--- title: "Download Security Logs for All Users" slug: "download-security-logs-for-all-users" updated: 2026-02-11T00:43:52Z published: 2026-02-11T00:43:52Z canonical: "docs.processmaker.com/download-security-logs-for-all-users" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # Download Security Logs for All Users > [!TIP] > [**Plan Availability:**](https://www.processmaker.com/products/pricing/) ![Enterprise](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Enterprise.png) Download the security logs for all users in your ProcessMaker Platform instance. Security logs prepared for download remain available for 24 hours. Thereafter, the security logs must be compiled again. ISO/IEC 27001 is an excellent standard for information security management systems (ISMS). An organization complying with ISO/IEC 27001 has put in place a system to better manage risks related to the security of data owned or handled by that organization. In compliance with ISO/IEC 27001, ProcessMaker Platform logs multiple aspects of each user's activity throughout the platform. [In the **Security Logs** tab within each user account](/v1/docs/edit-a-user-account#view-security-logs-for-this-user), ProcessMaker Platform maintains a record of the datetime, and IP address for the following activities that user performs: - **Log on:** Each successful and unsuccessful log on attempt - **Log off:** Each log off from ProcessMaker Platform - **User profile changes:** Any changes to that user's profile, including: - profile information - group memberships - permissions - API tokens, including creation, update, and deletion - **Collections:** Reading, creating, updating, and deleting any Collection or Collection record - **Settings:** Changing settings, including: - Create or revise any email server or changes in their configuration options (including IMAP) - Enable new SSO options or change configuration options - Enable or change configuration options to other systems, such as DocuSign and IDP - Enable LDAP or SCIM or change their configuration options - Enable or disable User Signals - Update User Extended Properties or change their designated time zone - **Customize UI:** Changes within the Customize UI menu (inputs to change setting values, including deletions) - **System messages:** System alerts and errors (including within Requests) - **Other user activities:** Other user activities in the platform, including: - Create, update, publish, archive, or unarchive a Process - Create, update, or delete any non-Designer assets, including Saved Searches, Saved Search Charts, auth client, Script Executors, Dynamic UI dashboards or menus, or Translations - Perform global or local search queries - Access, reassignments, retries, rollbacks, and completion of Tasks, including parent Request ID - Start, cancel, and complete Requests - Access Queue Management/Laravel Horizon by section name - Create a user or group See [Security Log Events](/v1/docs/download-security-logs-for-all-users#security-log-events) for a description of each user activity event. ## Download Security Logs for All Users **Permissions** Your user account or group membership must have the following permissions to download security logs for all users unless your user account has the **Make this user a Super Admin** setting selected: - Users: View Users - Security Logs: View Security Logs See the [Users](/v1/docs/permission-descriptions-for-users-and-groups#users) permissions and the [Security Logs](/v1/docs/permission-descriptions-for-users-and-groups#security-logs) permission, or ask your Administrator for assistance. Follow these steps to download security logs for all users: 1. [View all user accounts.](/v1/docs/user-accounts#view-all-scripts) The **Users** tab displays. 2. Click the **Logs** button. ProcessMaker Platform compiles the security logs from your your AWS S3 bucket in the background. You may continue working as necessary in ProcessMaker Platform. The following message displays from the currently displaying page when the security logs are ready to download: **Click on the link and download the file**. This link is available for 24 hours. 