> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/search-and-investigation/viewing-logs-and-record-detail.md).

# Viewing logs and record detail

Selecting a record from Global Search, the Dashboard, or a monitoring view opens the detail sidebar. The detail sidebar is the primary surface for examining a single compromised identity and the device it was captured from.

**Availability:** All plans. Full log archive downloads require a Threat Intelligence subscription.

<figure><img src="/files/e6MnHOOYOu3f6qLZgIMD" alt=""><figcaption></figcaption></figure>

### Layout

The detail sidebar opens from the right and is organized into tabs:

* **Summary** — a narrative description, device metadata, and the exposed credentials.
* **History** — every recorded sighting of the device, presented as an audit trail.
* **Downloads** — full log archives, when available for the record.

The Downloads tab appears only when at least one downloadable archive exists for the record.

### Summary tab

#### Description

A short narrative explains how the identity and credentials were compromised and the recommended remediation, such as rotating passwords, revoking sessions, and enforcing multi-factor authentication.

#### Meta data

The metadata grid shows device attributes such as hostname, IP address, country, operating system, anti-virus, and the relevant dates. The most recent sighting is shown first.

When the most recent record does not contain a particular attribute, the platform fills the gap with the most recent earlier sighting that does, and marks that value with a small clock indicator. A footer note explains the convention, and hovering the value reveals the date it was observed. Attributes that changed across sightings always show the latest known value rather than an older one.

<figure><img src="/files/VV4S4GOhAggTaPRVsP5E" alt=""><figcaption></figcaption></figure>

#### Exposed credentials

Credentials are listed with the application or URL, the username, the password, and the capture date. Passwords are masked by default. They can be revealed individually, or all at once using the reveal control at the top of the section. Where supported, captured cookies and session data are also available.

<figure><img src="/files/hHWCI35NrffLZD22znIL" alt=""><figcaption></figcaption></figure>

### History tab

The History tab lists every sighting of the device, newest first, so an analyst can trace how the device's attributes and exposure changed over time. Internal bookkeeping fields are omitted so the view stays focused on meaningful attributes.

### Downloads tab

When a full log archive has been retained, it can be downloaded from this tab. Archive availability is indicated per record, and downloads require a Threat Intelligence subscription. Archives that are still uploading or that failed are labeled accordingly.

<figure><img src="/files/xESkm6oqLwByC8XY3ZFL" alt=""><figcaption></figcaption></figure>

### Access restrictions

Record detail is subject to rate limits and entitlement checks. If access is temporarily restricted, the sidebar shows a clear notice rather than failing silently. Session expiry returns you to sign-in.
