Logs & Monitoring

Monitor access activity, configuration changes, and security events.

Log tabs overview

Logs and Alerts page showing the Traffic Log tab with summary metrics and traffic entries

At the top of the page, a summary bar shows activity for the last 7 days:

MetricWhat it shows
Total TransactionsAll connection attempts through the GSA client
Allowed TrafficConnections that were permitted
Blocked TrafficConnections that were denied
Security AlertsActive security events

The Logs and Alerts section has five tabs:

TabWhat it shows
Traffic LogEvery connection attempt through the GSA client — who accessed what, when, and whether it was allowed
Security AlertsSecurity events and policy violations from Entra Network Access monitoring
Audit LogConfiguration changes made to GSA settings in Microsoft Entra
Local Audit LogChanges made through the Cetegra console specifically
Device LogDevice-level activity and connection events

Traffic logs

Traffic logs showing connection attempts with user, destination, and outcome

Traffic logs record every connection attempt through the GSA client. As a viewer, you can use these logs to:

  • Confirm whether a user successfully reached a resource
  • Find out why access was blocked
  • Audit which resources have been accessed and by whom

Available filters:

FilterUse
Time rangeNarrow to a specific period
Source IPThe user’s external IP address
DestinationInternal hostname, IP, or range
UserFilter by name or UPN
ApplicationFilter by enterprise application
OutcomeAllowed or Blocked

Common lookups:

Is a user reaching a specific resource? Filter by username and destination. Look for Allowed entries with the correct destination and port.

Why is access being blocked? Filter by username and Blocked outcome. The log entry includes the reason — policy, no matching segment, no active connector, etc.

Who accessed a specific server over the past week? Filter by destination and set the time range to the relevant period.


Audit logs

Audit log tab showing the category selector and audit entries

The Audit tab shows configuration changes in Microsoft Entra. Select a category to filter the entries shown.

Categories

CategoryWhat it covers
Administrative UnitChanges to administrative units and scoped role assignments
Application ManagementApp registrations, service principals, and consent operations
Group ManagementGroup creation, membership changes, and ownership updates
PolicyConditional access, authentication methods, and other policies

Entry structure

ColumnDescription
Date/TimeWhen the event occurred
ActivityThe operation performed
TargetThe resource that was changed
Initiated byThe user or service that triggered the change
ResultSuccess, Failure, or Timeout

Filters

  • General search — free-text search across activity, target, and initiated by
  • Result — filter by Success, Failure, or Timeout
  • Date range — narrow to a specific period

Useful for answering questions like:

  • “When was this connection last modified?” → Application Management
  • “When was this access group created or modified?” → Group Management
  • “Has the conditional access policy changed recently?” → Policy

Local audit logs

Local Audit tab showing console mutation entries

The Local Audit tab shows changes made specifically through the Cetegra console (not changes made directly in Entra). This is useful when you need to attribute a configuration change to a specific console user.

Each entry includes:

  • Timestamp
  • User who made the change (UPN)
  • What resource was affected
  • Operation type (create, update, delete)
  • A Correlation ID for cross-referencing with the Entra audit log

Security alerts

Security Alerts tab showing alerts with severity badges

The Security Alerts tab surfaces events from Microsoft Entra Network Access monitoring. Alerts are grouped by severity:

SeverityTypical meaning
CriticalAccess disruption or critical security gap — escalate immediately
HighSignificant issue requiring prompt attention
MediumShould be reviewed, but not immediately blocking
LowInformational — review periodically

Alert types include dependency issues (missing connectors or policies), secret expiry warnings, version issues, and licensing gaps.

If you see Critical or High alerts, report them to your Cetegra administrator promptly.


Jobs

Background import and sync operations are tracked in the Jobs section.

StatusMeaning
QueuedWaiting to start
RunningIn progress
CompletedFinished successfully
FailedEncountered an error

Jobs are initiated by Cetegra administrators. If a job shows as Failed, report it to your Cetegra administrator along with the job timestamp and any error message shown.