How Do You Audit User and Technician Activity in ManageEngine ServiceDesk Plus? - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How Do You Audit User and Technician Activity in ManageEngine ServiceDesk Plus?

What Should You Know First?

Here is the short version for admins in a hurry.

  • Auditing means answering four questions. Who did something, what they did, when they did it and on which record.
  • Several tools cover different angles. Request history tracks ticket actions, login reports show sign-in activity, custom reports track status and technician changes, and the system log viewer records admin-level events.
  • “Audit” has two meanings in the product. Asset audit reports describe workstation scans, not user behaviour, so do not mix them up.
  • Deleted records need special care. Once someone deletes a request, its history disappears, so restrict delete permissions.
  • A routine beats a one-time check. Schedule reports and reviews, then act on what you find.
  • Menu names vary by edition. Confirm paths in your own console.

Follow the steps below to build an audit process that satisfies managers, auditors and your own curiosity.


What Is ManageEngine ServiceDesk Plus and Why Does Auditing Matter?

ManageEngine ServiceDesk Plus – ITSM Software is an IT service management platform. IT teams use it to log incidents, handle service requests, manage changes, track assets and publish knowledge articles. Every action on those records comes from a person, so the platform sits at the centre of accountability in your IT department.

How Does Auditing Relate to the Software?

Technicians hold real power in ManageEngine ServiceDesk Plus – ITSM Software. They close tickets, change priorities, reassign work and sometimes edit assets. Most of the time, they use that power well. Occasionally, though, a ticket vanishes, a status changes without explanation or an account logs in at a strange hour. Auditing gives you the evidence to resolve those situations quickly and fairly.

Why Do Auditors Care?

Frameworks such as ISO 27001, SOC 2 and internal governance policies expect you to log and review privileged activity. The National Institute of Standards and Technology (NIST) covers this in its SP 800-53 controls under the audit and accountability family, and in SP 800-92, the guide to computer security log management. Both documents stress that you must generate, protect and review logs, not just store them.


What Can You Audit in ServiceDesk Plus?

Before you open any report, decide what you want to learn. ServiceDesk Plus offers several audit sources, and each one answers a different question.

Which Audit Sources Exist?

Audit sourceWhat it showsBest question it answers
Request History tabEvery action on a single request“What happened to this ticket?”
Login reportsLast login, logout and login hours“Who signed in, and when?”
Custom reports (status, technician, group changes)Change history across many requests“Who reassigned or reclassified tickets?”
System Log ViewerApplication and admin-level log entries“What happened behind the scenes?”
Asset audit reportsWorkstation scan history“How did this computer change?”

Why Should You Separate Activity Audits from Asset Audits?

The word “audit” appears in two places. ManageEngine’s documentation describes audit history reports for workstations, which list hardware and software changes after scans. Those reports help with inventory management, not technician oversight. Keep them separate in your mind, so you do not hunt for user actions in an asset report.


How Do You Review the History of a Single Request?

The request history gives you the most detailed view of ticket-level activity. Start here for most investigations.

Where Do You Find the History Tab?

ManageEngine’s help documentation explains the path: open the Requests tab, click the subject of the request, and select the History tab in the request details page. The tab displays the complete list of actions from the moment of creation. The documentation describes the history as essential for future reference and audit purposes.

The page lists entries in order, with the earliest action at the top and the latest at the bottom. Read from the top to follow the story chronologically.

What Details Should You Look For?

Focus on the following clues:

  • Who created and who last updated the request.
  • When the status changed and who changed it.
  • When the technician or group changed.
  • Which notes, replies or resolutions someone added or edited.
  • How long the request sat in each status.

How Do You Use the History in a Dispute?

Suppose a requester says nobody responded for two days. Open the history and check the first technician action. The timestamps settle the question. If the history shows a fast reply, share it with the requester. If it shows a gap, use it as a coaching moment for the team.


