Unified Activity Reports
Unified Activity is a reusable report type that merges the site's history stores into one time-ordered view. It answers the cross-cutting question “what happened here?” across commands and API calls, access control, alarms, automation, site modes, monitors, and entity state.
Create a Unified Activity report
Event kinds
| Kind | Source | What it shows |
|---|---|---|
| Requests | Request history | Commands, macro calls, and API requests with user and result |
| Access | Access log | Access control events with grant or denial result |
| Alarms | Alarm events | Alarm activations with severity, message, and lifecycle status |
| Automation | Automation history | Trigger, schedule, and macro runs with status |
| Site Modes | Site mode history | Mode changes for the site and its spaces |
| Monitors | Monitor tag history | Monitor rollup state transitions |
| State Changes | Attribute history | Recorded attribute changes for one selected zone or device |
Choose one or more kinds in the report definition. State Changes are available only when the report is scoped to a zone or device.
Filters and scope
Unified Activity reports support:
- A start-inclusive, end-exclusive date range.
- Whole-site activity or one selected zone or device.
- One or more activity kinds.
- An exact recorded username.
- Text matching across the curated title, detail, status, severity, user, and target fields.
- A configurable row limit.
The Unified Activity buttons in zone and device editors, and in Device Health rows, open Reports with a new Unified Activity definition already scoped to that entity.
Output and delivery
Choose the columns to show, preview the result, export CSV, send it immediately, or save one or more email schedules. Scheduled Unified Activity reports support previous day, rolling 24 hours, and today periods.
Unified Activity reports expose only curated event fields. Raw request JSON and underlying record bodies are deliberately excluded from report previews, CSV, email, and AI context because they may contain credentials or tokens. Use Access Activity, Request History, Alarms, and Monitoring when deeper operational investigation is needed.
Limits and retention
Each source is bounded before the combined timeline is sorted. The preview indicates when a source or the merged result was capped; narrow the date range or kinds for more complete coverage.
The report only reaches as far back as each source's retention window, configured on Data Retention.