Open Audit (/audit).
Each IPAM write (prefix, subnet, pool, reservation, token, DNS record, webhook, NetBox, force-release, …) records before/after. The table is append-only. Use it when someone asks “who moved that reservation.”
Overview also shows recent IPAM changes.
DHCP acks are not audit rows; they are lease rows and JSON logs (xid, MAC, IP). Subscribe ipam.audit on a webhook if a SIEM should see the same events.