**TL;DR** — Every Canvas quiz keeps a per-second event log for every student. It records question views, answer changes, browser-tab focus events, submission time, and IP address. Instructors can open this log for any submission.
Last updated: July 2026.
Exact fields the log captures
- Session start timestamp.
- Every "question viewed" event with timestamp.
- Every "answer selected / changed" event with timestamp.
- Every "session stopped viewing the Canvas window" event (tab switch, alt-tab, monitor change).
- Every "session resumed viewing" event.
- Total time on each question.
- Final submission timestamp and IP.
What the log does NOT capture
- Which application you switched to.
- What was on your other monitor.
- Your webcam or microphone (that's proctoring software, separate).
- Copy-paste events inside answer fields (Canvas does not log this).
How professors use it
Common flags:
- You "stopped viewing" for 40 seconds while answering a 4-line short-answer, then came back with a polished paragraph.
- Total quiz time was 6 minutes on a 45-minute timed quiz, all answers correct.
- Answer changes cluster in bursts across questions — pattern suggests referencing an external source.
Where the log lives
SpeedGrader → student attempt → "View Log." Instructors need to enable Quiz Log Auditing in course settings first, but it's on by default in most modern Canvas installations.
What you can do
- Don't leave the Canvas tab during a quiz.
- Don't answer with 40-second gaps followed by full paragraphs.
- Take short-answer questions in a single, natural pass.
If you want to prepare so the log tells a normal story, see our [exam preparation service](/services/online-exam-help).
**Sources**: Instructure Canvas Quiz Log Documentation (2026), Canvas Community forum instructor discussions (2025-26).
