Audit Log Events for Tenant and Identity Management
Focus
Focus
Strata Logging Service

Audit Log Events for Tenant and Identity Management

Table of Contents

Audit Log Events for Tenant and Identity Management

Review the administrative operations and system events that generate audit log records for tenant and identity management.
records audit log events for administrative and system operations performed in your tenants. You can use these audit log events to monitor configuration changes, track access grants and revocations, review tenant lifecycle events, and investigate authentication activity. Each event captures whether the operation succeeded or failed, along with contextual details such as the affected tenant, user, or resource.

Key Audit Log Fields

The following fields are most useful when querying or analyzing audit log events related to tenant and identity management in Strata Cloud Manager. For field names and descriptions in HTTPS CEF, EMAIL, and LEEF formats, see the Audit Log Field Reference.
event_name, event_description, event_detail, event_result, event_source_user_email, event_source_user_first_name, event_source_user_last_name, event_client_ip.value, actor_id, actor_display_name, tsg_id, event_time, sub_type.value, event_category, event_sub_category, vendor_severity.value.
The event description in the following tables correspond to the values in the event_description field in the log viewer. You can create log queries based on the event_description values to filter for specific operations. The event_result field captures whether each operation succeeded or failed.

Service Account Management

These events are generated when you create, update, delete, or reset the password of a service account within a tenant.
Event DescriptionDescription
Create Service AccountIndicates that a service account was created in a tenant. The log record identifies the service account name and the tenant service group (TSG) where the account was created.
Update Service AccountIndicates that the configuration of an existing service account was modified in a tenant. The log record identifies the service account name and the TSG where the update occurred.
Delete Service AccountIndicates that a service account was deleted from a tenant. The log record identifies the service account name and the TSG from which the account was removed.
Reset Service Account PasswordIndicates that the password for a service account was reset. The log record identifies the service account whose credentials were changed.

Access Management

These events are generated when you grant or remove role-based access for a user within a tenant.
Event DescriptionDescription
Grant AccessIndicates that a user was granted a specific role in a tenant. The log record identifies the user, the role that was assigned, and the TSG where access was granted.
Remove AccessIndicates that a role was revoked from a user in a tenant. The log record identifies the user, the role that was removed, and the TSG from which access was revoked.

Custom Role Management

These events are generated when you create, update, or delete a custom role within a tenant.
Event DescriptionDescription
Create Custom RoleIndicates that a custom role was created in a tenant. The log record identifies the custom role name and the TSG where the role was created.
Update Custom RoleIndicates that the permissions or configuration of an existing custom role were modified in a tenant. The log record identifies the custom role name and the TSG where the update occurred.
Delete Custom RoleIndicates that a custom role was deleted from a tenant. The log record identifies the custom role name and the TSG from which the role was removed.

Tenant Management

These events are generated when you create, update, or delete a tenant, or when you update or delete the IP restriction policy for a tenant.
Event DescriptionDescription
Create TenantIndicates that a new tenant was created. The log record identifies the TSG of the newly created tenant.
Update TenantIndicates that the configuration of an existing tenant was modified. The log record identifies the TSG of the updated tenant.
Delete TenantIndicates that a tenant was deleted. The log record identifies the TSG of the removed tenant.
Update Tenant IP Restriction PolicyIndicates that the IP restriction policy for a tenant was updated. The log record identifies the TSG whose IP restriction policy was modified.
Delete Tenant IP Restriction PolicyIndicates that the IP restriction policy for a tenant was deleted. The log record identifies the TSG whose IP restriction policy was removed.

Tenant Acquisitions

These events are generated during the tenant service group (TSG) acquisition lifecycle when a TSG acquisition is created, deleted, acknowledged, or when a TSG is moved between parent TSGs.
Event DescriptionDescription
Acquisition of TSG createdIndicates that an acquisition request was initiated for a target TSG. The log record identifies the TSG being acquired.
Acquisition of TSG deletedIndicates that a pending acquisition request was deleted. The log record identifies the target TSG and the acquisition request identifier.
Acquisition of TSG acknowledgedIndicates that a TSG acquisition was acknowledged by the target tenant. The log record identifies the acquired TSG and the acquisition request identifier.
TSG movedIndicates that a TSG was moved from one parent TSG to another. The log record identifies the TSG that was moved, the source parent TSG, and the destination parent TSG.

Licensing and Device Management

These events are generated when you activate product licenses, or when you add devices to, remove devices from, or associate devices with a tenant. You can also use these events to track changes to tenant-to-deployment-profile associations.
Event DescriptionDescription
Product license activationIndicates that a license activation was initiated for a tenant. Check the tenant management page for the activation status.
Add devices to tenantIndicates that one or more devices were added to a tenant.
Associate devicesIndicates that a device association was initiated for one or more devices in a tenant.
Manage tenant to deployment profile associationIndicates that the association between a tenant and a deployment profile was updated.
Remove devices from tenantIndicates that one or more devices were removed from a tenant.
Remove device associationIndicates that a device disassociation was initiated, removing the application association for one or more devices.

Authentication

These events are generated when a user successfully logs in to or logs out of a tenant service group.
does not record authentication failures as audit log events.
Event DescriptionDescription
Authorized UserIndicates that a user successfully logged in to a tenant service group. The log record identifies the TSG that the user accessed.
Logout SuccessfulIndicates that a user successfully logged out of a tenant service group.