How Do You Track Login and Logout Activity?

Login data reveals patterns that ticket history cannot. It shows who accessed the system, how often and from where.

Which Login Reports Does ServiceDesk Plus Provide?

ManageEngine’s report documentation lists predefined login reports based on user login activity. They include details such as last login time, last logout time, IP address, domain, email and department. The documented reports include:

  • Last login and logout time of technicians.
  • Login hours of technicians in the current month.
  • Users’ last login and logout time.
  • Support groups with their technicians, login names and last login time.

How Do You Read a Login Report?

Look for anomalies. A technician who logs in from an unusual IP address deserves a question. An account with no logins for months may need deactivation. A technician with very long login hours might signal shared credentials or a workload problem. Login reports do not prove wrongdoing, but they point you toward the right follow-up.

How Do Login Reports Help with Licences?

ServiceDesk Plus licences follow technician logins, according to ManageEngine’s admin FAQ. Login reports therefore help you spot idle accounts that waste licences. Remove the login from inactive technicians and reclaim the seat.

Which Steps Should You Follow Each Month?

  1. Open the login reports from the reports section.
  2. Filter for the current month.
  3. Sort by last login time.
  4. Flag accounts with no recent activity.
  5. Check unusual IP addresses or login hours.
  6. Record your findings and actions.

How Do You Audit Changes Across Many Requests?

Single-request history works well for one ticket. For patterns across the whole help desk, use reports.

Which Report Types Track Changes?

ServiceDesk Plus lets you build custom reports. ManageEngine’s documentation lists tabular report modules such as status changed history, technician changed history and group changed history. You can also create matrix, summary and request metrics reports.

Use the change history modules to answer questions like these:

  • Who changed the most request statuses last week?
  • Which technician reassigned the most tickets?
  • Which requests moved between groups repeatedly?

How Do You Build a Custom Audit Report?

  1. Open the reports section and choose to create a new custom report.
  2. Select a report type, such as Tabular Report.
  3. Choose a module, for example the technician changed history.
  4. Pick the columns you need, such as request ID, old technician, new technician, changed by and date.
  5. Add filters for a date range or group.
  6. Run the report and review the results.
  7. Save the report and schedule it if your edition supports scheduling.

What Do Assessment Reports Add?

The predefined reports also include assessment-style views. ManageEngine describes reports that assess request status, technician and group changes, along with status change comments and time spent. Use them to compare technicians fairly and to catch unusual handling patterns.

How Do You Avoid Unfair Conclusions?

Numbers need context. A technician who reassigns many tickets may work in triage, where reassignment is the job. Always compare like with like, and discuss surprising results with the technician before you draw conclusions.


How Do You Use the System Log Viewer for Admin-Level Events?

The system log viewer records what happens inside the application itself. It complements ticket-level history.

Where Do You Find the System Log Viewer?

ManageEngine’s MSP documentation explains that users with permission to view support information see a Support tab in the header. From there, you open the System Log Viewer to view the error logs the application generates. Each entry shows the message, the module, the time and a probable cause if known.

What Does It Track About User Activity?

The log focuses on errors and system events, and it also captures some admin operations. A ManageEngine community answer from an earlier release explains that the application logs many admin operations in the log viewer, but it does not track every request open, update or close there, because the request history covers those actions. The same answer notes that when someone deletes a request, the request history vanishes, and only the deletion appears in the system log.

That community thread dates from several years ago, so verify current behaviour in your version. Nevertheless, the lesson holds: deletion leaves less evidence than other actions.

How Do You Protect Against Silent Deletions?

Restrict delete permissions through roles. Give delete rights only to senior technicians or administrators. Then review the system log for deletion events on a schedule. Fewer people with delete rights means fewer gaps in your audit trail.


How Do You Build a Repeatable Audit Routine?

One investigation fixes one problem. A routine prevents many. Design a schedule your team can maintain.

Which Tasks Belong in Your Routine?

