VelocityBlog
Nextcloud Auditing: A Complete Guide to Nextcloud Audit Logs
Updated: August 12, 2026
Published: August 12, 2026

TL:DR
Windows’ auditing is mostly inaccessible for SME sized businesses.
Nextcloud’s auditing log system is ideal for businesses with legal compliance obligations.
If a staff member left tomorrow, could your business say exactly which client files they opened in their final month? Not just what they changed, but what they viewed, downloaded or shared, and when?
For most Australian businesses, the honest answer is no. That gap is exactly what nextcloud file audit logging is built to close, and it matters most for the businesses with the least room for a gap: law firms, health and allied health practices, APRA-regulated financial institutions, accountants, and anyone else holding records that a regulator, insurer or court might one day ask about.
This guide walks through what audit logging actually means, why Windows file servers fall short, how nextcloud auditing solves the problem, and what it means for businesses working under Law Society and AHPRA style obligations. If your team is weighing up Velocity Host’s managed Nextcloud service against sticking with SharePoint, Microsoft 365 or Google Drive, the audit trail is one of the most consequential differences between them, and one of the least discussed.
What Does Audit Logging Mean for a File System?
Audit logging means keeping a permanent, timestamped record of who did what to a piece of data: who opened a file, who edited it, who deleted it, who downloaded it, and who shared it, and with whom. A proper audit log records the action, the exact time, and the real identity of the person responsible, not just a device name or a shared login.
For a business, this is the difference between saying “someone probably accessed that file” and being able to state, with evidence, precisely who did, and when. That distinction matters every time a staff member leaves under a cloud, a document goes missing, a client disputes what they were told, or a regulator asks how access to sensitive records is controlled.
Does Windows Have an Audit Log?
Technically, yes, but not in a form most small and mid sized businesses can actually use. Windows file servers can generate a security event log, and Microsoft’s own guidance sets out how administrators can enable auditing on individual files and folders through System Access Control Lists (SACLs) and Group Policy. In practice, this is switched off by default, has to be configured folder by folder, and produces raw security events rather than a readable “who touched this file” history.
That is the core problem with relying on a windows file audit log as your compliance record. Nothing is captured until someone deliberately turns it on, the settings are easy to get wrong or leave incomplete, and the resulting file server log audit sits in the Windows Event Viewer as thousands of cryptic entries rather than a plain answer. Add mapped drives and shared logins into the mix, a very common setup in small offices, and even a correctly configured windows file audit log often shows a generic account name instead of a real person. Most businesses discover this the day they actually need the history, and find it was never being kept.
How Nextcloud Auditing Closes the Gap
This is where Nextcloud takes a fundamentally different approach. Rather than bolting a monitoring tool onto a file server after the fact, Nextcloud is built so that the platform itself is the only door to your files. Every action, whether it happens in a browser, the desktop sync client, or a mobile app, is written to a dedicated log with the person’s real name and a timestamp.
Nextcloud’s built in admin_audit app records events including file access, edits, deletions, downloads, sharing activity, and login attempts, and can be reviewed directly inside the Nextcloud admin interface. Because access rides on each user’s own account rather than a shared login, nextcloud audit logs name an individual, not “user1” or a generic device. That single detail is what makes the difference between a genuine audit trail and a record that answers nothing.
On a well configured Velocity Host managed Nextcloud instance, this is what the audit log typically captures:
| What you need to know | Recorded? |
| Who opened or viewed a file, and when | Yes, by name |
| Who edited a file | Yes, by name |
| Who deleted a file | Yes, by name |
| Who downloaded a file | Yes, by name |
| Who shared a file, and with whom | Yes, by name |
| Failed and successful login attempts | Yes, timestamped |
| Administrator access to a user’s account | Yes, recorded |
| How long the history is kept | Set to your compliance needs |
No per user auditing licence, no separate server, no database to outgrow. It is part of how Velocity Host’s Nextcloud as a service is run from day one.
Where Can I Find Nextcloud Logs, and How Do I See File History?
Inside a standard Nextcloud instance, an administrator can find Nextcloud logs under Administration Settings, in the Logging section, which shows both the general system log and, once enabled, the admin_audit log. Individual users can also see a simplified version of file history through the built in Activity app, which shows recent changes, shares and comments on a file or folder from the user’s own view.
For a full audit history covering every user, retained over a longer period, most Australian businesses with compliance obligations are better served by a managed setup where retention, log storage location and access controls are deliberately configured rather than left on default settings, since out of the box installs can silently under log activity if nobody checks. This is one of the areas where a managed Nextcloud provider adds real value beyond simply hosting the software.
Nextcloud Audit Logs and the Law Society’s Digital Document Guidelines
Australian legal practices operate under some of the clearest expectations around file access records anywhere in the small business sector. The Law Society of NSW’s own guidance on the management and storage of digital documents recommends that a firm’s record retention policy include audit and monitoring requirements, specifically that document access logs are maintained and reviewed periodically as part of good practice management.
