We need to submit log paths for Splunk auditing. This includes authentication/logon checks, user permission changes, system events, account management, and other server activity. Is it all in \Qlik\Compose\data\logs? I see tons of task activity.
Compose.log within that mentioned folder should give you all required details.
Example:
29 2023-02-21 09:38:30 [Authorization ] [INFO ] Could not get UserPrincipal for user XXXXX 67 2023-02-21 09:38:31 [Authorization ] [INFO ] Could not get UserPrincipal for user XXXXX