Skip to content

AccessManagement

authz


AccountOwnershipAssigned

${userEmail} assigned account ownership to ${targetUser}.

SeverityStatusAudit Event
InfoSuccessYes

AccountOwnershipRevoked

${userEmail} revoked account ownership from ${targetUser}.

SeverityStatusAudit Event
InfoSuccessYes

AdminRequestedPasswordChange

${userName} initiated a mandatory password reset for ${userNames}.

SeverityStatusAudit Event
InfoSuccessYes

AllRolesDeassignedFromUser

${userName} removed all role assignments from the user ${targetUser}.

SeverityStatusAudit Event
InfoSuccessYes

AllRolesDeassignedFromUserGroup

${userEmail} revoked all roles from user group ${groupName}.

SeverityStatusAudit Event
InfoSuccessYes

AuthorizedUserGroupsToOrg

${userEmail} authorized user groups in organization ${orgName}: ${userGroupNames}.

SeverityStatusAudit Event
InfoSuccessYes

HideUser

${userName} updated the hidden status to ${hiddenStatus} for ${targetUserName}.

SeverityStatusAudit Event
InfoSuccessYes

OrgCreated

${userEmail} created organization ${orgName}.

SeverityStatusAudit Event
InfoSuccessYes

OrgCreationFailed

${userEmail} failed to create organization ${orgName}, Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

OrgDeleted

${userEmail} deleted organization ${orgName}.

SeverityStatusAudit Event
InfoSuccessYes

OrgDeletionFailed

${userEmail} failed to delete organization ${orgName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

OrgInviteEmailsFailedToSend

Unable to send user invite emails for organization ${orgName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

OrgUpdated

${userEmail} modified organization ${orgName}.

SeverityStatusAudit Event
InfoSuccessYes

OrgUpdateFailed

${userEmail} modified organization ${orgName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

PasswordComplexityPolicyUpdated

${userName} updated the password policy (${changedPolicies}) for the ${orgName} organization.

SeverityStatusAudit Event
InfoSuccessYes

PasswordComplexityPolicyUpdateFailed

${userName} failed to update the password policy for the ${orgName} organization.

SeverityStatusAudit Event
WarningFailureYes

RoleAssignedToUser

${userEmail} updated the assigned roles for ${principalType} ${principal} from ${previousRoles} to ${currentRoles}

SeverityStatusAudit Event
InfoSuccessYes

RoleAssignedToUserGroup

${userEmail} updated the assigned roles for SSO group ${principal} from ${previousRoles} to ${currentRoles}

SeverityStatusAudit Event
InfoSuccessYes

RoleAssignmentToUserFailed

${userEmail} failed to change role of ${targetUser} to ${role}. Reason: ${reason}

SeverityStatusAudit Event
InfoSuccessYes

RoleAssignmentToUserGroupFailed

${userEmail} failed to change role of user group ${groupName} to ${role}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

RoleCreated

${userEmail} created role ${role}.

SeverityStatusAudit Event
InfoSuccessYes

RoleCreationFailed

${userEmail} failed to create role ${role}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

RoleDeassignedFromUser

${userEmail} revoked role ${role} from user ${targetUser}.

SeverityStatusAudit Event
InfoSuccessYes

RoleDeassignedFromUserGroup

${userEmail} revoked role ${role} from user group ${groupName}.

SeverityStatusAudit Event
InfoSuccessYes

RoleDeleted

${userEmail} deleted sync ${syncStatus} role ${role}

SeverityStatusAudit Event
InfoSuccessYes

RoleDeletionFailed

${userEmail} failed to delete role ${role}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

RoleSyncUpdated

${userEmail} modified role ${origRole}${role} and  ${updatedSyncStatus} syncing for the role to CDM clusters.

SeverityStatusAudit Event
InfoSuccessYes

RoleUpdated

${userEmail} modified role ${origRole}${role}.

SeverityStatusAudit Event
InfoSuccessYes

RoleUpdateFailed

${userEmail} failed to modify role ${role}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

ServiceAccountCreated

${actorSubjectName} created service account ${targetSubjectName}.

SeverityStatusAudit Event
InfoSuccessYes

ServiceAccountCreationFailed

${actorSubjectName} failed to create service account ${targetSubjectName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

ServiceAccountDeleted

${actorSubjectName} deleted service account ${targetSubjectName}.

SeverityStatusAudit Event
InfoSuccessYes

ServiceAccountDeletionFailed

${actorSubjectName} failed to delete service account ${targetSubjectName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

ServiceAccountDeletionPreparationFailed

${actorSubjectName} tried to start a delete request on ${count} service accounts. The preparation for the deletion failed. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

ServiceAccountSecretRotated

${actorSubjectName} rotated the secret of the service account ${targetSubjectName}.

SeverityStatusAudit Event
InfoSuccessYes

ServiceAccountSecretRotationFailed

${actorSubjectName} failed to rotate the secret of the service account ${targetSubjectName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

ServiceAccountUpdated

${actorSubjectName} udpated service account ${targetSubjectName}.

