AccessManagement
authz
AccountOwnershipAssigned
Severity | Status | Audit Event |
Info | Success | Yes |
AccountOwnershipRevoked
Severity | Status | Audit Event |
Info | Success | Yes |
AdminRequestedPasswordChange
Severity | Status | Audit Event |
Info | Success | Yes |
AllRolesDeassignedFromUser
Severity | Status | Audit Event |
Info | Success | Yes |
AllRolesDeassignedFromUserGroup
Severity | Status | Audit Event |
Info | Success | Yes |
AuthorizedUserGroupsToOrg
Severity | Status | Audit Event |
Info | Success | Yes |
HideUser
Severity | Status | Audit Event |
Info | Success | Yes |
OrgCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
OrgDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
OrgInviteEmailsFailedToSend
Severity | Status | Audit Event |
Warning | Failure | Yes |
OrgUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
PasswordComplexityPolicyUpdated
Severity | Status | Audit Event |
Info | Success | Yes |
PasswordComplexityPolicyUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleAssignedToUser
${userEmail} updated the assigned roles for ${principalType} ${principal} from ${previousRoles} to ${currentRoles}
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignedToUserGroup
${userEmail} updated the assigned roles for SSO group ${principal} from ${previousRoles} to ${currentRoles}
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignmentToUserFailed
Severity | Status | Audit Event |
Info | Success | Yes |
RoleAssignmentToUserGroupFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleDeassignedFromUser
Severity | Status | Audit Event |
Info | Success | Yes |
RoleDeassignedFromUserGroup
Severity | Status | Audit Event |
Info | Success | Yes |
RoleDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
RoleDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
RoleSyncUpdated
${userEmail} modified role ${origRole}${role} and ${updatedSyncStatus} syncing for the role to CDM clusters.
Severity | Status | Audit Event |
Info | Success | Yes |
RoleUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountCreated
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountDeletionPreparationFailed
${actorSubjectName} tried to start a delete request on ${count} service accounts. The preparation for the deletion failed. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountSecretRotated
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountSecretRotationFailed
${actorSubjectName} failed to rotate the secret of the service account ${targetSubjectName}. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
ServiceAccountUpdated
Severity | Status | Audit Event |
Info | Success | Yes |
ServiceAccountUpdateFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SSOUserCreated
Severity | Status | Audit Event |
Info | Success | Yes |
SSOUserCreationFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SyncedRoleCreated
Severity | Status | Audit Event |
Info | Success | Yes |
UpdatedUserGroupsInOrg
Severity | Status | Audit Event |
Info | Success | Yes |
UserChangedOtherUserPassword
Severity | Status | Audit Event |
Info | Success | Yes |
UserChangeOtherUserPasswordFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
UserDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserDeletionPreparationFailed
${actorUserEmail} tried to start a delete request on ${count} users. The preparation for the deletion failed. Reason: ${reason}
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserGroupDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
UserGroupDeletionFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UserInvited
Severity | Status | Audit Event |
Info | Success | Yes |
classification_settings
DisabledClassificationBanner
Severity | Status | Audit Event |
Info | Success | Yes |
DisabledLoginBanner
Severity | Status | Audit Event |
Info | Success | Yes |
EnabledClassificationBanner
Severity | Status | Audit Event |
Info | Success | Yes |
EnabledLoginBanner
Severity | Status | Audit Event |
Info | Success | Yes |
UpdateClassificationBanner
Severity | Status | Audit Event |
Info | Success | Yes |
UpdateLoginBanner
Severity | Status | Audit Event |
Info | Success | Yes |
federated_access
SetCDMInventoryDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetCDMInventoryEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetCDMInventoryEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetFederatedAccessDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetFederatedAccessEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetFederatedAccessEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
mfa
MaxPasskeysChanged
Severity | Status | Audit Event |
Info | Success | Yes |
MfaRememberDisable
Severity | Status | Audit Event |
Info | Success | Yes |
MfaRememberHoursUpdate
${username} updated Rubrik Two-Step Verification to remember device from ${initialHours} to ${hours} hours.
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyAdded
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyDeleted
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeysAllowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeysDisallowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyTypeAllowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasskeyTypeDisallowed
Severity | Status | Audit Event |
Info | Success | Yes |
PasswordlessLoginDisabled
Severity | Status | Audit Event |
Info | Success | Yes |
PasswordlessLoginEnabled
Severity | Status | Audit Event |
Info | Success | Yes |
TotpGlobalEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpGlobalUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpLdapEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpLdapUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpReconfigure
Severity | Status | Audit Event |
Info | Success | Yes |
TotpReminderDisable
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpReminderHoursUpdate
${username} updated the Rubrik Two-Step Verification reminder frequency from every ${initialHours} hours to once every ${hours} hours.
Severity | Status | Audit Event |
Info | Success | Yes |
TotpReset
Severity | Status | Audit Event |
Warning | Success | Yes |
TotpSetup
Severity | Status | Audit Event |
Info | Success | Yes |
TotpUserLevelEnforce
Severity | Status | Audit Event |
Info | Success | Yes |
TotpUserLevelUnenforce
Severity | Status | Audit Event |
Warning | Success | Yes |
moat
AddIPWhitelistEntries
Severity | Status | Audit Event |
Info | Success | Yes |
DeleteIPWhitelistEntries
Severity | Status | Audit Event |
Critical | Success | Yes |
FailedAPICallDueToIPViolation
${api_name} failed to execute as it was accessed from an unauthorized IP address ${ip_address} for the ${user_domain} ${username}
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetIPWhitelistSetting
Severity | Status | Audit Event |
Critical | Success | Yes |
SetWhitelistDisabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
SetWhitelistEnabledFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
SetWhitelistEnabledSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
UpdateIPWhitelistEntry
${actorUserEmail} updated an entry in the IP allowlist from (ip: ${oldIpCidr}, description: ${oldDescription}) to (ip: ${newIpCidr}, description: ${newDescription}).
Severity | Status | Audit Event |
Info | Success | Yes |
UpdateWhitelistFailed
Severity | Status | Audit Event |
Warning | Failure | Yes |
UpdateWhitelistSucceeded
Severity | Status | Audit Event |
Info | Success | Yes |
userlockout
AutoUnlocked
Severity | Status | Audit Event |
Info | Success | Yes |
LockedByAdmin
Severity | Status | Audit Event |
Info | Success | Yes |
LockedByBruteForce
Severity | Status | Audit Event |
Warning | Success | Yes |
LockedDueToInactivity
Severity | Status | Audit Event |
Info | Success | Yes |
LockedDueToLeakedPassword
User ${email}'s account was locked because the account is at risk of being compromised. The account credentials were found to have been compromised in another vendors security breach.
Severity | Status | Audit Event |
Warning | Success | Yes |
LockoutConfigChanged
${admin} updated the account lockout configuration, (${changedConfigs}), for the ${orgName} organization.
Severity | Status | Audit Event |
Info | Success | Yes |
UnlockedByAdmin
Severity | Status | Audit Event |
Info | Success | Yes |