Audit Events
This section lists the auditing events available in the Syslog Export, and the version of N-central where they were introduced :
Event Name | N-central Version (from) | Notes |
---|---|---|
Auditing User Login | 2024.3 | This entry does not include IDP or other login methods. |
User Logout | 2024.3 | |
User Create/Modify/(single) delete | 2024.3 | |
Role Create/Modify/delete | 2024.3 | |
Bulk User Deletion | 2024.3 | |
Bulk Role Deletion | 2024.3 | |
Customer delete auditing | 2024.3 |
Covers the deletion of:
|
CRUD Events for SO, Customer, Site | 2024.3 |
Covers Create, Update, Delete (CRUD) events for:
|
User Failed Login (with count) | 2024.6 | |
User Create Device (manual) | 2024.6 | |
User Create Device (not imported or “Unmanaged”) | 2024.6 | |
Adjust Device Modify Message | 2024.6 | |
User Logged In (IDP) | 2024.6 | |
User Logged Out (IDP) | 2024.6 | |
User Enabled Remote Control Option | 2024.6 | |
User Deleted Device | 2024.6 | |
User Created Device (auto import via discovery) | 2024.6 | |
User Terminated Remote control Session | 2024.6 | |
Events for User Edits | 2024.6 | |
User Enabled | 2024.6 | |
User Unlocked | 2024.6 | |
User Deleted Service Organization | 2024.6 | |
User Deleted Customer | 2024.6 | |
User Deleted Site | 2024.6 | |
User Deleted | 2024.6 | |
User Created | 2024.6 | |
User Edited | 2024.6 | |
User Access Group Assigned | 2024.6 | |
User Access Group Names Pulled from the database | 2024.6 | |
User Logout | 2024.6 | |
user Logged in with level reflected | 2024.6 | |
User Locked | 2024.6 | |
User Disabled | 2024.6 | |
User Initiated Remote Control Session | 2024.6 | |
User Disabled Remote Control Session | 2024.6 | |
Capture Reboot Events in N-central | 2024.6 | |
MFA Enabled | 2024.6 | |
MFA Disabled | 2024.6 | |
User Role is Deleted | 2024.6 | |
User Rule (Add/Clone) | 2024.6 | |
User Edit Rule | 2024.6 | |
User Delete Rule | 2024.6 |