AccessManagement
authz
AccountOwnershipAssigned
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
AccountOwnershipRevoked
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
AdminRequestedPasswordChange
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
AllRolesDeassignedFromUser
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
AllRolesDeassignedFromUserGroup
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
AuthorizedUserGroupsToOrg
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
HideUser
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
OrgCreated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
OrgCreationFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
OrgDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
OrgDeletionFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
OrgInviteEmailsFailedToSend
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
OrgUpdated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
OrgUpdateFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
PasswordComplexityPolicyUpdated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasswordComplexityPolicyUpdateFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
RoleAssignedToUser
${userEmail} updated the assigned roles for ${principalType} ${principal} from ${previousRoles} to ${currentRoles}
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleAssignedToUserGroup
${userEmail} updated the assigned roles for SSO group ${principal} from ${previousRoles} to ${currentRoles}
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleAssignmentToUserFailed
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleAssignmentToUserGroupFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
RoleCreationFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
RoleDeassignedFromUser
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleDeassignedFromUserGroup
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleDeletionFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
RoleSyncUpdated
${userEmail} modified role ${origRole}${role} and ${updatedSyncStatus} syncing for the role to CDM clusters.
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleUpdated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
RoleUpdateFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
ServiceAccountCreated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
ServiceAccountCreationFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
ServiceAccountDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
ServiceAccountDeletionFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
ServiceAccountDeletionPreparationFailed
${actorSubjectName} tried to start a delete request on ${count} service accounts. The preparation for the deletion failed. Reason: ${reason}
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
ServiceAccountSecretRotated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
ServiceAccountSecretRotationFailed
${actorSubjectName} failed to rotate the secret of the service account ${targetSubjectName}. Reason: ${reason}
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
ServiceAccountUpdated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
ServiceAccountUpdateFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SSOUserCreated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
SSOUserCreationFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SyncedRoleCreated
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UpdatedUserGroupsInOrg
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UserChangedOtherUserPassword
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UserChangeOtherUserPasswordFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UserCreationFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UserDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UserDeletionFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UserDeletionPreparationFailed
${actorUserEmail} tried to start a delete request on ${count} users. The preparation for the deletion failed. Reason: ${reason}
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UserGroupDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UserGroupDeletionFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UserInvited
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
classification_settings
DisabledClassificationBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
DisabledLoginBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
EnabledClassificationBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
EnabledLoginBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UpdateClassificationBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UpdateLoginBanner
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
federated_access
SetCDMInventoryDisabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
SetCDMInventoryEnabledFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SetCDMInventoryEnabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
SetFederatedAccessDisabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
SetFederatedAccessEnabledFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SetFederatedAccessEnabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
mfa
MaxPasskeysChanged
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
MfaRememberDisable
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
MfaRememberHoursUpdate
${username} updated Rubrik Two-Step Verification to remember device from ${initialHours} to ${hours} hours.
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeyAdded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeyDeleted
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeysAllowed
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeysDisallowed
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeyTypeAllowed
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasskeyTypeDisallowed
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasswordlessLoginDisabled
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
PasswordlessLoginEnabled
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpGlobalEnforce
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpGlobalUnenforce
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
TotpLdapEnforce
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpLdapUnenforce
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
TotpReconfigure
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpReminderDisable
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
TotpReminderHoursUpdate
${username} updated the Rubrik Two-Step Verification reminder frequency from every ${initialHours} hours to once every ${hours} hours.
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpReset
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
TotpSetup
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpUserLevelEnforce
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
TotpUserLevelUnenforce
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
moat
AddIPWhitelistEntries
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
DeleteIPWhitelistEntries
| Severity | Status | Audit Event |
|---|---|---|
| Critical | Success | Yes |
FailedAPICallDueToIPViolation
${api_name} failed to execute as it was accessed from an unauthorized IP address ${ip_address} for the ${user_domain} ${username}
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SetIPWhitelistSetting
| Severity | Status | Audit Event |
|---|---|---|
| Critical | Success | Yes |
SetWhitelistDisabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
SetWhitelistEnabledFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
SetWhitelistEnabledSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UpdateIPWhitelistEntry
${actorUserEmail} updated an entry in the IP allowlist from (ip: ${oldIpCidr}, description: ${oldDescription}) to (ip: ${newIpCidr}, description: ${newDescription}).
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UpdateWhitelistFailed
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Failure | Yes |
UpdateWhitelistSucceeded
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
userlockout
AutoUnlocked
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
LockedByAdmin
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
LockedByBruteForce
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
LockedDueToInactivity
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
LockedDueToLeakedPassword
User ${email}'s account was locked because the account is at risk of being compromised. The account credentials were found to have been compromised in another vendors security breach.
| Severity | Status | Audit Event |
|---|---|---|
| Warning | Success | Yes |
LockoutConfigChanged
${admin} updated the account lockout configuration, (${changedConfigs}), for the ${orgName} organization.
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |
UnlockedByAdmin
| Severity | Status | Audit Event |
|---|---|---|
| Info | Success | Yes |