All Products
Search
Document Center

Cloud Firewall:Audit logs

Last Updated:May 28, 2026

After enabling protection for Agent assets, you can view comprehensive behavior and traffic audit logs to meet compliance and auditing requirements.

Procedure

View Agent behavior audit logs

Go to the Behavior Audit tab to display the Agent request list. You can perform the following operations:

  • Filter by time and log delivery region: In the area above the list, you can filter requests by time range. If the dual-region log delivery feature is enabled, you can also switch the Region for Log Delivery.

  • View total request count: The area above the list displays the total number of requests within the selected time period, including both successful and failed requests.

  • View request list overview: In the list at the bottom of the page, you can view summary information such as the response ID, time, Agent network environment, associated Agent, model, and linked Skill and Tool.

  • View specific request details: In the list at the bottom of the page, click the Response ID of a request to view the following details in a pop-up window:

    • Skill: A list of skills that the Agent can invoke.

    • Tool: A list of provided tools and actually invoked tools.

    • Request System Message: System-defined settings and instructions for the AI.

    • Request User Message: The content input by the user.

    • Request Assistant Reasoning Message: The AI reasoning process before generating a response.

    • Response Reasoning Message: The final output from the AI to the user.

View Agent traffic audit logs

Go to the Traffic Audit tab to view the Agent traffic log list. You can perform the following operations:

  • Switch log delivery region: In the upper-left corner of the page, if the dual-region log delivery feature is enabled, you can switch the Region for Log Delivery.

  • Filter and search logs: Above the log list, you can filter logs by time range. The left-side panel of the list provides multiple filter options, including log type, IP address, port, protocol, and asset region. Click any option to quickly filter logs.

  • View log count distribution chart: After filtering, the distribution area above the list displays a chart showing the log count distribution and total log count under the current conditions. If the time span in the chart is too large, you can click specific time points in the chart to zoom in or restore the view.

  • View log list overview: The log list displays fields such as log type, time, five-tuple, and asset region by default. You can click the image icon in the upper-right corner to customize which fields to display.

  • View log details: Click Details in the Actions column of a log entry to view the specific details of that log.