Review Audit and Session History

Use event history to reconstruct production, Remote Control, ASL, takeover, glossary, and configuration actions.

Written By 4ALL.LIVE

Last updated About 1 month ago

Use event history to reconstruct production, Remote Control, ASL, takeover, glossary, and configuration actions.

Best for: Organization administrators, event producers, live operators, and authorized support staff.

Before you start

Event access and actions depend on organization role, team scope, plan entitlements, limits, and current event state.

  • Use an individual verified account in the correct organization and team.
  • Confirm the event owner, live operator, output owner, and incident authority.
  • Review the current configuration before changing an existing or live event.

Review workflow

  1. Open Audit & Logs. Confirm organization/event and time zone.
  2. Set the incident window. Record start/end and synchronize with external system clocks.
  3. Identify actors. Review named accounts, host/controller presence, roles, and ownership transitions.
  4. Trace state actions. Find preflight, Go Live, Stop, recovery, takeover, and output changes.
  5. Trace configuration. Review language/provider/routing/glossary/display/Remote Control/ASL changes available in the log.
  6. Correlate external evidence. Compare browser/desktop/provider/XPression/Encoder/receiver logs using timestamps.
  7. Export/capture safely. Redact tokens, credentials, personal data, and private URLs.
  8. Document finding. Separate observed fact from inference and record follow-up.

What success looks like: The event reaches the intended saved or live state, and every required operator can verify the result without receiving unnecessary access.

Check your setup

  • An incident timeline identifies authoritative event state, actors, changes, impact, and evidence gaps.

Troubleshooting

Expected action missing

Check event, time zone, log scope, product/source, and whether the action occurred locally or externally.

Actor unclear

Review named account, session ownership, Remote Control presence, and organization audit.

Timestamps differ

Normalize clocks/time zones before concluding sequence.

Security and operational notes

  • Audit data is sensitive.
  • Do not alter evidence while investigating.
  • Use individual accounts so actions remain attributable.