AccessManagement
authz
AccountOwnershipAssigned
Severity | Status | Audit Event |
Info | Success | Yes |
AccountOwnershipRevoked
Severity | Status | Audit Event |
Info | Success | Yes |
AdminRequestedPasswordChange
Severity | Status | Audit Event |
Info | Success | Yes |
AllRolesDeassignedFromUser
Severity | Status | Audit Event |
Info | Success | Yes |
AllRolesDeassignedFromUserGroup
Severity | Status | Audit Event |
Info | Success | Yes |
AuthorizedUserGroupsToOrg
Severity | Status | Audit Event |
Info | Success | Yes |
HideUser
Severity | Status | Audit Event |
Info | Success | Yes |
OrgCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
OrgDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
OrgUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
PasswordComplexityPolicyUpdated
Severity | Status | Audit Event |
Info | Success | Yes |
PasswordComplexityPolicyUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleAssignedToUser
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignedToUserGroup
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignmentToUserFailed
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignmentToUserGroupFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleDeassignedFromUser
Severity | Status | Audit Event |
Info | Success | Yes |
RoleDeassignedFromUserGroup
Severity | Status | Audit Event |
Info | Success | Yes |
RoleDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleUpdated
Severity | Status | Audit Event |
Info | Success | Yes |
RoleUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountCreated
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountDeletionPreparationFailed
${actorSubjectName} tried to start a delete request on ${count} service accounts. The preparation for the deletion failed. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountSecretRotated
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountSecretRotationFailed
${actorSubjectName} failed to rotate the secret of the service account ${targetSubjectName}. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
SSOUserCreated
Severity | Status | Audit Event |
Info | Success | Yes |
SSOUserCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UpdatedUserGroupsInOrg
Severity | Status | Audit Event |
Info | Success | Yes |
UserChangedOtherUserPassword
Severity | Status | Audit Event |
Info | Success | Yes |
UserChangeOtherUserPasswordFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
UserDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserDeletionPreparationFailed
${actorUserEmail} tried to start a delete request on ${count} users. The preparation for the deletion failed. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserGroupDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
UserGroupDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserInvited
Severity | Status | Audit Event |
Info | Success | Yes |
federated_access
SetCDMInventoryDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetCDMInventoryEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetCDMInventoryEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetFederatedAccessDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetFederatedAccessEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetFederatedAccessEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
mfa
MaxPasskeysChanged
Severity | Status | Audit Event |
Info | Success | Yes |
MfaRememberDisable
Severity | Status | Audit Event |
Info | Success | Yes |
MfaRememberHoursUpdate
${username} updated Rubrik Two-Step Verification to remember device from ${initialHours} to ${hours} hours.
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyAdded
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeysAllowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeysDisallowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyTypeAllowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyTypeDisallowed
Severity | Status | Audit Event |
Info | Success | Yes |
TotpGlobalEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpGlobalUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpLdapEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpLdapUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpReconfigure
Severity | Status | Audit Event |
Info | Success | Yes |
TotpReminderDisable
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpReminderHoursUpdate
${username} updated the Rubrik Two-Step Verification reminder frequency from every ${initialHours} hours to once every ${hours} hours.
Severity | Status | Audit Event |
Info | Success | Yes |
TotpReset
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpSetup
Severity | Status | Audit Event |
Info | Success | Yes |
TotpUserLevelEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpUserLevelUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
moat
FailedAPICallDueToIPViolation
${api_name} failed to execute as it was accessed from an unauthorized IP address ${ip_address} for the ${user_domain} ${username}
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetWhitelistDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetWhitelistEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetWhitelistEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
UpdateWhitelistFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UpdateWhitelistSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
userlockout
AutoUnlocked
Severity | Status | Audit Event |
Info | Success | Yes |
LockedByAdmin
Severity | Status | Audit Event |
Info | Success | Yes |
LockedByBruteForce
Severity | Status | Audit Event |
Warning | Success | Yes |
LockedDueToLeakedPassword
User ${email}'s account was locked because the account is at risk of being compromised. The account credentials were found to have been compromised in another vendors security breach.
Severity | Status | Audit Event |
Warning | Success | Yes |
LockoutConfigChanged
${admin} updated the account lockout configuration, (${changedConfigs}), for the ${orgName} organization.
Severity | Status | Audit Event |
Info | Success | Yes |
UnlockedByAdmin
Severity | Status | Audit Event |
Info | Success | Yes |