That is a plain description of what file audit logging is meant to achieve. A matter file with no record of who has opened it leaves a firm unable to answer a client, an auditor or the Law Society itself if access is ever questioned. Nextcloud gives a practice a way to answer that question without needing a separate compliance product bolted onto a file server, and because Velocity Host runs on Australia’s only Tier 4 data centre, those records and the files they describe stay under Australian jurisdiction throughout.
These guidelines are general practice management guidance rather than a legal requirement in themselves, and firms should confirm their own obligations under the Legal Profession Uniform Law and their state Law Society’s current rules.
Nextcloud Auditing for Health Practices and AHPRA Standards
Health, allied health and NDIS providers face a similar expectation from a different direction. AHPRA’s Good medical practice code of conduct requires practitioners to ensure medical records are held securely and protected against unauthorised access, alongside keeping records accurate, dated and legible.
Protecting records against unauthorised access is difficult to demonstrate without an audit trail showing exactly who has accessed a patient file and when. For a clinic running client files through a Windows share with no logging switched on, that expectation is effectively unmet by default. Nextcloud’s audit log addresses this directly: every file open, download or share is attributed to a named staff member, which gives a practice something concrete to point to if a patient, an auditor or a Board notification process ever asks how access to a record was controlled.
This is guidance for medical practitioners specifically; allied health, NDIS and aged care providers operate under related but distinct record keeping obligations from their own registration boards, and should check the current requirements that apply to their profession.
Nextcloud and APRA’s CPS 234 for Financial Institutions
Financial institutions face the most codified version of this requirement anywhere in the Australian economy. Banks, insurers and superannuation trustees regulated by APRA operate under Prudential Standard CPS 234 Information Security, which requires a regulated entity to maintain information security controls commensurate with the sensitivity of its data, to systematically test the effectiveness of those controls, and to include information security within its internal audit activities. Material information security incidents must be reported to APRA within 72 hours, and material control weaknesses within 10 business days.
An audit log is one of the more direct pieces of evidence a regulated entity, or a third party service provider supporting one, can point to when demonstrating control effectiveness. CPS 234 also makes clear that where information assets are managed by a related party or third party, the regulated entity must evaluate that party’s control design and operating effectiveness, which means the file platform underneath a broker, adviser or fund administrator’s day to day work is squarely in scope even if that business is not itself the APRA-regulated entity.
This gives a financial services business a running record it can hand to an internal auditor or an APRA-regulated principal on request, named users, timestamped actions, and a retention period set to the obligation rather than a default. This is general information rather than a compliance determination, and businesses operating under CPS 234, directly or as a service provider to a regulated entity, should confirm their specific control testing and reporting obligations with their compliance function or APRA directly.
The Privacy Act, the NDB Scheme and Why the Record Has to Exist Before the Breach
Every Australian business holding personal information, not just regulated professions, has a reason to care about this. Under the Privacy Act, if a data breach is suspected, the OAIC’s Notifiable Data Breaches scheme requires the business to assess whether personal information was actually accessed, and whether that access is likely to cause serious harm, in order to decide whether individuals need to be notified.
That assessment depends entirely on access records that already exist. A business cannot retroactively create a file audit logging history after the fact. The record is already there, covering the months before an incident is even suspected, rather than starting from the moment someone first asks the question.
Nextcloud Audit Logs vs SharePoint, Microsoft 365 and Google Drive
Pricing and audit capability tend to be discussed separately, but for SharePoint, Microsoft 365 and Google Drive they are closely linked. In each case, meaningful auditing is not simply switched on by default at the entry level plan.
On Microsoft 365, Purview Audit (Standard) is included with commercial plans and retains most records for 180 days. Extending that to one year, or accessing the deeper forensic detail most compliance reviews actually want, means moving to Audit (Premium), which is tied to Microsoft 365 E5 or a separate compliance add on, both priced well above the roughly $18 to $33 per user per month of the standard Business plans. On Google Workspace, audit trail and retention tools sit inside Google Vault, which is not included on the Business Starter or Business Standard tiers and only becomes available from Business Plus upward.
In both ecosystems, the pattern is the same: the audit capability a regulated business actually needs is an upgrade, priced per user, on top of the plan most small businesses start on. Multiply that across a growing team and the audit trail itself becomes one of the more expensive line items in the subscription.
Velocity Host’s managed Nextcloud pricing works differently. Nextcloud as a service starts from $80 per month for up to five users on a dedicated instance, with file audit logging included as standard rather than gated behind a higher tier or a per user add on. There is no seat based multiplier on the audit feature itself, and no separate compliance SKU to budget for as the team grows.
What About a Dedicated Windows Auditing Suite Like Netwrix?
For businesses committed to staying on a Windows file server rather than moving to Nextcloud, a dedicated auditing product such as Netwrix Auditor is a capable option. It is purpose built for Windows environments, covering Active Directory, file servers, Exchange, SharePoint and a range of other platforms with proper change and access auditing rather than the raw Event Viewer logs a default Windows setup produces.
