Gatana logoGatana Docs

Audit Logs

A record of everything that happens in your organization, from sign-ins and configuration changes to every MCP call

Introduction

Gatana keeps an audit log of everything that happens in your organization:

  • every MCP request, including each tool call
  • every sign-in
  • every change to a resource: servers, credentials, profiles, teams, skills, artifacts, secret stores, and organization settings

Each record names the identity behind the event: the user, the profiles that were active, and the credential the call came through, whether an OAuth client or a personal access token. This lets you answer "what did this client do?" even when several clients act as the same user.

Open Audit Logs in the left sidebar to read the log. Organization owners see all records; everyone else sees their own activity.

Logging Detail

How much an MCP call records is set by the MCP audit log level in your organization settings:

LevelWhat a call records
offMCP calls are not recorded
terse (default)The server, the tool, the duration, and who called it
detailedAdds the call arguments
detailed-with-errorAdds the response of failed calls
verboseAdds the response of every call

Sign-ins and resource changes are always recorded, whatever the level.

Filtering

The list opens on the last 7 days, with a date control for other ranges. Add filter builds conditions from a field, a comparison (is, is not, contains; for dates is after and is before), and a value. You can filter by event name, resource type, user, OAuth client, access token, server, tool, profile, team, credential, and secret store. Known values are offered as pick lists, so you point at a client by name instead of typing its id. A record must match all conditions, and the filters are kept in the page URL, so a view can be bookmarked or shared.

The same conditions work on the audit log endpoints of the public API, as a repeated query parameter of the form filter=field:operator:value:

GET /api/v1/audit-logs?filter=clientId:eq:CLIENT_ID&filter=toolName:contains:search

The fields are eventName, entityType, entityId, userId, date, clientId, patId, serverSlug, toolName, profileId, teamId, credentialId, and secretStoreId.

Streaming to Your SIEM

To push audit events to a security platform you control, with your own retention, dashboards, and detection rules, see SIEM Streaming.

On this page