# Reviewing audit logs for GitHub Copilot

> Check for changes to settings or licenses in your Copilot plan.

- 网址：https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-for-enterprise/review-audit-logs/
- 来源：GitHub Copilot 官方文档原文（英文），CC-BY-4.0 许可，同步于 2026-10-11
- 官方原文：https://docs.github.com/en/copilot/how-tos/administer-copilot/manage-for-enterprise/review-audit-logs

---
You can use the audit log to review actions taken in your enterprise. The audit log includes a record of:

* Changes to your Copilot plan, such as changes to settings and policies or a user losing or receiving a license
* Agent activity on the GitHub website

The audit log does **not** include client session data, such as the prompts a user sends to Copilot locally. A custom solution is required to access this data: for example, some companies use custom hooks to send Copilot CLI events to their own logging service.

## Viewing your enterprise's audit logs

1. Navigate to your enterprise. For example, from the [Enterprises](https://github.com/settings/enterprises?ref_product=ghec&ref_type=engagement&ref_style=text) page on GitHub.com.

1. At the top of the page, click gear **Settings**.
1. Under "Settings", click **Audit log**.

## Searching audit log events

Use the `action:copilot` search term to view all events related to your Copilot plan.

You can also filter by a specific event. For example, `action:copilot.cfb_seat_assignment_created` returns events related to a license being assigned to a new user. For a full list of Copilot events, see [AUTOTITLE](https://docs.github.com/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise) or [AUTOTITLE](https://docs.github.com/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/audit-log-events-for-your-organization).

To view a record of agent activity, use the `actor:Copilot` search term. See [AUTOTITLE](https://funcoding.ai/agents/github-copilot/reference/enterprise-administrators/agentic-audit-log-events/).

<div class="callout callout-note">

For team-based seat assignments, the `copilot.cfb_seat_added` event's actor may not be the account that performed the membership change. See [AUTOTITLE](https://funcoding.ai/agents/github-copilot/reference/copilot-billing/seat-assignment/#seat-assignment-management).

</div>

## Retaining audit log history

The audit log retains events for the last 180 days. We recommend streaming the audit log to a Security Information and Event Management (SIEM) platform, where you can view long-term history and set up alerts for anomalous activity. See [AUTOTITLE](https://docs.github.com/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
