Activity log
Activity log
Edition: Enterprise only
The activity log records scan events across every source, so you can see when a scan started, completed, or failed, and how often a source has been failing. For per-run coverage and duration, see Scan details.
Overview
Open the activity log when you need the history behind a source's scans: whether a failure is a one-off or a pattern, and when the source last scanned successfully.
Events are written automatically. There is nothing to enable and nothing to configure.
The log is a historical record. Rows are never edited after they are written, and events are kept for 90 days.
The activity log is available in TruffleHog Enterprise and through a read API. See the API reference for endpoints, filters, and response fields.
How it works
- Events are written as scans move through their lifecycle. A state change adds a new row rather than updating an existing one, so a single scan produces several rows over its life.
- A scan fails when TruffleHog cannot determine what to scan, or when every part of the scan fails. Authentication failures and unreachable sources fail a scan outright. If some parts fail and others succeed, the scan completes with a partial status instead of failing.
- Anomalies are detected by heuristic. A scan can finish successfully and still be wrong. TruffleHog flags a completed scan that scanned nothing, or that finished too fast to have done real work. See Troubleshooting for the messages and what causes them.
- Completion and anomaly events can lag. TruffleHog evaluates finished scans on a cycle, so these events can appear up to seven minutes after the scan itself ends.
- Deleting a source deletes its activity. The source's events are removed along with its findings. To stop scanning a source while keeping its history, archive it instead.
Events
Event | Written when |
|---|---|
scan_started | A scan run begins. |
scan_completed | A scan run finishes. |
scan_failed | TruffleHog cannot determine what to scan, or every part of the scan fails. |
scan_scheduled | A scan is scheduled, either one time or recurring. |
scan_anomaly_detected | A heuristic identifies a scan that finished or progressed abnormally. The Event type filter lists this as Anomaly detected. |
Statuses
Each event carries one status, shown as a color chip.
Status | Appears on | Meaning |
|---|---|---|
Success | scan_completed | The scan finished with no errors. |
Partial | scan_completed | The scan finished and some parts of it errored. |
Failure | scan_failed | The scan did not run, or every part of it failed. |
In progress | scan_started | The scan is running. |
Scheduled | scan_scheduled | The scan is queued for a future time. |
Warning | scan_anomaly_detected | The scan needs a look. |
View scan activity
Viewing the activity log requires the Editor or Admin role.
- Click Activity log in the main navigation.![Activity log in the main navigation]
- Read the table. Each row is one event, with the date, event, status, source, actor, and message.
Events are always listed newest first. The columns are not sortable.
Actor shows System for events TruffleHog writes on its own, and the user's name for a scan someone scheduled. Source IDs are available through the API only.
Filter the log
- Use the filter chips above the table: Date range, Event, Status, Source, and Actor.
- Select more than one value in Event, Status, and Source to widen a filter. Actor takes one selection.
Filters are held in the page URL. Copy the link to share the filtered view you're looking at.
Open an event
- Click any row in the table.
- The drawer opens on the right, headed with the event and source, the time it occurred, and the actor.
- Read Full message for the complete text. The table truncates it, the drawer doesn't.
- Click the source card to open that source in Integrations.
Close the drawer to return to the table with your filters still applied. The drawer has its own URL, so you can link someone directly to an event.
Notes
- Events older than 90 days are purged automatically.
- The activity log covers scan events. Integration and notifier health events are not yet included.
Troubleshooting
Message | Cause | Solution |
|---|---|---|
Scan completed without scanning any data. | The scan ran and found nothing to read. The source is empty, the configured scope matches nothing, or the content is all in formats TruffleHog doesn't scan. | Confirm the source's scope covers the repositories, projects, or buckets you expect. |
Scan completed too quickly. | The scan finished faster than a real pass over the source takes, which usually means it covered far less than you expect. | Compare the resource counts against the previous run in Scan details. |
Scan completed with errors. | Some parts of the scan failed and the rest succeeded, so coverage is incomplete. | Check the source's most recent run in Scan details for which resources errored. |
Activity log is missing from the navigation | Your role is below Editor. | Ask an Admin to change your role. |