Common Audit Log Fields
You can search and filter audit records using the following Common Audit Log fields.
Event fields
- Action
- Identifies the action performed on the target. Examples include Create, Modify, Delete, and Read. Interpret Action together with Feature, Audit Type, and Message for additional context.
- Initiation Type
- Identifies how the action was initiated, such as by an interactive user action or an automated service operation. The initiation types are:
- Manual: Indicates that the action was initiated directly by the user.
- AI Assisted: Indicates that the action was initiated or guided by an AI-assisted workflow (such as N-zo) while another service (such as an MCP server) performs the action on behalf of the user.
- Automatic: Indicates that the action was initiated automatically by a service or system process.
- Action Occurred At
- Identifies when the audited action occurred. Use this field to determine when an action occurred and establish the sequence of related events.
- Feature
- Identifies the product capability associated with the event. Use this field to narrow an investigation to activity generated by a particular area of the product, such as policy management or patching.
- Audit Type
- Identifies the category of the audited activity. Use this field to group or filter related audit records.
- Message
- Provides additional information about the event. Use this field when the structured fields do not provide enough detail to understand the action. Message content can differ by source product and event type and can be unavailable or truncated in the table.
- ID
- Identifies the audit record. Use this field to distinguish a specific record from other audit records.
- Correlation ID
- Identifies audit records created by the same or a related operation. Use this field to reconstruct an activity that generated multiple records. Filter for the same correlation ID, and then order the matching records by Action Occurred At.
User fields
- User Name
- Identifies the display name of the user or account associated with the event. Because display names might not be unique, use User ID or User Email when you need to distinguish between accounts. A service-generated event might not include a conventional user name.
- User ID
- Identifies the user or account associated with the event. Use this field to distinguish users that have similar or identical display names.
- User Email
- Identifies the email address of the user or account associated with the event. Use this field to distinguish accounts or correlate the audit record with identity and access information.
- User IP Address
- Identifies the IP address associated with the initiating activity, when available. Use this field as supporting information when investigating the source of an action. An IP address does not by itself identify a person or device because IP addresses can be shared, translated, proxied, or reassigned.
- User Organization Name
- Identifies the display name of the organization associated with the user or account that initiated the activity. Use this field to distinguish the initiator's organizational context from the organization or resource affected by the action.
- User Organization ID
- Identifies the organization associated with the initiating user or account. Use this field when organization names are duplicated or have changed.
Target fields
- Partner Name
- Identifies the display name of the partner associated with the affected target.
- Partner ID
- Identifies the partner associated with the affected target. Use this field to distinguish partners that have the same or similar display names.
- Service Organization Name
- Identifies the display name of the service organization associated with the affected target. Use this field to review events within a specific service organization.
- Service Organization ID
- Identifies the service organization associated with the affected target. Use this field to distinguish service organizations that have the same or similar display names.
- Customer Name
- Identifies the display name of the customer associated with the affected target. Use this field to filter activity for a customer, and then narrow the results by site or resource.
- Customer ID
- Identifies the customer associated with the affected target. Use this field to distinguish customers that have the same or similar display names.
- Site Name
- Identifies the display name of the site associated with the affected target. Use this field to narrow customer activity to a specific site.
- Site ID
- Identifies the site associated with the affected target. Use this field to distinguish sites that have the same or similar display names.
- Resource Name
- Identifies the display name of the resource affected by the event. A resource represents a managed object associated with the audited action. Interpret this field together with Resource Type and the applicable customer and site information.
- Resource ID
- Identifies the resource affected by the event. Use this field to distinguish resources that have the same or similar display names.
- Resource Type
- Identifies the type of resource affected by the event. Interpret this field together with Resource Name or Resource ID to determine the managed object associated with the action.
