Audit Log Events for Tenant and Identity Management
Review the administrative operations and system events that generate audit log
records for tenant and identity management.
records audit log events for administrative and system
operations performed in your tenants. You can use these audit log events to monitor
configuration changes, track access grants and revocations, review tenant lifecycle
events, and investigate authentication activity. Each event captures whether the
operation succeeded or failed, along with contextual details such as the affected
tenant, user, or resource.
Key Audit Log Fields
The following fields are most useful when querying or analyzing audit log events
related to tenant and identity management in Strata Cloud Manager. For field names
and descriptions in HTTPS CEF, EMAIL, and LEEF formats, see the
Audit Log Field Reference.
event_name, event_description,
event_detail, event_result,
event_source_user_email,
event_source_user_first_name,
event_source_user_last_name,
event_client_ip.value, actor_id,
actor_display_name, tsg_id,
event_time, sub_type.value,
event_category, event_sub_category,
vendor_severity.value.
The event description in the following tables correspond to the values in the
event_description field in the log viewer. You can create log
queries based on the event_description values to filter for
specific operations. The event_result field captures whether each
operation succeeded or failed.
Service Account Management
These events are generated when you create, update, delete, or reset the password of
a service account within a tenant.
| Event Description | Description |
| Create Service Account | Indicates that a service account was created in a tenant. The log
record identifies the service account name and the tenant service
group (TSG) where the account was created. |
| Update Service Account | Indicates that the configuration of an existing service account
was modified in a tenant. The log record identifies the service
account name and the TSG where the update occurred. |
| Delete Service Account | Indicates that a service account was deleted from a tenant. The
log record identifies the service account name and the TSG from
which the account was removed. |
| Reset Service Account Password | Indicates that the password for a service account was reset. The
log record identifies the service account whose credentials were
changed. |
Access Management
These events are generated when you grant or remove role-based access for a user
within a tenant.
| Event Description | Description |
| Grant Access | Indicates that a user was granted a specific role in a tenant.
The log record identifies the user, the role that was assigned, and
the TSG where access was granted. |
| Remove Access | Indicates that a role was revoked from a user in a tenant. The
log record identifies the user, the role that was removed, and the
TSG from which access was revoked. |
Custom Role Management
These events are generated when you create, update, or delete a custom role within a
tenant.
| Event Description | Description |
| Create Custom Role | Indicates that a custom role was created in a tenant. The log
record identifies the custom role name and the TSG where the role
was created. |
| Update Custom Role | Indicates that the permissions or configuration of an existing
custom role were modified in a tenant. The log record identifies the
custom role name and the TSG where the update occurred. |
| Delete Custom Role | Indicates that a custom role was deleted from a tenant. The log
record identifies the custom role name and the TSG from which the
role was removed. |
Tenant Management
These events are generated when you create, update, or delete a tenant, or when you
update or delete the IP restriction policy for a tenant.
| Event Description | Description |
| Create Tenant | Indicates that a new tenant was created. The log record
identifies the TSG of the newly created tenant. |
| Update Tenant | Indicates that the configuration of an existing tenant was
modified. The log record identifies the TSG of the updated
tenant. |
| Delete Tenant | Indicates that a tenant was deleted. The log record identifies
the TSG of the removed tenant. |
| Update Tenant IP Restriction Policy | Indicates that the IP restriction policy for a tenant was
updated. The log record identifies the TSG whose IP restriction
policy was modified. |
| Delete Tenant IP Restriction Policy | Indicates that the IP restriction policy for a tenant was
deleted. The log record identifies the TSG whose IP restriction
policy was removed. |
Tenant Acquisitions
These events are generated during the tenant service group (TSG) acquisition
lifecycle when a TSG acquisition is created, deleted, acknowledged, or when a TSG is
moved between parent TSGs.
| Event Description | Description |
| Acquisition of TSG created | Indicates that an acquisition request was initiated for a target
TSG. The log record identifies the TSG being acquired. |
| Acquisition of TSG deleted | Indicates that a pending acquisition request was deleted. The log
record identifies the target TSG and the acquisition request
identifier. |
| Acquisition of TSG acknowledged | Indicates that a TSG acquisition was acknowledged by the target
tenant. The log record identifies the acquired TSG and the
acquisition request identifier. |
| TSG moved | Indicates that a TSG was moved from one parent TSG to another.
The log record identifies the TSG that was moved, the source parent
TSG, and the destination parent TSG. |
Licensing and Device Management
These events are generated when you activate product licenses, or when you add
devices to, remove devices from, or associate devices with a tenant. You can also
use these events to track changes to tenant-to-deployment-profile
associations.
| Event Description | Description |
| Product license activation | Indicates that a license activation was initiated for a tenant.
Check the tenant management page for the activation status. |
| Add devices to tenant | Indicates that one or more devices were added to a
tenant. |
| Associate devices | Indicates that a device association was initiated for one or more
devices in a tenant. |
| Manage tenant to deployment profile association | Indicates that the association between a tenant and a deployment
profile was updated. |
| Remove devices from tenant | Indicates that one or more devices were removed from a
tenant. |
| Remove device association | Indicates that a device disassociation was initiated, removing
the application association for one or more devices. |
Authentication
These events are generated when a user successfully logs in to or logs out of a
tenant service group.
does not record authentication failures as audit log
events.
| Event Description | Description |
| Authorized User | Indicates that a user successfully logged in to a tenant service
group. The log record identifies the TSG that the user
accessed. |
| Logout Successful | Indicates that a user successfully logged out of a tenant service
group. |