Following a suspected insider threat incident, the security team requests a complete record of all configuration changes, user logins, and administrative actions performed within the Instana tenant over the past 45 days. Which Instana feature provides this information?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Instana maintains an Audit Log that captures a timestamped record of all administrative activities within the tenant, including user authentication events, configuration changes, and user management actions performed by named actors. This log is accessible through the Settings section of the Instana UI and provides the evidence trail required for security investigations and compliance audits. The Events feed and trace list reflect monitored application and infrastructure data, not Instana platform administrative activity.
Full explanation below image
Full Explanation
Instana maintains an Audit Log that captures a timestamped record of all administrative activities within the tenant, including user authentication events, configuration changes, and user management actions performed by named actors. This log is accessible through the Settings section of the Instana UI and provides the evidence trail required for security investigations and compliance audits. The Events feed and trace list reflect monitored application and infrastructure data, not Instana platform administrative activity. The correct answer is 'The Audit Log, accessible under Instana Settings, which records user logins, configuration changes, and administrative actions with timestamps and actor identity'. The incorrect options — 'The Events feed filtered by severity level Critical and category Infrastructure to isolate security-relevant events', 'The Unbounded Analytics section, queried with a custom ERQL filter targeting internal Instana management service calls', 'The Application Monitoring trace list filtered to show only internal service calls directed at Instana APIs' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 7: Security/Compliance domain of the IBM Instana Observability certification.