info

The level reflects the security context associated with the event.

For example, repeated denied requests may receive a higher classification than normal protected activity.


Step 4: Search the logs

Use the Search field to search across information including:

  • Log ID
  • Threat Level
  • Section
  • Date
  • Message
  • User
  • IP Address

This is useful when searching for a specific user, IP, endpoint, or security event.


Step 5: Filter by date

Use:

  • From Date
  • To Date

to restrict the Security Log Tracker to a specific investigation period.


Step 6: Filter by Threat Level

Select a Threat Level to focus on events such as:

Critical
High
Medium
Low

This can help isolate higher-risk activity from normal informational events.


Step 7: Filter by Section

Select a specific Section when investigating activity related to one AXQA component or security workflow.


Step 8: Use Live Mode

The Security Log Tracker includes a LIVE mode.

When enabled, AXQA automatically refreshes the Security Log Tracker approximately every five seconds.

Use the toggle to pause Live Mode when you need to inspect a fixed set of results.


Step 9: Change Page Size

Available page sizes include:

  • 10
  • 25
  • 50
  • 100

Choose the size that best matches the investigation.


Step 10: Copy or export results

Use:

Copy Visible

to copy the currently visible log rows.

Use:

Export CSV

to export the currently loaded log information for additional analysis.


Best practices

  • Review High and Critical events regularly.
  • Use date and IP filters when investigating an incident.
  • Pause Live Mode when examining a specific event.
  • Export relevant logs when additional analysis or evidence retention is required.
  • Correlate user identity, IP address, timestamp, and event message instead of reviewing one field alone.

Common mistakes

❌ Assuming every recorded event represents an attack.
✔ Security logs include both security operations and suspicious activity.

❌ Searching only by username.
✔ Also review IP, time, Section, and event message.

❌ Leaving a large live result set open while performing detailed analysis.
✔ Pause Live Mode when you need a stable investigation view.


Security & permissions

  • The Security Log Tracker is restricted to Superuser access.
  • AXQA masks or redacts supported sensitive values before security-request information is stored.
  • Sensitive fields such as passwords, OTP codes, tokens, authorization values, and API keys are excluded or masked by supported audit logging.
  • Sensitive authentication paths receive additional body-redaction protection.
  • Uploaded file contents are not stored as part of request-body security logging.
  • Security logging is designed not to interrupt the main AXQA workflow if log creation fails.

Related documentation

  • Security Architecture Overview
  • Login Attempts Blocker & Rate Limiting
  • IP Whitelist Security
  • Smart Agent Network Allowlist & Step-Up Verification
  • Security & Client Isolation

Tools

A+ A-

Version

1.2