The AXQA Security Log Tracker provides a centralized view of security-related platform activity.
It combines threat-level classification, user and IP information, filtering, live refresh, searching, and export tools to support security monitoring and investigation.
Why it matters
- Gives administrators visibility into security-relevant activity.
- Helps identify repeated denied requests and suspicious patterns.
- Provides traceability for protected platform operations.
- Makes security investigations faster by keeping relevant events searchable.
When to use it
- When investigating unusual activity.
- When reviewing unauthorized-access attempts.
- When checking security-related configuration changes.
- When monitoring the workspace during sensitive operations.
- When preparing security evidence for an internal review.
Core concepts
- Security Event – A security-relevant action or platform event recorded by AXQA.
- Threat Level – Classification applied to the recorded event.
- Section – The AXQA area associated with the event.
- Logged By – The authenticated user or system identity associated with the event.
- IP Address – The client IP associated with the recorded request or event.
- Live Mode – Automatic refreshing of the Security Log Tracker.
How it works
- Security-relevant platform activity is detected.
- AXQA records the corresponding security event.
- The event is classified with a security or threat level.
- User, IP, timestamp, section, and event information are stored where available.
- The Security Log Tracker displays the newest events first.
- Administrators can search, filter, copy, or export the visible information.
- Live Mode periodically refreshes the log view.
How to use it
Step 1: Open the Security Log Tracker
Open:
Security → Security Log Tracker
The page displays security events associated with the workspace.
Step 2: Review the available information
The log table includes:
- ID
- Threat Level
- Section
- Date
- Message
- Logged By
- IP Address
Use these fields together when investigating an event.
Step 3: Understand Threat Levels
AXQA can display security classifications including:
- Critical
- High
- Medium
- Low
- Security
- Error
- Warn
- Info
The level reflects the security context associated with the event.
For example, repeated denied requests may receive a higher classification than normal protected activity.
Step 4: Search the logs
Use the Search field to search across information including:
- Log ID
- Threat Level
- Section
- Date
- Message
- User
- IP Address
This is useful when searching for a specific user, IP, endpoint, or security event.
Step 5: Filter by date
Use:
- From Date
- To Date
to restrict the Security Log Tracker to a specific investigation period.
Step 6: Filter by Threat Level
Select a Threat Level to focus on events such as:
Critical
High
Medium
Low
This can help isolate higher-risk activity from normal informational events.
Step 7: Filter by Section
Select a specific Section when investigating activity related to one AXQA component or security workflow.
Step 8: Use Live Mode
The Security Log Tracker includes a LIVE mode.
When enabled, AXQA automatically refreshes the Security Log Tracker approximately every five seconds.
Use the toggle to pause Live Mode when you need to inspect a fixed set of results.
Step 9: Change Page Size
Available page sizes include:
- 10
- 25
- 50
- 100
Choose the size that best matches the investigation.
Step 10: Copy or export results
Use:
Copy Visible
to copy the currently visible log rows.
Use:
Export CSV
to export the currently loaded log information for additional analysis.
Best practices
- Review High and Critical events regularly.
- Use date and IP filters when investigating an incident.
- Pause Live Mode when examining a specific event.
- Export relevant logs when additional analysis or evidence retention is required.
- Correlate user identity, IP address, timestamp, and event message instead of reviewing one field alone.
Common mistakes
❌ Assuming every recorded event represents an attack.
✔ Security logs include both security operations and suspicious activity.
❌ Searching only by username.
✔ Also review IP, time, Section, and event message.
❌ Leaving a large live result set open while performing detailed analysis.
✔ Pause Live Mode when you need a stable investigation view.
Security & permissions
- The Security Log Tracker is restricted to Superuser access.
- AXQA masks or redacts supported sensitive values before security-request information is stored.
- Sensitive fields such as passwords, OTP codes, tokens, authorization values, and API keys are excluded or masked by supported audit logging.
- Sensitive authentication paths receive additional body-redaction protection.
- Uploaded file contents are not stored as part of request-body security logging.
- Security logging is designed not to interrupt the main AXQA workflow if log creation fails.
Related documentation
- Security Architecture Overview
- Login Attempts Blocker & Rate Limiting
- IP Whitelist Security
- Smart Agent Network Allowlist & Step-Up Verification
- Security & Client Isolation