Netwrix does need its own server to deploy and operate, separate from the file server it is auditing, and licensing is charged per user listed in Active Directory plus per module, so File Server auditing, Exchange, AD and any other platform each add to the bill individually. Pricing is on an annual subscription only, with no monthly option, and it scales with headcount in the same way the Microsoft 365 and Google Workspace audit tiers do.
Where Netwrix genuinely earns its cost is reporting. It can generate detailed, customisable compliance reports and schedule them to be emailed automatically to a compliance officer, practice manager or partner, which is a step beyond what Nextcloud’s built in admin_audit log offers out of the box.
For a business that wants to keep its existing Windows file server and is willing to take on the deployment work, Netwrix is a legitimate and well regarded solution. The trade off is the requirement of another server to manage, a longer deployment timeline, and an ongoing per user, per module cost that sits on top of whatever the file server itself already costs to run.
Real Results: Nextcloud Auditing in an Australian Business
A group of related Australian organisations, sharing an administration team and running over 100 users across sensitive client, HR and financial records, illustrates what this looks like in practice. Their files lived on a traditional Windows file server, reached through mapped drives, with permissions managed through Active Directory. It worked, until anyone asked a question about history: what had a departing staff member accessed, who had touched a document that had gone missing, or how access to personnel files was being controlled.
The Windows file server had no usable answer to any of it. Velocity Host migrated the group’s file workloads to a managed Nextcloud platform and made it the only path to the data, phasing out direct network share access entirely. Staff kept the folder structures and logins they were used to, now backed by two factor authentication, while every file open, edit, deletion, download and share was written to a dedicated audit log under the person’s real identity.
The result was a full audit trail retained for years rather than months, at no additional per user cost, alongside a capability the group had not asked for but gained anyway: real time co-editing of documents and spreadsheets, something a traditional Windows file share had never supported. Velocity Host’s case studies cover further examples of businesses making this kind of move.
Best Practices for File Server Auditing
Whether a business is running Nextcloud, a Windows file server, or a mix of both during a migration, the same principles hold for effective file server auditing:
- Record identity, not devices. An audit entry is only useful if it names a person, not a shared login or generic account.
- Log the full range of activity. Views and downloads matter as much as edits and deletions, particularly for confidentiality obligations.
- Store logs outside the system being audited. A log kept on the same server as the files it describes can be lost or altered in the same incident it is meant to explain.
- Set retention to match your obligations, not the default. Many defaults expire logs well before a typical investigation looks back.
- Review access periodically, not only after an incident. Regular spot checks catch problems earlier than waiting for a breach or complaint.
- Verify the logging survives updates. Software updates and reconfigurations can silently interrupt logging if audit settings are not deliberately checked afterwards.
Ready to Put a Real Audit Trail Behind Your Files?
If your business has ever needed to know who accessed a file and could not find out, that is worth fixing before it happens again rather than after. Talk to Velocity Host about managed Nextcloud and see how Nextcloud’s audit logging, hosted on Australia’s first Tier 4 data centre, fits your compliance obligations and your budget.
This article provides general information about audit logging for business files and is not legal or professional compliance advice. Businesses in regulated sectors should confirm their specific obligations with their relevant professional body or a qualified adviser. Regulatory references and pricing figures were verified as of 11 August 2026.
Frequently Asked Questions
Email Us About Nextcloud
"*" indicates required fields

Gerardo Altman, Director of Problem Solving
With over 25 years’ experience in the IT industry, Gerardo Altman is a key solutions architect and MD of Velocity Host, with a love for Tetris and complex puzzles of every nature you'll find me hard at work doing what I do best – finding solutions.
Don’t Pay for SEO (Unless You Are Able To Do These Things)
Most Australian small business owners who come to us with high expectations for SEO. Our SEO campaigns are capable of delivering leads, but the success of a campaign also depends on whether your business is operationally ready to make the most of the enquiries and visibility that SEO generates. VelocityHost…
How to Backup NAS to Cloud Storage For Secure Data Protection
Protecting your Network Attached Storage (NAS) data is essential for any organisation that handles critical information. While NAS systems provide excellent local storage capabilities, combining them with cloud backup creates a robust defence against data loss, ransomware attacks, and hardware failures. This guide explains the best NAS backup strategy, explores…
Cloud Based Server Backup Solutions: The Complete Guide for Australian Businesses
Every business that relies on digital infrastructure operates with a risk that most people prefer not to think about: what happens when the server goes down and the data is gone? Ransomware, hardware failure, accidental deletion, fire, flood. These issues happen to real businesses every week, and the organisations that…
Data Backup Best Practices: A Complete Guide for Australian Businesses
Every year, Australian businesses lose critical data to hardware failure, ransomware, accidental deletion, and natural disasters. In most cases, the damage is not caused by a lack of technology, but rather user error or a lack of processes. Without a documented & tested data backup strategy, even large organisations find…
Full vs Incremental vs Differential Backup: Understanding the Differences
For Australian business decision makers, selecting the right backup strategy is imperative. Understanding the difference between a full backup and an incremental backup, along with differential backup alternatives, determines how quickly your organisation recovers from data loss and how efficiently you use your storage resources. This comprehensive guide examines the three…