Skip to main content

September 2, 2026

Monitoring Administrator and End User Activity from the Activity Logs Page

The Activity Logs page presents data regarding current and past events in the system. You can use activity logs for auditing and debugging purposes.

Access the Activity Logs page by selecting Monitor > Activity Logs from the Horizon Universal Console. The page contains the Admin tab for audit logs and system activities and the End User tab for user events. You can perform the following tasks:

  • Filter the events displayed using the filter tools available on each tab.
  • Refresh the list.
  • Export the event log to a CSV file that you can download.

Note: By default, the Activity Logs show the past 24 hours. While you can view the last 90 days of historical data, the maximum date range you can query at one time is 31 days.

Administrator Events

The Admin tab displays a table of information about both administrator and system initiated events. Expand an event to view details, such as information about related events, resource event history and subtasks.

The table of events consists of several columns, including Event, Status, and Type. The Type column lists two types of admin events, as follows.

  • System

    Indicates system activities.

  • Audit

    Indicates audit logs. Audit logs are generated by various operations initiated by administrators and users. Some audit logs might require you to take action, but many are for informational purposes only. For example, audits related to Horizon Edge Gateway updates are informational only.

The following filtering options are available on the Admins tab:

  • Display events for only a certain time period or a certain operation name using the filters at the top of the tab.
  • Filter events shown in the table using the filter tool in each column.

Automatic Agent DCT Log Collect Events

When a virtual machine fails during the customization step, Horizon Cloud automatically collects the agent diagnostic (DCT) logs if the customer has enabled Omnissa Operator access to diagnostic logs.

These automatically collected logs appear in the Admin tab with the following characteristics:

  • Event: Collect Agent DCT Log
  • Status: Indicates whether the log collection succeeded or failed
  • Initiated By: Omnissa Operations

These entries help administrators identify when diagnostic data has been collected automatically for troubleshooting purposes.

User Events

The End User tab displays details about user actions, such as the name of the user who initiated the action, type of action, status of the action, and time the action was initiated. If the status is Failed, click the word Failed to reveal details about the failure.

The following filtering options are available on the End User tab:

  • Display events for only a certain time period using the filters at the top of the tab.
  • Filter events shown in the table using the filter tool in each column.

Viewing End User Logs

Administrators can view activity logs for end users for up to the past 60 days.

Procedure: Viewing and Exporting Admin Activity Logs

Administrators can view and export activity logs for administrators for up to the past 90 days.

Exported logs are saved in CSV format. The default file name includes a timestamp. You can customize the file name.

  1. From the Horizon Cloud left pane navigation, click Monitor > Activity Logs and then select the Admin tab.
  2. You can use the All events drop-down above the logs table to view all events or specific events.
  3. You can use the Manage Columns button to control the display of table column filters.
  4. Specify the desired time range within the last 90 days. You can specify up to a 31 day From To date range as noted in onscreen help. The From date must be within the last 90 days.
  5. Click Export and specify a file name for the log file or accept the default file name.
  6. As prompted, open the Downloads page by clicking Monitor > Downloads in the Horizon Cloud left pane navigation.
  7. Locate your named file row on the Downloads page and click Download in the Action column for that row.
  8. Open the downloaded CSV file to view its contents. Contents include the event name and description, type, initiator, status, site name, edge name, time, resource name and ID, and severity for each event in the log.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…