Backup & Recovery - Audit Logs

This article contains information on activities logged in Backup & Recovery, including content access, exports, and policy changes, plus key review scenarios and compliance recommendations.

What Is Logged

The Backup & Recovery Audit Log captures the following activity:

  • Content browsing and searching: any instance of an admin browsing or searching mailbox content.
  • Export actions: exports that were initiated, cancelled, or downloaded.
  • Policy management actions: policy creation, edits, activation, deactivation, and priority changes.

Common Use Cases

The Audit Log is useful in two common scenarios:

  • Internal review: confirming who accessed or exported specific mailbox content, and when.
  • Compliance and security reviews: providing supporting evidence in broader compliance or security investigations.

Accessing Audit Logs

You can access the Audit Logs by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Account | Audit Logs.
  3.  Click on the Filter
  4. Select Backup & Recovery Logs.
  5. Click on Apply.

Searching Audit Logs

You can search for particular Audit Logs and apply filters by using the following steps:

  1. Click on the Search field.
  2. Enter any known details in the Search field.
  3. Click on the Search Icon. Your results are displayed.

Exporting Audit Logs

Rows/page navigation in the Audit Logs screen

You can export the Audit Logs from your search results and/or a selected / custom time period by using the following steps:

  1. Click on Export.
  2. Complete the dialog as follows:
Field / Option Description
Columns to Include By default, all the check boxes are selected; uncheck the boxes for the information you wish to exclude.
Format The file format is in CSV.
  1. Click on Export.
  2. Once the export is complete, it will be downloaded directly to the workstation from which the request was made.
Export Log pop-over in the Audit Logs screen

Recommendations

We recommend surfacing the Backup & Recovery Audit Log as a standing item in periodic compliance reviews, rather than only pulling it reactively after an incident.

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.