What's changed: New GH-100 Chapter 5 (monitoring usage & activity = analyze audit logs/API usage, SIEM streaming, admin vs Support triage and diagnostics, usage patterns [adoption/activity/underutilized features]; cost & performance optimization = usage reports for metered products [Actions minutes/storage/Packages/Copilot/GHAS], Actions cost optimization [filters/concurrency/caching/matrix/runner], reclaim unused seats, cut waste without lowering quality)
5.1Monitoring Enterprise Usage and Activity
Understand analyzing audit logs and API usage, distinguishing admin vs GitHub Support responsibilities and generating diagnostics, and evaluating usage patterns (adoption, activity, underutilized features).
Admins continuously monitor whether the enterprise is used safely, efficiently, and correctly. GH-100 tests analyzing audit logs and API usage, triaging issues (admin vs Support), and evaluating usage patterns (how much is adopted, where activity is, which features are underused).
5.1.1Analyzing audit logs and API usage
The audit log records "who did what, when," the basis for security, compliance, and troubleshooting (Chapter 3). Stream to a SIEM for long-term retention and correlation as needed. For API usage, analyze which tokens/apps call the API how much and whether they approach rate limits—excessive calls or anomalous patterns can signal inefficiency or abuse. This visibility detects and addresses issues early.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

