Audit log
Who did what to the project's tickets, and when: an activity chart, filters, the details of every action and a CSV export.
Audit is in the main menu for the project owner and admins. The log holds every action on a ticket — by an operator, by the system or by the customer.
Filters
- Period — the same choices as in analytics: Today, 7 days, 30 days (the default), 90 days, Year, All time or a custom range. Days and times in the log are in your time zone.
- Who: operators, the system, customers — or one operator.
- Actions: pick several; clicking a group's name picks the whole group.
- Search by the ticket's subject or its number — the first characters after «#», as in the ticket list.
Chart and list
Activity by day shows how many actions happened in the period — with the same filters as the list; a bar's colour is the action's group. Below, events are grouped by day, the day header stays on top while scrolling, and more events load as you scroll.
Clicking a row opens the details: what changed (before → after: status, operator, department, snooze time, resolution time, the rating with its comment), the event's raw data and a link to the ticket.
| Group | Actions |
|---|---|
| Created | a ticket was created |
| Assignment | assigned, reassigned, force-taken, moved to another department, an operator joined |
| Closing | closed, resolved |
| Reopening | reopened, resumed after a snooze |
| Timing & SLA | snoozed, inactivity warning, kept open, response-time hint |
| Ratings | the customer rated the ticket |
| System | status changes, rules, emails and delivery failures, identification, customer moderation, widget disconnects |
CSV export
Export CSV downloads what's on the screen — with the chosen period and filters, up to 25,000 rows, newest first. Columns: time (in your zone), who, actor type, action, event code, the ticket's number and subject, details. The export is part of the plan's Analytics export feature.
Through the API
With the sign-in Bearer token of an owner or admin. Parameters: period (today, 7d, 30d, 90d, year, all, custom with from and to), tz, actor (operator, system, customer), actor_id, comma-separated event_types, q; the list pages by next_cursor.
GET https://api.support.forestsnet.com/api/w/{workspace_id}/audit/events?period=30d&cursor=…
GET https://api.support.forestsnet.com/api/w/{workspace_id}/audit/activity?period=30d
POST https://api.support.forestsnet.com/api/w/{workspace_id}/audit/export?period=30d
