Investigate an action#

  1. Open Settings → Audit.
  2. Narrow the available time, actor, action and resource filters to the event you are investigating.
  3. Inspect the recorded request/action context and result. Correlate the object, cluster and time with Kubernetes state or the related Delivery run.
  4. Use pagination to review the surrounding events instead of assuming the first page contains the complete interval.
Use the search and operation/user filters to narrow audit records. This example search has no matching events; clear it to broaden the results.
Use the search and operation/user filters to narrow audit records. This example search has no matching events; clear it to broaden the results. View full size ↗

Separate the different histories#

RecordWhat it explains
Audit logWho performed an application action and the recorded outcome/context.
Resource historyRecorded changes associated with a resource.
Delivery run and eventsThe sequence, plan, approvals, execution and verification of a delivery attempt.
Container logsOutput written by the selected workload container.

Interpret missing evidence#

An absence in the current filter is not proof that no action happened. Check the scope, filters, pagination and retention settings. An API failure can occur before a Kubernetes change; an interrupted mutation can require investigation of the live resource to establish the final outcome.

Preserve relevant record identifiers and times when opening a support case. Do not paste secrets or entire unreviewed diagnostic archives into a general issue tracker.