Audit Logging in SaaS Security Inline
Focus
Focus
SaaS Security

Audit Logging in SaaS Security Inline

Table of Contents

Audit Logging in SaaS Security Inline

Learn about audit logging in SaaS Security Inline.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • SaaS Security Inline license
  • NGFW or Prisma Access license
Or any of the following licenses that include the SaaS Security Inline license:
  • CASB-X
  • CASB-PA
SaaS Security Inline captures administrative actions and records them in audit logs so you can track changes, maintain accountability, and meet compliance requirements. Audit events from SaaS Security Inline are published to the central audit logs on Strata Cloud Manager, where you can view them alongside audit events from other services managed by Strata Cloud Manager.
Only state-changing operations are logged. Read-only operations such as viewing dashboards, searching applications, and retrieving metadata are not captured in audit logs. The following categories of administrative actions are logged:
  • Policy Management: Creating, updating, deleting, and enabling or disabling security rules, and downloading policy data.
  • Application Management: Updating the sanctioned status of discovered applications, and updating or resetting application risk scores.
  • Tag Management: Creating, updating, and deleting custom tags, and applying or removing tags from applications.
  • Application Instances: Updating the sanctioned status or instance type of application instances, and downloading instance data.
  • Reports: Generating and deleting reports.
  • Risk Configuration: Updating custom risk score weights, and resetting weights to defaults.
  • Data Export: Downloading discovered users or discovered applications as CSV files.
Each audit log entry captures who performed the action, what the action was, and when the action occurred.

View Audit Logs

You can view SaaS Security Inline audit logs from the central audit logs on Strata Cloud Manager
  1. Select Strata Cloud ManagerLog ViewerCommonAudit.
  2. Apply a time filter to narrow down the results.
  3. Filter for the log source to display only SaaS Security Inline events.
  4. Click any log record to view details about who performed the action, what the action was, and when it occurred.