3. Click the **Download** link. The security logs download in CSV format. ## Security Log Events View these security log event labels when: - [Downloading security logs for all users](/v1/docs/download-security-logs-for-all-users) - [Viewing all activities for a user](/v1/docs/edit-a-user-account#view-all-security-logs-for-a-user) - [Viewing information about a security log for a user](/v1/docs/edit-a-user-account#view-information-about-a-security-log-for-a-user) - [Downloading the security logs for a user](/v1/docs/edit-a-user-account#download-the-security-logs-for-a-user) - [Sorting the security logs for a user](/v1/docs/edit-a-user-account#sort-the-security-logs-for-a-user) - [Searching the security logs for a user](/v1/docs/edit-a-user-account#search-the-security-logs-for-a-user) | Event Label | Event Description | | --- | --- | | ActivityReassignment | [Reassign a task](/v1/docs/open-a-task#summary) | | AnalyticReportCreated | Create an analytic report | | AnalyticReportDeleted | Delete an analytic report | | AnalyticReportUpdated | Configure an analytic report | | AuthClientCreated | [Create an Authenticated Client](/v1/docs/create-a-new-authenticated-client) | | AuthClientDeleted | [Delete an Authenticated Client](/v1/docs/delete-an-authenticated-client) | | AuthClientUpdated | [Edit an Authenticated Client](/v1/docs/edit-an-authenticated-client) | | CategoryCreated | [Create a Process Category](/v1/docs/process-categories#create-a-new-process-category) | | CategoryDeleted | [Delete a Process Category](/v1/docs/process-categories#delete-a-process-category) | | CategoryUpdated | [Edit a Process Category](/v1/docs/process-categories#edit-a-process-category) | | CollectionAccessed | View all records in a Collection | | CollectionCreated | Create a Collection | | CollectionDeleted | Delete a Collection | | CollectionRecordAccessed | View a Collection record | | CollectionUpdated | Configure a Collection | | CustomizeUiUpdated | [Customize site design](/v1/docs/site-design#customize-site-design) | | DashboardCreated | Create a Dashboard | | DashboardDeleted | Delete a Dashboard | | DashboardUpdated | Edit a Dashboard | | DataConnectorCreated | Create a Data Connector | | DataConnectorDeleted | Delete a Data Connector | | DataConnectorResourceAction | Add, edit, or delete a resource from a Data Connector | | DataConnectorUpdated | Edit Configuration for a Data Connector's REST Data Source or Edit Configuration for a Data Connector's SOAP Data Source | | DecisionTableCategoryCreated | Create a Decision Table category | | DecisionTableCategoryDeleted | Delete a Decision Table category | | DecisionTableCategoryUpdated | Edit a Decision Table category | | DecisionTableCreated | Create a Decision Table | | DecisionTableDeleted | Delete a Decision Table | | DecisionTableUpdated | Edit a Decision Table | | EmailServerCreated | Create an Email Server Configuration | | EmailServerDeleted | Delete an Email Server Configuration | | EnvironmentVariablesCreated | [Create an Environment Variable](/v1/docs/create-a-new-environment-variable) | | EnvironmentVariablesDeleted | [Delete an Environment Variable](/v1/docs/manage-environment-variables#delete-an-environment-variable) | | EnvironmentVariablesUpdated | [Edit an Environmental Variable](/v1/docs/manage-environment-variables#edit-a-environment-variable) | | FilesAccessed | [Preview a File from File Manager](/v1/docs/preview-a-file) | | FilesCreated | [Add a File to the Public Folder](/v1/docs/files-in-the-public-folder#add-a-file-to-the-public-folder) | | FilesDownloaded | [Download a File from File Manager](/v1/docs/download-a-file-or-folder#download-a-file-from-file-manager) | | FilesUpdated | [Rename a File in the Public Folder](/v1/docs/files-in-the-public-folder#rename-a-file-in-the-public-folder-1) | | FolderAccessed | [View All Files in the Public Folder](/v1/docs/files-in-the-public-folder#view-all-files-in-the-public-folder) | | FolderCreated | [Create a Folder in the Public Folder](/v1/docs/files-in-the-public-folder#create-a-folder-in-the-public-folder) | | FolderDownloaded | [Download the Contents of a Folder from File Manager](/v1/docs/download-a-file-or-folder#download-the-contents-of-a-folder-from-file-manager) | | FolderUpdated | [Rename a Folder in the Public Folder](/v1/docs/files-in-the-public-folder#rename-a-folder-in-the-public-folder-1) | | GroupCreated | [Create a Group](/v1/docs/create-a-new-group) | | GroupDeleted | [Delete a Group](/v1/docs/delete-a-group) | | GroupUpdated | [Edit Group Settings](/v1/docs/edit-a-group#edit-group-settings) | | GroupUsersUpdated | [Manage Group Members](/v1/docs/edit-a-group#manage-group-members) | | Login | Each successful and unsuccessful [log on](/v1/docs/participant-basics#log-on-to-processmaker-platform) attempt | | Logout | Each [log off](/v1/docs/participant-basics#log-out-of-processmaker-platform) from ProcessMaker Platform | | MenuCreated | Create a Menu | | MenuDeleted | Delete a Menu | | MenuUpdated | Edit a Menu | | PermissionUpdated | Edit [user](/v1/docs/edit-a-user-account#edit-user-permissions) or [group](/v1/docs/edit-a-group#edit-group-permissions) permissions | | PmBlockArchived | Archive a PM Block | | PmBlockCreated | Create a New PM Block | | PmBlockUpdated | [Configure a PM Block](/v1/docs/configure-a-pm-block) or [Edit a PM Block](/v1/docs/create-and-edit-a-pm-block#edit-a-pm-block) | | ProcessArchived | [Archive a Process](/v1/docs/archive-and-restore-a-process) | | ProcessCreated | [Create a Process](/v1/docs/create-a-process) | | ProcessUpdated | [Configure a Process](/v1/docs/configure-general-process-settings) | | QueueManagementAccessed | [Queue Management](/v1/docs/queue-management) | | RecordCreated | Create a Collection Record | | RecordDeleted | Delete a Collection Record | | RecordUpdated | Edit a Collection Record | | RequestAction | Create, Cancel, or Complete a Request | | RequestError | When a Request has errors | | SavedSearchChartCreated | Create a Saved Search Chart | | SavedSearchChartDeleted | Delete a Saved Search Chart | | SavedSearchChartUpdated | Edit a Saved Search Chart | | SavedSearchCreated | Create and Share a Saved Search | | SavedSearchDeleted | Delete a Saved Search | | SavedSearchRecounted | Manage Your Own Saved Searches | | SavedSearchUpdated | Configure a Saved Search | | ScreenCreated | [Create a Screen](/v1/docs/create-a-new-screen) | | ScreenDeleted | [Delete a Screen](/v1/docs/manage-screens#delete-a-screen) | | ScreenUpdated | [Configure](/v1/docs/manage-screens) or [edit](/v1/docs/manage-screens#edit-a-screen) a Screen | | ScriptCreated | [Create a Script](/v1/docs/create-a-new-script) | | ScriptDeleted | [Delete a Script](/v1/docs/manage-scripts#delete-a-script) | | ScriptExecutorCreated | [Edit a Script Executor](/v1/docs/edit-a-script-executor) | | ScriptExecutorDeleted | [Create a Script Executor](/v1/docs/create-a-new-script-executor) | | ScriptExecutorUpdated | [Edit a Script Executor](/v1/docs/edit-a-script-executor) | | ScriptUpdated | [Configure](/v1/docs/configure-a-script) or [edit](/v1/docs/manage-scripts#edit-a-script) a Script | | SettingsUpdated | Edit Settings. | | SignalCreated | [Create a Signal](/v1/docs/create-a-new-signal) | | SignalDeleted | [Delete a Signal](/v1/docs/delete-a-signal) | | SignalUpdated | [Edit a Signal](/v1/docs/edit-a-signal) | | TemplateCreated | [Import and Configure a Process Template](/v1/docs/import-a-process-template) | | TemplateDeleted | [Delete a Process Template](/v1/docs/edit-export-and-delete-a-process-template#delete-a-process-template) | | TemplatePublished | [Create a Template from a Process](/v1/docs/create-a-template-from-a-process) | | TemplateUpdated | [Edit](/v1/docs/edit-export-and-delete-a-process-template) or [configure](/v1/docs/configure-a-process-template) a Process Template | | TokenCreated | [Generate an API Token](/v1/docs/edit-a-user-account#generate-an-api-token) | | TokenDeleted | [Delete an API Token](/v1/docs/edit-a-user-account#delete-an-api-token) | | TranslationReseted | [Reset All User Interface Labels and Messages to Their Defaults](/v1/docs/reset-all-user-interface-labels-and-messages-to-their-defaults) | | TranslationUpdated | [Edit Text that Displays in the User Interface](/v1/docs/edit-text-that-displays-in-the-user-interface) | | UnauthorizedAccessAttempt | URLs that are not allowed to access | | UserCreated | [Create a user account](/v1/docs/create-a-new-user-account) | | UserDeleted | [Delete a user account](/v1/docs/deleted-user-accounts) | | UserGroupsUpdated | [Edit to Which Groups the User is a Member](/v1/docs/edit-a-user-account#edit-to-which-groups-the-user-is-a-member) | | UserRestored | [Restore a Deleted User Account](/v1/docs/deleted-user-accounts#restore-a-deleted-user-account) | | UserUpdated | [Edit a user account](/v1/docs/edit-a-user-account) | | WebEntryAccessed | Start a Request through the Web Entry URL |