PingOne

Running an audit report

You can run reports to see a summary of user events or events for actions performed in the PingOne admin console.

You can find a complete list of events logged in PingOne in Audit Reporting Events in the PingOne API documentation.

Steps

  1. In the PingOne admin console, go to Monitoring > Audit and enter the report parameters.

    Learn more in Audit parameters.

    A screen capture of the Audit Parameters section without any selections made.

    Option Description

    Time Range

    Limit the report results to a specific time period.

    Data up to 14 days old relative to the current date is available immediately. Data older than 14 days must be requested from the Audit page or using the API. You can’t request data for dates that are more than 2 years (730 days) before the current date.

    You can run reports or retrieve data for a maximum of 14 days at a time.

    Filter Type

    Limit the results to a particular type, user, or resource. Learn more about the filters available in Audit parameters.

    Selected Fields

    Specify which columns appear in the results list.

    Time Zone

    Specify the time zone to use in the results list. The timestamp shows the date and time for the selected time zone.

    Secondary Filter Type

    Specify a secondary filter to further limit the results to a particular type, user, or resource. You must specify a primary filter type before you can select a secondary filter type.

  2. Click Run Report.

Result

The information displayed depends on the date range for which you requested data.

Within the 14-day window for immediate availability

For example, on May 4, 2026, you enter a relative time range of 9 days, or a specific date range of 2026-04-26 to 2026-05-04.

Full results display immediately for the requested dates because no older data needs to be retrieved.

A screen capture of the Audit Report results for a 9 day time range in the current 14-day reporting retrieval window.
Outside of the 14-day window for immediate availability

For example, on July 23, 2026, you enter a specific date range of 2026-07-01 to 2026-07-08.

The Run Report modal displays explaining that the requested data isn’t immediately available and must be retrieved. The requested dates are displayed in the modal. Select the checkbox and then click Run Report to retrieve data for the requested dates.

A screen capture of the Run Report modal with a message to retrieve data because requested dates aren’t immediately available.

A message indicating a data retrieval is in progress displays in the Available Dates (UTC) section of the Audit Parameters page.

Includes both dates for which data is immediately available and dates for which data must be retrieved

For example, on August 7, 2026, you enter a specific date range with a start date of 2026-07-16 and an end date of 2026-07-27.

This range includes 9 days of data that must be retrieved (2026-07-16 to 2026-07-24) and 3 days of immediately available data (2026-07-25 to 2026-07-27).

The Run Report modal displays, and you must confirm that you want to retrieve the data for the dates that aren’t immediately available. Select the checkbox and then click Run Report to retrieve data for the requested dates.

A screen capture of the Run Report modal with a message to retrieve data for some dates because requested dates aren’t immediately available.

The results display for the dates that are immediately available. A message indicating a retrieval request for the older data is in progress displays in the Available Dates (UTC) section of the Audit Parameters page.

  • Depending on the number of days requested and the average number of events logged per day, the process can take from 2 to 24 hours.

  • You can request a maximum of 14 days of data within the data retention period, and you can’t request additional data while another request is pending. If you request more than 14 days of data, or another request is pending, the checkbox in the Run Report modal is disabled and you can’t submit the request.

  • If you have a valid email address in PingOne, you’ll receive a notification email when the data is ready. After the data is retrieved, you can return to the Audit Parameters page and run reports against the data for the timeframe requested.

  • The retrieved data is available for 14 days from the date of the retrieval request.

Next steps

  • To rearrange the columns in the report summary, click Columns. The Re-order Columns modal displays. Drag the columns into the order you want to display them, then click Save.

  • To view the details of an event, click View in the Details column.

  • To export your results to a CSV file, click Export.