SeverityStatusAudit Event
InfoSuccessYes

ServiceAccountUpdateFailed

${actorSubjectName} failed to update service account ${targetSubjectName}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

SSOUserCreated

${userName} created SSO user, ${targetUserName}.

SeverityStatusAudit Event
InfoSuccessYes

SSOUserCreationFailed

${userName} failed to create SSO user, ${targetUserName}.

SeverityStatusAudit Event
WarningFailureYes

SyncedRoleCreated

${userEmail} created role ${role} and enabled syncing for the role to CDM clusters.

SeverityStatusAudit Event
InfoSuccessYes

UpdatedUserGroupsInOrg

${userEmail} updated user groups in organization ${orgName}: ${userGroupNames}.

SeverityStatusAudit Event
InfoSuccessYes

UserChangedOtherUserPassword

${userName} changed the password for user ${targetUser}.

SeverityStatusAudit Event
InfoSuccessYes

UserChangeOtherUserPasswordFailed

${userName} failed to change the password for user ${targetUser}.

SeverityStatusAudit Event
WarningFailureYes

UserCreated

User ${userEmail} was created.

SeverityStatusAudit Event
InfoSuccessYes

UserCreationFailed

User ${userEmail} failed to create.

SeverityStatusAudit Event
WarningFailureYes

UserDeleted

${actorUserEmail} deleted user ${targetUserEmail}.

SeverityStatusAudit Event
InfoSuccessYes

UserDeletionFailed

${actorUserEmail} failed to delete user ${targetUserEmail}. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

UserDeletionPreparationFailed

${actorUserEmail} tried to start a delete request on ${count} users. The preparation for the deletion failed. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

UserGroupDeleted

${actorUserName} deleted role group mapping ${groupName}.

SeverityStatusAudit Event
InfoSuccessYes

UserGroupDeletionFailed

${actorUserName} was unable to delete role group mapping ${groupName}.

SeverityStatusAudit Event
WarningFailureYes

UserInvited

${actorUserEmail} invited user ${targetUserEmail}.

SeverityStatusAudit Event
InfoSuccessYes

classification_settings


DisabledClassificationBanner

${actorUserEmail} disabled the classification banners successfully.

SeverityStatusAudit Event
InfoSuccessYes

DisabledLoginBanner

${actorUserEmail} disabled the login classification modal successfully.

SeverityStatusAudit Event
InfoSuccessYes

EnabledClassificationBanner

${actorUserEmail} enabled the classification banners successfully.

SeverityStatusAudit Event
InfoSuccessYes

EnabledLoginBanner

${actorUserEmail} enabled the login classification modal successfully.

SeverityStatusAudit Event
InfoSuccessYes

UpdateClassificationBanner

${actorUserEmail} updated the classification banners successfully.

SeverityStatusAudit Event
InfoSuccessYes

UpdateLoginBanner

${actorUserEmail} updated the login classification modal successfully.

SeverityStatusAudit Event
InfoSuccessYes

federated_access


SetCDMInventoryDisabledSucceeded

${actorUserEmail} disabled the Display Rubrik CDM inventory in Polaris successfully.

SeverityStatusAudit Event
InfoSuccessYes

SetCDMInventoryEnabledFailed

${actorUserEmail} failed to change the Display Rubrik CDM inventory in Polaris. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

SetCDMInventoryEnabledSucceeded

${actorUserEmail} enabled the Display Rubrik CDM inventory in Polaris successfully.

SeverityStatusAudit Event
InfoSuccessYes

SetFederatedAccessDisabledSucceeded

${actorUserEmail} disabled the Rubrik CDM federated access successfully.

SeverityStatusAudit Event
InfoSuccessYes

SetFederatedAccessEnabledFailed

${actorUserEmail} failed to change the Rubrik CDM federated access. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

SetFederatedAccessEnabledSucceeded

${actorUserEmail} enabled the Rubrik CDM federated access successfully.

SeverityStatusAudit Event
InfoSuccessYes

mfa


MaxPasskeysChanged

${username} has changed the maximum allowed passkeys from ${prevValue} to ${newValue}.

SeverityStatusAudit Event
InfoSuccessYes

MfaRememberDisable

${username} disabled Rubrik Two-Step Verification to remember device.

SeverityStatusAudit Event
InfoSuccessYes

MfaRememberHoursUpdate

${username} updated Rubrik Two-Step Verification to remember device from ${initialHours} to ${hours} hours.

SeverityStatusAudit Event
InfoSuccessYes

PasskeyAdded

${username} has added ${type} passkey ${passkeyName} for MFA.

SeverityStatusAudit Event
InfoSuccessYes

PasskeyDeleted

${username} has deleted ${type} passkey ${passkeyName} for MFA.

SeverityStatusAudit Event
InfoSuccessYes

PasskeysAllowed

${username} has enabled passkeys for the account.

SeverityStatusAudit Event
InfoSuccessYes

PasskeysDisallowed

${username} has disabled passkeys for the account.

SeverityStatusAudit Event
InfoSuccessYes

PasskeyTypeAllowed

${username} has enabled ${passkeyType} passkeys for the account.

SeverityStatusAudit Event
InfoSuccessYes

PasskeyTypeDisallowed

${username} has disabled ${passkeyType} passkeys for the account.

