In the Admin Console, navigate to Settings > Content Logs.
- Adobe Enterprise & Teams: Administration guide
- Plan your deployment
- Basic concepts
- Deployment Guides
- Deploy Creative Cloud for education
- Deployment home
- K-12 Onboarding Wizard
- Simple setup
- Syncing Users
- Roster Sync K-12 (US)
- Key licensing concepts
- Deployment options
- Quick tips
- Approve Adobe apps in Google Admin Console
- Enable Adobe Express in Google Classroom
- Integration with Canvas LMS
- Integration with Blackboard Learn
- Configuring SSO for District Portals and LMSs
- Add users through Roster Sync
- Kivuto FAQ
- Primary and Secondary institution eligibility guidelines
- Set up your organization
- Identity types | Overview
- Set up identity | Overview
- Set up organization with Enterprise ID
- Setup Azure AD federation and sync
- Set up Google Federation and sync
- Set up organization with Microsoft ADFS
- Set up organization for District Portals and LMS
- Set up organization with other Identity providers
- SSO common questions and troubleshooting
- Set up Frame.io for enterprise
- Manage your organization setup
- Manage existing domains and directories
- Enable automatic account creation
- Domain Enforcement for restricted authentication
- Set up organization via directory trust
- Migrate to a new authentication provider
- Asset settings
- Authentication settings
- IP-based access control
- Privacy and security contacts
- Console settings
- Manage encryption
- Manage existing domains and directories
- Manage users
- Overview
- Manage administrative roles
- Manage user roles
- Manage Frame.io account roles
- User management strategies
- Assign licenses to a Teams user
- In-app user management for teams
- Add users with matching email domains
- Change user's identity type
- Manage user groups
- Manage directory users
- Manage exception list for domain enforcement
- Manage developers
- Migrate existing users to the Admin Console
- Migrate user management to the Admin Console
- Migrate Frame.io user management to the Admin Console
- Overview
- Manage products and entitlements
- Manage products and product profiles
- Manage products
- Buy products and licenses
- Manage product profiles for enterprise users
- Manage automatic assignment rules
- Entitle users to train Firefly custom models
- Review product requests
- Manage self-service policies
- Manage app integrations
- Manage product permissions in the Admin Console
- Enable/disable services for a product profile
- Single App | Creative Cloud for enterprise
- Optional services
- Manage Shared Device licenses
- Manage products and product profiles
- Get started with Global Admin Console
- Adopt global administration
- Select your organization
- Manage organization hierarchy
- Manage product profiles
- Manage administrators
- Manage user groups
- Create license assignment reports
- Update organization policies
- Manage policy templates
- Allocate products to child organizations
- Execute pending jobs
- Download audit logs and export reports
- Export or import organization structure
- Manage storage and assets
- Storage
- Manage projects
- Asset migration
- Reclaim assets from a user
- Student asset migration | EDU only
- Manage services
- Adobe Stock
- Custom fonts
- Adobe Asset Link
- Adobe Acrobat Sign
- Creative Cloud for enterprise - free membership
- Frame.io and Creative Cloud for teams and enterprise plans
- Deploy apps and updates
- Overview
- Create packages
- Customize packages
- Deploy Packages
- Manage updates
- Adobe Update Server Setup Tool (AUSST)
- Adobe Remote Update Manager (RUM)
- Troubleshoot
- Manage your Teams account
- Renewals
- Manage contracts
- Reports & logs
- Get help
Applies to enterprise & teams.
As an enterprise, you can get information on how end users are working with your assets, such as folders, files, and libraries.
Introduction
System administrators can access detailed Content Logs, which are available for direct download from the Admin Console or for real-time streaming through Adobe I/O Events. These reports provide information on how end users are working with corporate assets.
As end users interact with assets — actions such as create, update, or move — the details are recorded in log files. Actions performed on PDF Spaces are also logged. You can export these log files to track actions that users perform on the Creative Cloud and Document Cloud assets owned by your organization. As you move more assets into Adobe's cloud storage solutions, your coverage becomes more robust and meaningful.
Content Logs only contain details for users in the directories that you own. They do not contain details for users in a trusted directory. For more information on directories, see Directory Trusting.
You can track assets your Enterprise ID and Federated ID users manage. You can also track how Adobe ID users use these assets.
However, you can only track and control assets for the Adobe ID users migrated to Enterprise storage and authenticated by your organization. For personal Adobe IDs, individuals hold legal control of their assets. Learn how to migrate users from Adobe IDs to Enterprise ID, or Federated ID.
