Activity log
9 min
activity log edition enterprise only the activity log records scan events across every source, so you can see when a scan started, completed, or failed, and how often a source has been failing for per run coverage and duration, see scan details overview open the activity log when you need the history behind a source's scans whether a failure is a one off or a pattern, and when the source last scanned successfully events are written automatically there is nothing to enable and nothing to configure the log is a historical record rows are never edited after they are written, and events are kept for 90 days the activity log is available in trufflehog enterprise and through a read api see the api reference for endpoints, filters, and response fields how it works events are written as scans move through their lifecycle a state change adds a new row rather than updating an existing one, so a single scan produces several rows over its life a scan fails when trufflehog cannot determine what to scan, or when every part of the scan fails authentication failures and unreachable sources fail a scan outright if some parts fail and others succeed, the scan completes with a partial status instead of failing anomalies are detected by heuristic a scan can finish successfully and still be wrong trufflehog flags a completed scan that scanned nothing, or that finished too fast to have done real work see troubleshooting for the messages and what causes them completion and anomaly events can lag trufflehog evaluates finished scans on a cycle, so these events can appear up to seven minutes after the scan itself ends deleting a source deletes its activity the source's events are removed along with its findings to stop scanning a source while keeping its history, archive it instead events event written when scan started a scan run begins scan completed a scan run finishes scan failed trufflehog cannot determine what to scan, or every part of the scan fails scan scheduled a scan is scheduled, either one time or recurring scan anomaly detected a heuristic identifies a scan that finished or progressed abnormally the event type filter lists this as anomaly detected statuses each event carries one status, shown as a color chip status appears on meaning success scan completed the scan finished with no errors partial scan completed the scan finished and some parts of it errored failure scan failed the scan did not run, or every part of it failed in progress scan started the scan is running scheduled scan scheduled the scan is queued for a future time warning scan anomaly detected the scan needs a look view scan activity viewing the activity log requires the editor or admin role click activity log in the main navigation !\[activity log in the main navigation] read the table each row is one event, with the date, event, status, source, actor, and message events are always listed newest first the columns are not sortable actor shows system for events trufflehog writes on its own, and the user's name for a scan someone scheduled source ids are available through the api only filter the log use the filter chips above the table date range , event , status , source , and actor select more than one value in event , status , and source to widen a filter actor takes one selection filters are held in the page url copy the link to share the filtered view you're looking at open an event click any row in the table the drawer opens on the right, headed with the event and source, the time it occurred, and the actor read full message for the complete text the table truncates it, the drawer doesn't click the source card to open that source in integrations close the drawer to return to the table with your filters still applied the drawer has its own url, so you can link someone directly to an event notes events older than 90 days are purged automatically the activity log covers scan events integration and notifier health events are not yet included troubleshooting message cause solution scan completed without scanning any data the scan ran and found nothing to read the source is empty, the configured scope matches nothing, or the content is all in formats trufflehog doesn't scan confirm the source's scope covers the repositories, projects, or buckets you expect scan completed too quickly the scan finished faster than a real pass over the source takes, which usually means it covered far less than you expect compare the resource counts against the previous run in scan details scan completed with errors some parts of the scan failed and the rest succeeded, so coverage is incomplete check the source's most recent run in scan details for which resources errored activity log is missing from the navigation your role is below editor ask an admin to change your role