HomeDocumentationAPI Reference
Log In
These docs are for v26. Click to read the latest docs for v33.

Audit Events Reference

NAMECODESEVERITYDESCRIPTION
License-error0Critical(2)The system license does not allow operation.
Configuration-error1Critical(2)The system configuration is invalid.
Service-starting10Info(6)The service is starting.
Service-running11Info(6)The service is running.
Service-stopped12Warning(4)The service has been stopped.
Unknown-event99Critical(2)Unknown event ID
User-logged-in100Info(6)User has logged in to the system.
User-login-failed102Warning(4)User login operation failed.
User-MFA-challenge-sent103Info(6)User tried to log in without MFA pin code.
User-MFA-challenge-accepted104Info(6)User successfully authenticated with MFA pin code.
User-MFA-challenge-setup-sent105Info(6)User was MFA setup information.
Access-token-granted106Info(6)Access token granted.
User-access-token-refreshed110Info(6)User refreshed the access token.
User-access-token-refresh-failed111Warning(4)User access token refresh failed.
OAuth-client-authenticated121Info(6)OAuth client authenticated.
OAuth-client-authentication-failed122Warning(4)OAuth client authentication failed.
User-login-attempt-rate-limited130Info(6)User login attempt rate limited.
Role-added201Info(6)New role added to the system.
Role-modified202Info(6)Role has been modified.
Role-removed203Info(6)Role has been removed.
Directory-added210Info(6)New directory added to the system.
Directory-modified211Info(6)Directory has been modified.
Directory-removed212Info(6)Directory has been removed.
Directory-authentication-failed213Info(6)Directory authentication failed.
User-roles-modified220Info(6)The user's role associations were changed.
AWS-token-granted230Info(6)AWS token was granted to a user.
AWS-token-grant-failed231Warning(4)AWS token grant failed.
LogConf-collector-created232Info(6)LogConf collector created.
LogConf-collector-modified233Info(6)LogConf collector modified.
LogConf-collector-removed234Info(6)LogConf collector removed.
LogConf-collector-failed235Warning(4)LogConf collector failed.
RoleContext-usage-alert250Warning(4)RoleContext limitations were violated.
RoleContext-role-blocked251Warning(4)RoleContext limitations were violated, role blocked.
Authorized-key-added260Info(6)Authorized key added.
Authorized-key-modified261Info(6)Authorized key modified.
Authorized-key-removed262Info(6)Authorized key removed.
Identity-provider-added270Info(6)New IDP added to the system.
Identity-provider-modified271Info(6)IDP has been modified.
Identity-provider-removed272Info(6)IDP has been removed.
Connection-requested300Info(6)Connection was requested.
Connection-authenticated301Info(6)Connection was authenticated.
Connection-rejected302Warning(4)Connection was rejected.
Connection-closed303Info(6)Connection was closed.
Connection-failed304Info(6)Connection closed with an error.
Client-authenticated305Info(6)Client was authenticated.
Session-added310Info(6)A session was added to a connection.
Session-removed311Info(6)A session was removed from a connection.
Session-rejected312Warning(4)A session was rejected.
File-upload320Info(6)File upload performed.
File-download321Info(6)File download performed.
File-upload-rejected322Warning(4)File upload was rejected.
File-download-rejected323Warning(4)File download was rejected.
Host-key-matched324Info(6)Host key matched.
Host-key-denied325Alert(1)Host key denied.
Host-key-accepted326Info(6)Host key accepted.
Host-key-saved327Info(6)Host key saved.
Extender-connected328Info(6)Extender connected.
Extender-disconnected329Warning(4)Extender disconnected.
File-removed330Info(6)File removed via SSH.
Folder-removed331Info(6)Folder removed via SSH.
File-moved332Info(6)File moved.
Folder-created333Info(6)Folder created.
Connection-audit-started334Info(6)Connection audit started.
Connection-audit-failed335Alert(1)Connection audit failed.
Host-certificate-trusted336Info(6)Host certificate trusted.
Host-certificate-matched337Info(6)Host certificate matched.
Host-certificate-denied338Alert(1)Host certificate denied.
Host-certificate-accepted339Info(6)Host certificate accepted.
Host-certificate-saved340Info(6)Host certificate saved.
Connection-accepted341Info(6)Connection accepted.
File-upload-blocked342Warning(4)File upload blocked by ICAP.
File-download-blocked343Warning(4)File download blocked by ICAP.
Authorization-requested400Info(6)A client requested an authorization.
Authorization-certificate-granted401Info(6)An authorization certificate granted.
Authorization-role-key-granted402Info(6)An authorization role key granted.
Authorization-role-key-sign-operation-rejected403Warning(4)An authorization role key sign operation was rejected.
Authorization-role-key-sign-operation-accepted404Info(6)An authorization role key sign operation was accepted.
Authorization-rejected405Alert(1)An authorization was rejected.
Authorization-certificate-warning406Warning(4)Authorization certificate creation generated warnings.
Authorization-passphrase-returned407Info(6)Authorization passphrase was returned.
Principal-added410Info(6)A principal was added.
Principal-removed411Info(6)A principal was removed.
Trusted-client-added420Info(6)A trusted client was added.
Trusted-client-modified421Info(6)A trusted client was modified.
Trusted-client-removed423Info(6)A trusted client was removed.
API-client-added424Info(6)An API client was added.
API-client-modified425Info(6)An API client was modified.
API-client-removed426Info(6)An API client was removed.
License-updated430Info(6)The service license was updated.
CA-certificate-created440Info(6)CA certificate was created.
CA-certificate-deleted441Info(6)CA certificate was deleted.
