Users & audit
Users & audit is only in the left-hand menu for admins. It controls who can sign in and what they can do, and keeps a record of every change.
| Role | Can |
|---|---|
| Viewer | Read everything: documentation, topologies, IP plans, configs, lab plans. |
| Engineer | Everything a viewer can, plus edit documentation, import and re-sync from GNS3, run a Proxmox sync, fetch running configs and take snapshots. |
| Operator | Everything an engineer can, plus build labs in GNS3 and push configs to devices. |
| Admin | Everything, plus GNS3 and Proxmox connection settings, restore and import, user management and the audit log. |
Buttons a user isn’t allowed to use are hidden, and the server refuses the request even if someone tries it directly. Viewers see a read-only banner at the top of every page.
The first admin account
Section titled “The first admin account”On its first start, the NetSimLab server prints a one-time setup code in its terminal. Open NetSimLab in your browser, enter the code, and choose the admin’s username and password. The code makes sure nobody else on your network can claim the admin account first.
Add a user
Section titled “Add a user”- Open Users & audit → Users and click + Add user.
- Enter the Username, Display name and Role, and a Temporary password (at least 12 characters).
- Save and give the user their username and temporary password. They must choose their own password the first time they sign in.
Manage users
Section titled “Manage users”- Edit changes a user’s display name or role, or resets their password (Reset password (optional)). After a reset, they must choose a new password at their next sign-in.
- Disable stops a user signing in without deleting them; Enable lets them back in.
- You can’t change your own role, disable yourself, or remove the last active admin.
Every user can change their own password from the menu at the bottom of the left-hand menu (Change password). Doing so signs out their other sessions.
Sign-in protection
Section titled “Sign-in protection”- Five wrong passwords lock that account for 15 minutes; 20 failures from one address lock that address.
- You’re signed out after 60 minutes of inactivity, and after 12 hours in any case. Restarting the server signs everyone out.
Review the audit log
Section titled “Review the audit log”Users & audit → Audit log records:
- every sign-in, including failures and lockouts, and every password and user change;
- every change to the documentation, plus imports, restores, exports and downloads;
- GNS3 and Proxmox actions, lab builds and config pushes, and how each background job ended;
- every request that was refused.
Each entry shows the time, user, role, action, target, client IP address and result. Passwords, API keys, tokens and config text are never written to it.
To find something:
- Type in Search user, action, target, IP…, or pick a category in Action (sign-ins and passwords, user administration, snapshots, GNS3, Proxmox, lab builds, config pushes, background jobs).
- Click Load older entries to page back.
- Click Export CSV to download the entries for a report or your SIEM.
Tamper check
Section titled “Tamper check”Each entry includes a fingerprint (SHA-256 hash) of the one before it. The page shows chain intact when nobody has edited the log file outside NetSimLab, or chain broken at #n if they have. Entries from that point on can’t be trusted.