View Administrator Activity for SSPM
Focus
Focus
SaaS Security

View Administrator Activity for SSPM

Table of Contents

View Administrator Activity for SSPM

Learn how to monitor SSPM administrator activity by viewing activity logs.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • SaaS Security Posture Management license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
SaaS Security captures actions performed by administrators and records them in an activity log. From the Activity Log page, you can view this record of administrator actions. You can view recorded activity for all administrators or for a specific administrator. SaaS Security logs information for the following categories of SSPM events.
  • Application
    SaaS Security logs event information when an administrator establishes the initial connection between SSPM and a SaaS application. SaaS Security also logs events when an administrator modifies application configurations or deletes a connection. For example, events are logged when an administrator completes the following actions:
    • Onboards a SaaS application instance, which authenticates SSPM to the SaaS application to establish the initial connection for scanning. Events are subsequently logged if SSPM re-authenticates to the SaaS application.
    • Updates a SaaS application in SSPM, such as changing its display name in SSPM, modifying the configuration scan interval, or changing the application owner.
    • Assigns an application tag to, or removes an application tag from, a SaaS application in SSPM. Application tags help you distinguish between different types of environments (such as development and production environments) on the Applications page.
    • Deletes a SaaS application from SSPM.
  • Policy
    SaaS Security logs event information when an administrator creates, updates, or manages policies within SSPM. This logging includes actions on both policy types: Application Settings Policies and Plugin Access Control Policies. For example, events are logged when an administrator completes the following actions:
    • Creates a new policy.
    • Updates policy fields, such as the policy name, actions, or associated applications.
    • Enables or disables an individual policy, or multiple policies simultaneously.
    • Deletes an existing policy.
  • Report Downloads
    SaaS Security logs event information when an administrator downloads compliance, rule, or configuration data from SSPM as a CSV-formatted report. For example, events are logged when an administrator generates and downloads reports for the following items:
  • Configuration Settings
    SaaS Security logs event information when an administrator modifies a configuration setting for a managed application instance. For example, events are logged when an administrator completes the following actions for a setting. These controls are available on the settings flyout dialog when you view an application setting.
    • Enables or disables configuration monitoring of the setting.
    • Toggles the security configuration lock for the setting.
    • Overrides the suggested value for a configuration setting.
  • Third-Party Plugins
    SaaS Security logs event information when an administrator manages or reviews third-party plugins and their access permissions. For example, events are logged when an administrator completes the following actions:
    • Revokes access permissions for a third-party plugin.
    • Updates the review status of one or more third-party plugins.
  • Ticketing
    SaaS Security logs event information when an administrator creates a ticket in an issue tracking system from within SSPM. For example, events are logged when an administrator completes the following actions:
    • Creates a Jira or ServiceNow ticket for a misconfigured application setting.
    • Creates a Jira or ServiceNow ticket for a third-party plugin.
To view administrator activity for SSPM on the Activity Logs page, complete the following steps.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationSaaS SecuritySettingsMonitor actions taken by SaaS Security administrators.
    The Activity Logs page displays logged SSPM activity for all administrators. The Activity Logs page also shows information for Data Security.
  3. (Optional) Filter the Activity Logs table to focus on the information you're interested in.
    • Use the Search by user email field to filter the Activity Logs table to view logged activity for a single administrator.
    • Use the Duration list to filter the Activity Logs table for a specific time frame.
    • Use the Events list to filter the table by event types. You can filter based on the values shown in the Event column of the table.