The Security tab surfaces the activity most worth a second look: bulk deletions, activity outside working hours, and records being shared.
Select Dashboard in the left navigation, then Security.
Security Anomalies
Findings from the last 7 days, each tagged with a severity.

Figure 1. The Security tab showing the Security Anomalies finding for off hours activity and the Recent Deletes & Shares card.
The two patterns EaseLog looks for are bulk deletes and off hours activity. An off hours finding reports how many operations fell outside normal working hours, in UTC, and how many of those were deletions.
Read findings as questions, not verdicts
A finding is a prompt to look, not evidence of wrongdoing.
High off hours activity very often has an innocent explanation: an overnight integration, a scheduled job, a data migration, or simply colleagues in another time zone. The times are in UTC, so allow for the offset before deciding something happened at an odd hour.
What matters is whether you can explain it. An off hours finding you can account for is fine. One you cannot is worth pursuing.
Recent Deletes & Shares
Two lists side by side, showing the most recent Deletes and the most recent Shares, each with a count.
Deletions matter because they remove data. Shares matter because they widen who can see it. Both are worth a periodic glance even when nothing has been flagged.
If both read zero with nothing listed, nothing of either kind has been recorded.
Record Forensics
A search box that takes a record ID and returns that record's complete audit timeline.

Figure 2. The Record Forensics search box, where a record ID returns that record's full audit timeline.
This is the tool for the question "what happened to this specific record". It is covered in its own article. See Record Forensics: Tracing a Single Record.
A sensible routine
- Glance at Security Anomalies for anything new.
- Check Recent Deletes & Shares.
- If something needs explaining, take it to the Log View and filter by Changed Date and Changed By. See Filtering Records.
- If you have a specific record, use Record Forensics instead.
Note
This tab reports on the environment selected in the Environment picker at the top right. Check each environment separately.