Common Audit Log Fields

You can search and filter audit records using the following Common Audit Log fields.

Event fields

Action
Identifies the action performed on the target. Examples include Create, Modify, Delete, and Read. Interpret Action together with Feature, Audit Type, and Message for additional context.
Initiation Type
Identifies how the action was initiated, such as by an interactive user action or an automated service operation. The initiation types are:
  • Manual: Indicates that the action was initiated directly by the user.
  • AI Assisted: Indicates that the action was initiated or guided by an AI-assisted workflow (such as N-zo) while another service (such as an MCP server) performs the action on behalf of the user.
  • Automatic: Indicates that the action was initiated automatically by a service or system process.
Action Occurred At
Identifies when the audited action occurred. Use this field to determine when an action occurred and establish the sequence of related events.
Feature
Identifies the product capability associated with the event. Use this field to narrow an investigation to activity generated by a particular area of the product, such as policy management or patching.
Audit Type
Identifies the category of the audited activity. Use this field to group or filter related audit records.
Message
Provides additional information about the event. Use this field when the structured fields do not provide enough detail to understand the action. Message content can differ by source product and event type and can be unavailable or truncated in the table.
ID
Identifies the audit record. Use this field to distinguish a specific record from other audit records.
Correlation ID
Identifies audit records created by the same or a related operation. Use this field to reconstruct an activity that generated multiple records. Filter for the same correlation ID, and then order the matching records by Action Occurred At.

User fields

User Name
Identifies the display name of the user or account associated with the event. Because display names might not be unique, use User ID or User Email when you need to distinguish between accounts. A service-generated event might not include a conventional user name.
User ID
Identifies the user or account associated with the event. Use this field to distinguish users that have similar or identical display names.
User Email
Identifies the email address of the user or account associated with the event. Use this field to distinguish accounts or correlate the audit record with identity and access information.
User IP Address
Identifies the IP address associated with the initiating activity, when available. Use this field as supporting information when investigating the source of an action. An IP address does not by itself identify a person or device because IP addresses can be shared, translated, proxied, or reassigned.
User Organization Name
Identifies the display name of the organization associated with the user or account that initiated the activity. Use this field to distinguish the initiator's organizational context from the organization or resource affected by the action.
User Organization ID
Identifies the organization associated with the initiating user or account. Use this field when organization names are duplicated or have changed.

Target fields

Partner Name
Identifies the display name of the partner associated with the affected target.
Partner ID
Identifies the partner associated with the affected target. Use this field to distinguish partners that have the same or similar display names.
Service Organization Name
Identifies the display name of the service organization associated with the affected target. Use this field to review events within a specific service organization.
Service Organization ID
Identifies the service organization associated with the affected target. Use this field to distinguish service organizations that have the same or similar display names.
Customer Name
Identifies the display name of the customer associated with the affected target. Use this field to filter activity for a customer, and then narrow the results by site or resource.
Customer ID
Identifies the customer associated with the affected target. Use this field to distinguish customers that have the same or similar display names.
Site Name
Identifies the display name of the site associated with the affected target. Use this field to narrow customer activity to a specific site.
Site ID
Identifies the site associated with the affected target. Use this field to distinguish sites that have the same or similar display names.
Resource Name
Identifies the display name of the resource affected by the event. A resource represents a managed object associated with the audited action. Interpret this field together with Resource Type and the applicable customer and site information.
Resource ID
Identifies the resource affected by the event. Use this field to distinguish resources that have the same or similar display names.
Resource Type
Identifies the type of resource affected by the event. Interpret this field together with Resource Name or Resource ID to determine the managed object associated with the action.