SeverityStatusAudit Event
InfoSuccessYes

PasswordlessLoginDisabled

${username} has disabled passwordless login for the account.

SeverityStatusAudit Event
InfoSuccessYes

PasswordlessLoginEnabled

${username} has enabled passwordless login for the account.

SeverityStatusAudit Event
InfoSuccessYes

TotpGlobalEnforce

${username} set Rubrik Two-Step Verification enforced globally.

SeverityStatusAudit Event
InfoSuccessYes

TotpGlobalUnenforce

${username} set Rubrik Two-Step Verification not enforced globally.

SeverityStatusAudit Event
WarningSuccessYes

TotpLdapEnforce

${username} set Rubrik Two-Step Verification enforced on LDAP domain ${ldapName}.

SeverityStatusAudit Event
InfoSuccessYes

TotpLdapUnenforce

${username} set Rubrik Two-Step Verification not enforced on LDAP domain ${ldapName}.

SeverityStatusAudit Event
WarningSuccessYes

TotpReconfigure

${username} reconfigured Rubrik Two-Step Verification.

SeverityStatusAudit Event
InfoSuccessYes

TotpReminderDisable

${username} disabled Rubrik Two-Step Verification reminder.

SeverityStatusAudit Event
WarningSuccessYes

TotpReminderHoursUpdate

${username} updated the Rubrik Two-Step Verification reminder frequency from every ${initialHours} hours to once every ${hours} hours.

SeverityStatusAudit Event
InfoSuccessYes

TotpReset

${username} disabled Rubrik Two-Step Verification for  ${targetUsername}.

SeverityStatusAudit Event
WarningSuccessYes

TotpSetup

${username} enabled Rubrik Two-Step Verification.

SeverityStatusAudit Event
InfoSuccessYes

TotpUserLevelEnforce

${username} set Rubrik Two-Step Verification enforced for ${targetUsername}.

SeverityStatusAudit Event
InfoSuccessYes

TotpUserLevelUnenforce

${username} set Rubrik Two-Step Verification not enforced for ${targetUsername}.

SeverityStatusAudit Event
WarningSuccessYes

moat


AddIPWhitelistEntries

${actorUserEmail} added new addresses, (${newIpCidrs}), to IP allowlist.

SeverityStatusAudit Event
InfoSuccessYes

DeleteIPWhitelistEntries

${actorUserEmail} deleted addresses, (${deletedIpCidrs}), from IP allowlist.

SeverityStatusAudit Event
CriticalSuccessYes

FailedAPICallDueToIPViolation

${api_name} failed to execute as it was accessed from an  unauthorized IP address ${ip_address} for the ${user_domain} ${username}

SeverityStatusAudit Event
WarningFailureYes

SetIPWhitelistSetting

${actorUserEmail} updated IP allowlist settings to (enabled: ${newEnabled}, mode: ${newMode}).

SeverityStatusAudit Event
CriticalSuccessYes

SetWhitelistDisabledSucceeded

${actorUserEmail} disabled the IP whitelist successfully.

SeverityStatusAudit Event
InfoSuccessYes

SetWhitelistEnabledFailed

${actorUserEmail} failed to change the IP whitelist enforcement. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

SetWhitelistEnabledSucceeded

${actorUserEmail} enabled the IP whitelist successfully.

SeverityStatusAudit Event
InfoSuccessYes

UpdateIPWhitelistEntry

${actorUserEmail} updated an entry in the IP allowlist from (ip: ${oldIpCidr}, description: ${oldDescription}) to (ip: ${newIpCidr}, description: ${newDescription}).

SeverityStatusAudit Event
InfoSuccessYes

UpdateWhitelistFailed

${actorUserEmail} failed to update IP whitelist. Reason: ${reason}

SeverityStatusAudit Event
WarningFailureYes

UpdateWhitelistSucceeded

${actorUserEmail} updated IP whitelist successfully.

SeverityStatusAudit Event
InfoSuccessYes

userlockout


AutoUnlocked

User account for ${username} has been auto-unlocked.

SeverityStatusAudit Event
InfoSuccessYes

LockedByAdmin

${username} has been locked by administrator ${admin}.

SeverityStatusAudit Event
InfoSuccessYes

LockedByBruteForce

The user account for ${username} has been locked due to multiple  failed login attempts.

SeverityStatusAudit Event
WarningSuccessYes

LockedDueToInactivity

${username} has been locked due to inactivity.

SeverityStatusAudit Event
InfoSuccessYes

LockedDueToLeakedPassword

User ${email}'s account was locked because the account is at risk of being compromised.  The account credentials were found to have been compromised in another vendors security breach.

SeverityStatusAudit Event
WarningSuccessYes

LockoutConfigChanged

${admin} updated the account lockout configuration, (${changedConfigs}), for the ${orgName} organization.

SeverityStatusAudit Event
InfoSuccessYes

UnlockedByAdmin

${username} has been unlocked by administrator ${admin}.

SeverityStatusAudit Event
InfoSuccessYes

UnlockedBySupport

${username} has been unlocked by Rubrik Support.

SeverityStatusAudit Event
InfoSuccessYes