The Audit Log screen can report a partial chain, an inconsistent hash sequence, missing rows after restore, or a chain warning the filters cannot explain. Treat the case as security-relevant until the operator can connect it to an approved restore, backup import, update, retention policy or maintenance action.
Triage the issue
- Open Audit Log from the workspace, then use the topbar
?to confirm the current operator procedure. - Capture the active filters, date range and visible chain state before changing anything.
- Identify the first inconsistent event and the closest known-good event before it.
- Check whether a restore, backup import, update, retention cleanup or maintenance job ran in the same window.
- Stop non-essential write operations if the chain appears broken and no approved maintenance event explains it.
What to check
| Area | Check | Expected result |
|---|---|---|
| Filters | User, category, date and severity filters | A partial view caused by filters is clearly distinguishable from a broken chain. |
| Maintenance | Backup import, restore, update and retention events | The chain transition has a matching administrative event. |
| Storage | Server restart, disk full, database replacement or manual copy | No unsupported database movement occurred outside VaultPilot procedures. |
| Evidence | Last known-good export or backup metadata | The operator can explain what changed without exposing secret payloads. |
Safe evidence
- VaultPilot server version and approximate incident time.
- Redacted filter set, event ids and event categories around the first warning.
- Whether restore, import, update, retention cleanup or maintenance ran.
- Chain status text and count summary, not raw database rows.
- Windows service restart timestamps if relevant.
Escalate privately
Email support@vaultpilot.io when the warning remains after filter review, when the first inconsistent row cannot be tied to approved maintenance, or when multiple admins were active during the same window. Do not continue normal rotation, sharing or user-administration work until the chain status is understood.
Do not send
Do not send database files, backups, secret payloads, master passwords, raw logs with credentials, screenshots showing vault records, or customer/user identities, even to support.
Related
Still stuck?
Check the troubleshooting guide, then write to support@vaultpilot.io with the version, the steps you took and the exact redacted error. Never attach passwords, vault exports or private keys.