You can retrieve Content Logs for the following user actions:
Action | Description |
---|---|
Created | When a user uploads, imports, creates, or copies an item |
Read | When a user opens or views a file or library stored in the cloud, either through a browser or within an application |
Updated | When a user edits and saves an item |
Moved | When a user moves an item from one location to another |
Permanently deleted | When a user permanently deletes an item |
Version deleted | When the user deletes an item's version |
Sent an invite | When a user adds a collaborator to a shared item |
Accepted an invite | When a user accepts an invitation to join a shared item as a collaborator |
Changed a collaborator's role | When a user modifies a collaborator's role |
Created a public link | When a user creates a public link |
Read a public link |
When a user reads a public link |
Removed a public link | When a user removes a public link |
Requested access |
When a user requests access to an item |
Managed access |
When an item's owner responds to an access request |
Collaborator auto-added |
When an authenticated user is added as a collaborator to the asset by accessing a public link that is auto-add enabled |
Actions performed on assets stored within Lightroom, Lightroom Classic, Lightroom Mobile, Lightroom Web, Behance, and Adobe Stock are not logged.
To view the Content Logs for your organization, do the following:
-
-
Click Create Report.
-
Choose a date range and click Create Report.
The date range is as per your local time.
Logs can be generated for user activities that occurred in the past 90 days. When your report is ready for download, you receive a notification email.
-
After you receive the notification, click Download File under Content Logs in the Admin Console. The Content Logs report can contain multiple files, each of a maximum size of 100 MB.
A report is available in the Admin Console for seven days. Once deleted, you can regenerate it for the same time period, as long as the date range is within the past 90 days.
ملاحظة:For organizations with numerous users, the resulting 90-day Content Logs report can be large and contain many files, potentially preventing its full download, depending on the browser used. If you are unable to download the Content Logs report, try reducing the selected date range. For an improved experience, it might also be useful to edit the default settings of some browsers in order not to be asked where to save each file before each download.
Date Range
It displays the time in UTC. Depending on your location, it can differ from the date range you selected at the time of report creation.
Created Date
It displays your local time at the time of report creation.
The report is downloaded as csv files. For a description of the fields in the downloaded file, see Log Schema.
Stream content logs via Adobe I/O Events for real-time monitoring
In addition to downloading logs manually, enterprise customers can also stream content activity logs using Adobe I/O Events. This option is ideal for enterprises that require automated compliance tracking, security analytics, or integration into existing operational workflows.
It allows real-time ingestion into security and monitoring platforms such as:
- Splunk
- Microsoft Sentinel
- Sumo Logic
- Other SIEM or data analytics tools
Setting up
- Follow the Adobe I/O Events setup guide.
- Subscribe to Content Log Events.
Know your content log report
The report you download, contains the following information for each user activity:
Field | Description |
---|---|
Action | User action (For example, created, read, updated, moved, shared link) |
Date | Date and time of the event (UTC format) |
User name | Name of the user who performed the action |
User email | Email of the user who performed the action |
Source path | Source path of an item if moved within the same organization. External if moved across organizations. The field is blank for events other than Moved. |
Source version | Version of the source item when moved or copied |
Item path | Path of the item |
Item version | Version of the item |
Item name | Name of the item |
Item ID | Unique ID of the item generated by Adobe |
Item type | Folder, file, or library |
IP address | IP address from which the user performed the action. The field is blank for events other than the following: Created, Read, Updated, Moved, or Permanently deleted. |
Created | Date and time the item was uploaded or created in the cloud. The field is blank for events other than the following: Created, Read, Updated, Moved, or Permanently deleted. |
Last modified | Date and time the item was last modified. The field is blank for events other than the following: Created, Read, Updated, Moved, or Permanently deleted. |
Password protected | True if the shared link is password-protected, False if it isn't. The field is blank for events other than Shared link. |
Shared link | URL to the shared item. The field is blank for events other than Shared link. |
Collaborator role |
Role of the collaborator invited to join a shared item. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Collaborator email | Email of the collaborator invited to join the shared item. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Collaborator name |
Name of the user or group that requested access to an item. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Collaborator sharing privilege |
Can Share if the collaborator can share the item with other users or groups, Cannot Share if not. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Collaborator commenting privilege |
Can Comment if the collaborator can comment on the shared item, Cannot Comment if not. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Collaborator type |
User if the item has been shared with a User, Group if it has been shared with groups created by a user in Adobe Address Book, Enterprise Group if it has been shared with groups synced from Active Directory of the enterprise. The field is blank for events other than the following: Sent an invite, Accepted an invite, Changed a collaborator's role, or Managed Access. |
Access response |
Accepted or Rejected as per the response of the item's owner. The field is blank for events other than Managed Access. |
Release notes
The following issues may affect you if your organization has been updated to storage for business. You are on the new storage model if you see a Storage tab in the Admin Console.
- Logs can contain internal system events, such as events from system users identified as “<service name>@adobe.com” email addresses.
- Logs of internal system events may include paths that do not exist in the customer's directories.
- Some log entries may not include prefixes [creative_cloud] or [document_cloud] in the path column.