The audit trail lists the last 16 actions performed on the system from which the configuration loaded into Manager was received. It includes actions by service users such as sending a configuration back, reboots, upgrades and defaulting the system.
Audit trail events can be output to a Syslog server through the system's System | System Events settings.
The last failed action is always recorded and shown in red. It is kept even if there have been 16 subsequent successful actions.
The Audit Trail is part of the system configuration file received from the system. If the configuration is kept open between send and reboot operations (ie. if Close Configuration/Security Setting After Send is not selected), the Audit Trail will not show details of those operations. It will only show details of those operations if the configuration is closed and then a new copy of the configuration is received from the system.