Cost Analyzer user activities

Prev Next

Overview

User activities in Cost Analyzer records every management action taken by users across the module. You can view these logs to track who changed what, when, and within which feature — from module-level configuration down to individual cost management groups.

Business value

A complete audit trail of user actions supports governance requirements and simplifies incident investigation. When something changes unexpectedly — a budget threshold is modified, a tag rule is deleted, or a service principal is updated — you can identify the responsible action and actor without manual investigation.

How it works

User activities logs are organized into categories, each corresponding to a management domain in Cost Analyzer. You can access logs at two scopes:

  • Module level — click the settings (gear) icon next to Cost Analyzer at the top of the tree view and select User activities to see all activity across the module.
  • Cost management group level — click the Context menu ( ⋮ ) next to a group in the tree view and select User activities to see logs scoped to that group only.

Access to User activities depends on your role and scope:

  • Module-level User activities is available to Account owner, Owner, and Contributor roles only. Users with custom roles cannot access it.
  • Tree node-level User activities (cost management group and below) is accessible to users with custom roles.
  • Users with Specified access can only view User activities for the nodes within their assigned scope.

Each log entry includes:

  • User ID — the user who performed the action
  • Action type — the operation performed (Created, Updated, Deleted, Generation initiated, etc.)
  • Feature / Section — the Cost Analyzer feature where the action occurred
  • Timestamp — date and time of the action
  • Status — indicates whether the action was successful
  • Additional context — relevant details about the change

You can filter the log by category, cost management group, action type, and date using the Filter by controls. The Category filter lists each log domain individually so you can focus on a specific area.

Cost Management Groups

This category records all actions performed on cost management groups and their child resources, including monitors, dashboards, allocation rules, views, and workflows:

  • Creating a cost management group or child resource
  • Updating a cost management group or child resource
  • Deleting a cost management group or child resource

Service principal management

This category records all actions performed on service principals connected to Cost Analyzer:

  • Adding a service principal
  • Updating a service principal
  • Deleting a service principal

User management

This category records all user access and role changes within Cost Analyzer:

  • Adding a new user or group
  • Updating user permissions
  • Removing an existing user or group
  • Adding a new role
  • Updating an existing role
  • Deleting a role

Escalation policy management

This category records all actions performed on escalation policies in Cost Analyzer:

  • Creating an escalation policy
  • Updating an escalation policy
  • Deleting an escalation policy

Exposed API

This category records write operations performed via the Cost Analyzer API. Logged operations span four API groups:

Group management

  • Creating a cost analyzer group
  • Updating a cost analyzer group
  • Deleting a cost analyzer group

Monitoring

  • Adding a monitor
  • Updating a monitor
  • Deleting a monitor
  • Enabling or disabling a monitor

Schedule

  • Creating an optimization schedule
  • Updating an optimization schedule
  • Deleting an optimization schedule
  • Enabling or disabling an optimization schedule
  • Removing resources from a schedule
  • Adding an on-demand schedule run

Workflow

  • Running a workflow

Performance tuning

This category records all actions performed on Performance tuning configuration, including tag index creation and deletion:

  • Creating a tag index
  • Deleting a tag index

Chart library

This category records all actions performed on chart schemas in the Chart library:

  • Adding a chart schema
  • Editing a chart schema
  • Cloning a chart schema
  • Deleting a chart schema
  • Applying a chart schema
  • Importing a chart schema

Custom cost imports

This category records all actions performed on custom cost import configuration, including manual import triggers:

  • Creating a custom cost import
  • Updating a custom cost import
  • Deleting a custom cost import
  • Triggering a manual import

Tag manager

This category records all actions performed on tag rule configurations:

  • Creating a rule configuration
  • Updating a rule configuration
  • Deleting a rule configuration
  • Running a rule configuration on demand

Reports

This category records all actions performed on reports:

  • Updating a report
  • Initiating report generation

Related articles