---
title: Changes
description: The record of who changed what in the Cloudflare environment, when and through which channel, with filters, event detail and on-demand sync.
updated: 2026-09-27
---

The **Alterações** (Changes) screen shows who changed what in the Cloudflare environment, when and through which channel. Events come from the Cloudflare account's audit log. The history covers up to 18 months, the Cloudflare limit.

## Where to find it

In the side menu, go to **Segurança** (Security) > **Alterações**. The top of the screen shows when the log was collected (**Coletado em …**, Collected on …).

## Search and filter

Use the **Buscar por e-mail, descrição, zona, recurso ou token** (Search by email, description, zone, resource or token) box for free text. The filters only offer options that exist in the collected data.

| Filter | Options |
|---|---|
| **Ação: todas** (Action: all) | Criação (Create), Alteração (Update), Exclusão (Delete), Leitura (Read) |
| **Canal: todos** (Channel: all) | Painel (Dashboard), API token, Global API key, OAuth, API, Origin CA key |
| **Produto: todos** (Product: all) | The Cloudflare products present in the log. |
| **Resultado: todos** (Result: all) | Sucesso (Success), Falha (Failure) |
| Period | **Últimas 24 horas** (Last 24 hours), **Últimos 7 dias** (Last 7 days), **Últimos 30 dias** (Last 30 days, default), **Todo o histórico** (All history), **Período personalizado** (Custom period, with **De** (From) and **Até** (To)) |

## Columns

| Column | What it shows |
|---|---|
| **Quando** (When) | Date and time of the event. |
| **O que mudou** (What changed) | The description of the change. |
| **Ação** (Action) | Create, update, delete or read. |
| **Quem e por onde** (Who and how) | Who did it and through which channel. |
| **Zona** (Zone) | The affected zone, when there is one. |
| **Resultado** (Result) | Success or failure. |

## Event detail

Select an event to open the side panel:

| Group | Fields |
|---|---|
| **Quem** (Who) | E-mail, Tipo (Type), Canal (Channel), Token, IP, Agente (Agent) |
| **Onde** (Where) | Zona (Zone), Produto (Product), Recurso (Resource), Requisição (Request) |
| **O que mudou** (What changed) | **Enviado (request)** (Sent) and **Resultado (response)** (Result) |
| **Correlação** (Correlation) | **ID na Cloudflare** (Cloudflare ID) and **Ray ID** |

## Sync changes

Changes are part of the scheduled collection, which runs once a day at 02:00 (Brasília time). To fetch the latest events before that, use **Sincronizar alterações** (Sync changes). During the sync, the screen shows **Sincronizando alterações** (Syncing changes).

This action requires the `connections.scan` permission, which is not part of the default tenant roles. To enable it, contact Guardnet. See [Roles and permissions](/en/advisor/referencia/papeis-e-permissoes/).

:::caution
API token connections need the **Account Settings: Read** permission (Account group) to read the audit log. For OAuth connections without that access, Advisor asks you to reconnect. See [Connect Cloudflare](/en/advisor/primeiros-passos/conectar-cloudflare/#token-permissions).
:::

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/cloudflare/alteracoes/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
