Skip to main content

What logs can CircleCI provide for audit and forensic analysis?

This article explains which logs CircleCI Cloud makes available for audit and forensic analysis, how organization admins can request them, and what is included in the self-serve audit log export.

Overview

For CircleCI Cloud, the self-serve organization audit log export is the set of logs available to customers for audit and forensic analysis.

CircleCI does not provide separate customer exports beyond that audit log dataset. For example, full API access logs, job console output, and storage or CDN download history are not available as separate exports.


How to get audit logs

  1. Sign in as an organization admin.

  2. Go to Organization Settings > Security > Audit Logs.

  3. Select a date range and select Request audit logs.

  4. Download the CSV when processing completes.

Details and limits: How to Request Audit Logs? and Audit logs


​Quick limits

  • Free plan: 1 request per day. Paid plans: 3 per day.

  • Each request covers up to 30 days.

  • Scale plan customers can also stream audit logs to S3 (forward-looking only. No historical backfill).


What audit logs include

Audit logs record important organization events, such as:

  • Context and environment variable changes, and context.secrets.accessed

  • Project settings, project API token creates, SSH / checkout key changes

  • Workflow and job lifecycle events (start, finish, cancel, retry)

  • Member, invitation, and role changes

Fields can include action, actor, target, payload, occurred_at, success, and (when populated) request details such as IP address.
​

Read-only API status checks are generally not logged.


Recommended next steps

  • Rotate any secrets that may have been exposed. See Rotating Secrets.

  • Review the audit log for unexpected activity during the relevant window.

  • Continue to monitor going forward. Scale plan customers can also set up audit log streaming for ongoing visibility.


Related articles

Did this answer your question?