EE-certificate-enrolled442Info(6)End entity certificate was enrolled.
EE-certificate-revoked443Info(6)End entity certificate was revoked.
CA-certificate-enrolled444Info(6)CA certificate was enrolled.
CA-certificate-revoked445Info(6)CA certificate was revoked.
EE-certificate-deleted446Info(6)EE certificate was deleted.
Access-group-created450Info(6)Access group created.
Access-group-modified451Info(6)Access group modified.
Access-group-deleted452Info(6)Access group deleted.
User-added500Info(6)New user added to the system.
User-modified501Info(6)User has been modified.
User-removed502Info(6)User has been removed.
User-password-modified510Info(6)User password has been modified.
User-authenticated520Info(6)User has been authenticated.
User-authentication-failed521Warning(4)User authentication has failed.
Workflow-added600Info(6)A workflow was added.
Workflow-modified601Info(6)A workflow was modified.
Workflow-removed602Info(6)A workflow was removed.
Request-added610Info(6)A request was added.
Request-removed612Info(6)A request was removed.
Decision-made620Info(6)A decision has been made on a request.
Email-sent630Info(6)A email notification has been sent.
Email-configuration-modified631Info(6)Email configuration has been modified.
Email-not-sent632Info(6)Email not sent.
Log-downloaded700Info(6)Log files have been downloaded.
Log-level-modified710Info(6)The log level was modified.
Host-added801Info(6)A host was added.
Host-modified802Info(6)A host was modified.
Host-removed803Info(6)A host was removed.
Host-service-connection-re-established804Info(6)A host service connection re-established.
Host-service-connection-failure805Warning(4)A host service connection failed.
Host-disabled-state-changed806Info(6)Host disabled state changed.
White-list-added811Info(6)A white list was added.
White-list-modified812Info(6)A white list was modified.
White-list-removed813Info(6)A white list was removed.
Connection-terminated900Info(6)Connection terminated.
Connection-terminated-for-host901Info(6)Connection terminated for host.
Connection-terminated-for-user902Info(6)Connection terminated for user.
Licensed-connection-count-exceeded903Warning(4)Licensed connection count exceeded.
Access-role-granted910Info(6)Access role granted.
Access-role-revoked911Info(6)Access role revoked.
Connections-meta-removed920Info(6)Connections meta removed.
Connection-blocked-by-ueba930Alert(1)Connection blocked by Ueba.
Connection-unusual-behavior-by-ueba931Warning(4)Connection marked as unusual by Ueba.
Connection-marked-anomaly-by-ueba932Alert(1)Connection marked as anomaly by Ueba.
Trail-opened1000Info(6)Trail opened.
Trail-open-failed1001Alert(1)Failed to open trail.
Trail-file-open-failed1002Alert(1)Failed to open trail file.
Trail-file-read-failed1003Alert(1)Failed to read trail file.
Trail-removed1004Info(6)Trail removed.
Trail-remove-failed1005Warning(4)Failed to remove trail.
Trail-file-integrity-failed1006Alert(1)Trail file integrity check failed.
Trail-file-downloaded1007Info(6)Trail file downloaded.
Config-checksum-added1100Info(6)A config file checksum was added.
Config-checksum-changed1101Info(6)A config file checksum has changed.
Transcript-status-scheduled1201Info(6)Transcript status: scheduled.
Transcript-status-indexing1202Info(6)Transcript status: indexing.
Transcript-status-indexed1203Info(6)Transcript status: indexed.
Transcript-status-error1204Warning(4)Transcript status: error.
Transcript-status-not-indexed1205Info(6)Transcript status: not indexed.
Transcript-trail-removed1206Info(6)Transcript trail removed.
Transcript-opened1207Info(6)Transcript opened.
Disk-full1301Critical(2)Disk full.
Auditevent-removed1302Info(6)Auditevent removed.
PrivX-restarted1303Info(6)PrivX restarted.
PrivX-db-clock-out-of-sync1304Warning(4)PrivX and Database clocks are out of sync.
Secret-created1400Info(6)Secret created.
Secret-removed1401Info(6)Secret removed.
Secret-accessed1402Info(6)Secret accessed.
Secret-changed1403Info(6)Secret changed.
Secret-metadata-changed1404Info(6)Secret's metadata changed.
Settings-modified1501Info(6)Settings modified.
Network-target-created1600Info(6)Network target created.
Network-target-modified1601Info(6)Network target modified.
Network-target-removed1602Info(6)Network target removed.
Router-initialized1603Info(6)Router initialized for network access manager.
Router-init-failed1604Warning(4)Router initialization for network access manager failed.
Network-session-opened1605Info(6)Network session opened.
Network-session-closed1606Info(6)Network session closed.
Network-session-failure1607Warning(4)Network session failure.
Network-session-fatal-failure1608Alert(1)Network session fatal failure.
Network-target-disabled-state-changed1609Info(6)Network target disabled state changed.
Password-rotation-policy-created1700Info(6)Password rotation policy created.
Password-rotation-policy-modified1701Info(6)Password rotation policy modified.
Password-rotation-policy-removed1702Info(6)Password rotation policy removed.
Password-rotation-script-created1703Info(6)Password rotation script created.
Password-rotation-script-modified1704Info(6)Password rotation script modified.
Password-rotation-script-removed1705Info(6)Password rotation script removed.
Password-rotation-failure1706Alert(1)Password rotation failure.
SSH-live-event1800Info(6)SSH live event
SSH-whitelisted-command-allowed1801Info(6)SSH whitelisted command allowed
SSH-non-whitelisted-command-allowed1802Info(6)SSH non-whitelisted command allowed
SSH-command-blocked1803Info(6)SSH command blocked