Audit chain is partial or inconsistent

The Audit Log screen can report a partial chain, an inconsistent hash sequence, missing rows after restore, or a chain warning the filters cannot explain. Treat the case as security-relevant until the operator can connect it to an approved restore, backup import, update, retention policy or maintenance action.

Triage the issue

  1. Open Audit Log from the workspace, then use the topbar ? to confirm the current operator procedure.
  2. Capture the active filters, date range and visible chain state before changing anything.
  3. Identify the first inconsistent event and the closest known-good event before it.
  4. Check whether a restore, backup import, update, retention cleanup or maintenance job ran in the same window.
  5. Stop non-essential write operations if the chain appears broken and no approved maintenance event explains it.

What to check

AreaCheckExpected result
FiltersUser, category, date and severity filtersA partial view caused by filters is clearly distinguishable from a broken chain.
MaintenanceBackup import, restore, update and retention eventsThe chain transition has a matching administrative event.
StorageServer restart, disk full, database replacement or manual copyNo unsupported database movement occurred outside VaultPilot procedures.
EvidenceLast known-good export or backup metadataThe operator can explain what changed without exposing secret payloads.

Safe evidence

  • VaultPilot server version and approximate incident time.
  • Redacted filter set, event ids and event categories around the first warning.
  • Whether restore, import, update, retention cleanup or maintenance ran.
  • Chain status text and count summary, not raw database rows.
  • Windows service restart timestamps if relevant.

Escalate privately

Email support@vaultpilot.io when the warning remains after filter review, when the first inconsistent row cannot be tied to approved maintenance, or when multiple admins were active during the same window. Do not continue normal rotation, sharing or user-administration work until the chain status is understood.

Do not send

Do not send database files, backups, secret payloads, master passwords, raw logs with credentials, screenshots showing vault records, or customer/user identities, even to support.

Still stuck?

Check the troubleshooting guide, then write to support@vaultpilot.io with the version, the steps you took and the exact redacted error. Never attach passwords, vault exports or private keys.

Open the troubleshooting guide

Back to Knowledge base