Learn how to monitor SSPM administrator activity by viewing activity
logs.
| Where Can I Use This? | What Do I Need? |
|
|
- SaaS Security Posture Management license
Or any of the following licenses that include the Data Security license:
|
SaaS Security captures actions performed by administrators and records them
in an activity log. From the Activity Log page, you can view this record of
administrator actions. You can view recorded activity for all administrators or for
a specific administrator. SaaS Security logs information for the following
categories of SSPM events.
Application
SaaS Security logs event information when an administrator
establishes the initial connection between SSPM and a SaaS application. SaaS Security also logs events when an administrator modifies
application configurations or deletes a connection. For example, events are
logged when an administrator completes the following actions:
- Onboards a SaaS application
instance, which authenticates SSPM to the SaaS application to
establish the initial connection for scanning. Events are subsequently
logged if SSPM re-authenticates to the SaaS application.
- Updates a SaaS application in SSPM, such as changing its display name in
SSPM, modifying the configuration scan interval, or changing the
application owner.
- Assigns an application tag to, or removes an application tag from, a
SaaS application in SSPM. Application tags help you distinguish between
different types of environments (such as development and production
environments) on the Applications page.
- Deletes a SaaS application
from SSPM.
Policy
SaaS Security logs event information when an administrator creates,
updates, or manages policies within SSPM. This logging includes actions on
both policy types:
Application Settings Policies and
Plugin Access Control Policies.
For example, events are logged when an administrator completes the following
actions:
- Creates a new policy.
- Updates policy fields, such as the policy name, actions, or associated
applications.
- Enables or disables an individual policy, or multiple policies
simultaneously.
- Deletes an existing policy.
Report Downloads
SaaS Security logs event information when an administrator
downloads compliance, rule, or configuration data from SSPM as a
CSV-formatted report. For example, events are logged when an administrator
generates and downloads reports for the following items:
Configuration Settings
SaaS Security logs event information when an administrator modifies
a configuration setting for a managed application instance. For example,
events are logged when an administrator completes the following actions for
a setting. These controls are available on the settings flyout dialog when
you
view an application setting.
- Enables or disables configuration monitoring of the setting.
- Toggles the security configuration lock for the setting.
- Overrides the suggested value for a configuration setting.
Third-Party Plugins
SaaS Security logs event information when an administrator
manages or reviews third-party
plugins and their access permissions. For example, events are
logged when an administrator completes the following actions:
- Revokes access permissions for a third-party plugin.
- Updates the review status of one or more third-party plugins.
Ticketing
- Creates a Jira or ServiceNow ticket for a misconfigured application
setting.
- Creates a Jira or ServiceNow ticket for a third-party plugin.
To view administrator activity for SSPM on the Activity Logs page, complete the
following steps.