Theme
Activity
Monitoring, then Activity: every file operation this Connector performed or denied, most recent first.
This is where the real reason for a refusal lives. Users are told an operation was denied and never why; the full reason is recorded here.
What each row shows
| Column | Meaning |
|---|---|
| When | |
| User | |
| Operation | Upload, download, delete, rename, list, and so on |
| File or folder | The path, and the destination on a rename or move |
| Virtual file system | Which storage it happened in |
| Result | Allowed or Denied |
Filters
Filter by user, by virtual file system, by file or folder name, and by Denied only.
Denied only is the filter to reach for first when somebody says "it does not work". It usually answers the question in one click.
Two logs, not one
This page is the queryable activity log, and it can be turned off in Settings.
The tamper evident security log is always written, whatever this switch says, and cannot be turned off. It is the one that makes an evidence claim. See Log integrity.
If Activity says the queryable log is turned off, this page has nothing to show and the signed record is still complete.
What is not here
Sign in attempts. Authentication happens on your site, not on the Connector. A user who never gets past the sign in never reaches this log.
Account changes. Users, plans and team changes are in the Portal's own Activity log.
What is here that is nowhere else
Who touched which file. That record exists only on your Connector. It never travels to SFTP.cloud, and there is no interface anywhere in the Portal that could show it.