Controller audit log and timeline
SZ-MCP keeps its own copy of the controller’s admin audit log (Administration › Admin Activities) for 400 days, and merges it with every other kind of change into one timeline. Claude reads both. Every role can.
How do I find out who changed something on the controller?
Section titled “How do I find out who changed something on the controller?”Ask Claude, for example “who changed the Guest WLAN this week?” It uses
history.audit: the controller’s admin log, newest first, with each row’s
time, admin account, IP address, category, object, action, message and whether
it succeeded.
| Argument | Default | What it does |
|---|---|---|
sinceMinutes | 24 hours (at most 30 days) | How far back |
since, until | — | An exact window, in epoch milliseconds |
entity | — | Only rows that name an inventory object or anything under it, such as a zone and its WLANs |
user | — | One admin account, exact |
action | — | A substring of the action, such as update, create, delete, move or log on failed |
text | — | A substring of the message or object, such as a WLAN name |
includeLogons | Off | Log-on rows are left out unless this is on or action asks for them |
ok | — | Only successful (true) or failed (false) actions |
limit | 100 (at most 1,000) | Rows returned |
action: 'log on failed' shows failed log-on attempts, such as someone
guessing passwords.
How fresh is the copy, and how long is it kept?
Section titled “How fresh is the copy, and how long is it kept?”Each metric poll reads the rows added since the last one. The first poll
also backfills the previous 14 days. history.status() reports the newest
row, its age, and whether polling is on, when it last finished and its last
error.
The copy is kept 400 days, at most 100,000 rows, oldest deleted first. SmartZone itself keeps about a month.
What is the timeline?
Section titled “What is the timeline?”One list of everything that changed, newest first, from five sources.
history.timeline answers questions like “what changed before this started?”
or “what happened in Hall A last night?”
| Source | What it adds |
|---|---|
audit | Admin changes on the controller (log-ons left out) |
write | Writes made through SZ-MCP, with the SZ-MCP user |
inventory | Devices added, removed, renamed, moved, re-linked or tagged |
config | Which fields of a zone, WLAN, AP group or system setting changed between daily snapshots |
alert | Alert HARD state changes, acknowledgements and downtime |
It takes the same window and entity arguments as history.audit, plus
sources (default all) and limit (default 200, at most 1,000). With
entity, the writes listed are those post-change verification tied to that
object or what holds it.
Where do recent changes show on the dashboard?
Section titled “Where do recent changes show on the dashboard?”On the Overview page, the Recent changes card shows the last 7 days from the same sources except alerts, labelled Audit, Drift, Claude and Inventory. Its Write history link opens the list of SZ-MCP’s own writes. There is no dashboard page for the full audit log; ask Claude.