TaskSuggested frequencyOwner
Review login reports for anomaliesMonthlyService desk manager
Review technician change historyMonthlyService desk manager
Review deletion events in the system logMonthlyAdministrator
Audit technician roles and delete permissionsQuarterlyAdministrator
Check inactive technician loginsMonthlyAdministrator
Prepare evidence for external auditorsBefore each auditCompliance lead

How Do You Document Findings?

Keep a simple audit log of your own. Record the date, the report you reviewed, what you found, and what you did about it. Auditors appreciate evidence that you reviewed logs and acted, not just that you collected them.

How Do You Protect the Logs Themselves?

Logs lose value if someone can alter them. NIST’s log management guidance recommends protecting logs from unauthorised access and modification. Limit who can view support information and system logs, and keep separate accounts for administrative work. Also back up your database regularly, since much of the audit data lives there.


How Do Roles and Permissions Support Auditing?

Auditing works best when you limit what technicians can do in the first place. Fewer powers mean fewer things to investigate.

Which Role Settings Matter Most?

Review these settings in your technician roles:

  • Delete permissions for requests, problems and changes.
  • Permission to edit requester details.
  • Access to admin functions and support information.
  • Access to reports and report creation.
  • API key generation.

ManageEngine’s documentation explains that roles bundle add, edit, delete and view permissions per module, and that you can build custom roles. Use that flexibility to separate duties. For example, give your auditors a read-only role with report access, so they can inspect activity without changing it.

How Do You Support Separation of Duties?

Avoid a single person who can both perform and approve sensitive actions. Split responsibilities across roles and teams. When you do, your logs become more meaningful, because one person cannot quietly complete an entire chain of actions alone.


What Common Audit Problems Can You Fix Quickly?

ProblemLikely causeFix
A request has vanishedSomeone deleted itCheck the system log for the delete event, then restrict delete rights
A history tab shows fewer details than expectedVersion or setting differencesCheck your edition’s documentation and test with a sample ticket
Login report shows no data for a userThe user never logged in, or the account lacks login accessVerify the technician’s login settings
Report results look incompleteFilters exclude dataAdjust the date range and module selection
You cannot see the Support tabYour role lacks permissionAsk an administrator to grant view permission for support information
Auditors ask for older dataRetention limits or cleanup settingsReview retention and archive settings, and export reports regularly

What Are the Key Takeaways?

Auditing user and technician activity in ServiceDesk Plus combines several tools. The request history explains individual tickets, login reports reveal access patterns, custom reports expose change trends and the system log viewer records admin-level events. Together, they answer who did what, when and where.

ManageEngine ServiceDesk Plus – ITSM Software gives you these tools out of the box, but the value comes from consistent use. Build a monthly routine, restrict delete permissions, protect your logs and document your findings. Above all, treat audits as a way to improve service and fairness, not merely as a hunt for mistakes.

Because features and menu names change between editions and versions, check ManageEngine’s current help pages before you configure reports. Start with one report and one review meeting, then expand as your team gets comfortable.


What Questions Do Admins Ask Most About Auditing ServiceDesk Plus?

Does ServiceDesk Plus Track Every Action a Technician Takes?

Not everything appears in one place. The request history tracks actions on each request, login reports track sign-ins, and the system log records application and admin events. Because coverage differs, combine several sources. Test your own version by performing a sample action and checking where it appears.

What Happens to the History When Someone Deletes a Request?

According to a ManageEngine community answer, the request and its history no longer exist in the database after deletion, and only the delete event appears in the system log. Confirm current behaviour in your edition, and limit delete permissions through roles to reduce the risk.

Can I Schedule Audit Reports Instead of Running Them by Hand?

Custom reports let you define the modules, columns and filters you need, and many editions support report scheduling. Check the reporting options in your edition. If scheduling is available, send monthly login and change reports to your service desk manager automatically.


Recommended: