Audit Logs
Audit logs possess distinct characteristics that set them apart from the other types of logs. They are immutable, chronological records designed to track user and system actions that affect security, access, or data integrity. They are intended solely for audit purposes and must not be altered or repurposed [3] [4].
A typical audit log entry includes:
Who performed the action.
What action was taken.
When it happened.
Where in the system it occurred.