Skip to main content

Unified Activity Reports

Unified Activity is a reusable report type that merges the site's history stores into one time-ordered view. It answers the cross-cutting question “what happened here?” across commands and API calls, access control, alarms, automation, site modes, monitors, and entity state.

Create a Unified Activity report

Event kinds

KindSourceWhat it shows
RequestsRequest historyCommands, macro calls, and API requests with user and result
AccessAccess logAccess control events with grant or denial result
AlarmsAlarm eventsAlarm activations with severity, message, and lifecycle status
AutomationAutomation historyTrigger, schedule, and macro runs with status
Site ModesSite mode historyMode changes for the site and its spaces
MonitorsMonitor tag historyMonitor rollup state transitions
State ChangesAttribute historyRecorded attribute changes for one selected zone or device

Choose one or more kinds in the report definition. State Changes are available only when the report is scoped to a zone or device.

Filters and scope

Unified Activity reports support:

  • A start-inclusive, end-exclusive date range.
  • Whole-site activity or one selected zone or device.
  • One or more activity kinds.
  • An exact recorded username.
  • Text matching across the curated title, detail, status, severity, user, and target fields.
  • A configurable row limit.

The Unified Activity buttons in zone and device editors, and in Device Health rows, open Reports with a new Unified Activity definition already scoped to that entity.

Output and delivery

Choose the columns to show, preview the result, export CSV, send it immediately, or save one or more email schedules. Scheduled Unified Activity reports support previous day, rolling 24 hours, and today periods.

Unified Activity reports expose only curated event fields. Raw request JSON and underlying record bodies are deliberately excluded from report previews, CSV, email, and AI context because they may contain credentials or tokens. Use Access Activity, Request History, Alarms, and Monitoring when deeper operational investigation is needed.

Limits and retention

Each source is bounded before the combined timeline is sorted. The preview indicates when a source or the merged result was capped; narrow the date range or kinds for more complete coverage.

The report only reaches as far back as each source's retention window, configured on Data Retention.