Record Forensics answers the question an audit trail exists to answer: what happened to this particular record, who touched it, when, and how.
When to use it
Use Record Forensics when you already know which record you care about. A customer disputes a change, a record shows unexpected values, or an investigation names a specific record.
Record Forensics or Audit Details
Both give you a record's complete audit timeline. The difference is where you are starting from.
You have Use A record ID, from a colleague, a ticket, an export or Dynamics 365 Record Forensics. The record in front of you in the Log View Double click it and read Record History in the Audit Details drawer. See Opening the Audit Details of a Record.Record Forensics is the right tool when the record ID arrives from outside EaseLog. If you are already looking at the grid, double clicking is quicker.
The Audit Details drawer also has a copy control on its Record ID, so it is the usual way to obtain an ID to paste in here.
Trace a record
- Select Dashboard in the left navigation, then Security.
- Scroll to Record Forensics.
- Paste the record ID into the box. It is a GUID.
- Select Search.

Figure 1. The Record Forensics search box, where a record ID returns that record's full audit timeline.
Until you enter an ID the panel reads Enter a record ID to begin.
What you get back
The record's full audit timeline: who touched it, when, and what they did.
Finding the record ID
The ID is the GUID Dynamics 365 uses for that record. The usual sources are the record's URL in Dynamics 365, an export, or a colleague who is already looking at it.
If nothing comes back
Work through these in order:
- Check the environment. Record Forensics searches the environment selected in the Environment picker at the top right. A record in a different environment will not be found here.
- Check the ID. It must be the full GUID.
- Check the sync has caught up. If the record was touched very recently, the audit record may not have arrived yet. Look at Sync Latency on the Overview tab, or the environment's queue.
- Check auditing was enabled. If auditing was not switched on for that entity at the time, there is nothing to find. EaseLog can only report what Dynamics 365 recorded.
Point 4 is the one that catches people out. An empty result can mean nothing happened, or it can mean nothing was being recorded when it did.
Note
Record Forensics reads the audit data EaseLog has already offloaded. It does not query Dynamics 365 directly.