Searching an audit log is more than adding a text box. Cost depends on which investigations the team needs to perform, how records are indexed, who can search them, and how exports and retention are controlled.

Define search questions

List actor, action, resource, tenant, date range, outcome, reason, request ID, change type, and source. Start with investigations the business actually performs.

Scope fields and indexes

Cost increases with full-text, exact, range, multi-value, JSON, related-resource, saved, and fuzzy search. The audit log search filter checklist helps separate useful filters from expensive noise.

Price permission and tenant rules

Include field masking, role, tenant isolation, support access, sensitive actions, result counts, export, and access audit. Every search query must respect the same boundaries as the original event.

Include performance

Budget for index growth, date bounds, pagination, query timeout, cache, archive, retention, and incomplete-result state. Do not make an expensive unbounded query the default investigation path.

Privacy and retention

Mask values, limit free text, expire exports, define access logging, and keep audit evidence from becoming a second uncontrolled data store.

Maintenance cost

Allow for new event fields, schema updates, index tuning, storage, role changes, saved view review, support, and incident investigation. Assign an owner for search semantics.

Audit logs growing faster than the team can investigate? Ask Vertinus to scope search, access, retention, and performance together.