FortiSOAR Knowledge Base
FortiSOAR: Security Orchestration and Response software provides innovative case management, automation, and orchestration. It pulls together all of an organization's tools, helps unify operations, and reduce alert fatigue, context switching, and the mean time to respond to incidents.
Andy_G
Staff
Staff
Article Id 194871
Description

This playbook allows you to query and export the audit log using a playbook triggered from the attachments module.


Steps:

1. Import the playbook to a new collection

2. Go to the attachments module (/modules/attachments)

3. Run "Historical Audit Log Export"


It will generate a CSV file with the audit data and save it as an attachment. Optionally, the playbook contains an example of zipping the audit data into a password protected zip file and emailing it as an attachment.


Applicable to version 4.11.0+


for CyOPs versions 5.0 and higher, attached an updated version



Contributors