Common Audit Log (New)

The Common Audit Log provides a centralized view of audit activity across supported N-able products and platform services. Use the Common Audit Log to investigate administrative actions, identify changes to managed resources, review user activity, and collect evidence for security and compliance reviews.

Currently, the Common Audit Log (CAL) contains audit events from Ecoverse only. Over time, it will include audit events from additional N-able products.

An audit record is an immutable, time-stamped record of a critical event. Audit records combine information about the event, the user or process that initiated it, and the customer, site, or resource affected by it. Audit records support forensic investigation and regulatory evidence by maintaining a verifiable history of user, system, and resource activity.

The Common Audit Log provides a consistent format, query interface, and retention approach for audit records generated by supported N-able products and services.

The Common Audit Log supports investigations and evidence gathering. It does not determine whether an action was appropriate, malicious, or compliant. Interpret audit activity in the context of your organization’s security policies and operational procedures.

The Common Audit Log also delivers audit events to supported external security platforms such as SIEM or MDR platforms for anomaly or threat detection and compliance or regulatory purposes. The Common Audit Log currently supports event streaming to Adlumin. Use Adlumin when you need to combine N-able audit events with other security telemetry for centralized monitoring, investigation, or threat detection.

Delivery to Adlumin does not change the source audit record in the Common Audit Log.

Identify what happened in your environment

Use the Common Audit Log to answer questions such as:

  • Who performed an action?
  • When did the action occur?
  • Was the action initiated by a user or an automated process?
  • Which customer, site, or resource was affected?
  • Which product feature generated the event?
  • Are several audit records associated with the same operation?

For example, you can use the Common Audit Log to determine who modified a policy, identify the devices affected by an administrative action, or trace a sequence of related events.

How Common Audit Log helps

The Common Audit Log helps you:

  • Review activity from multiple N-able products in a single location.
  • Investigate configuration changes and user actions.
  • Search and filter large numbers of audit records.
  • Support compliance, governance, and security investigations through a verifiable historical chain of events.
  • Stream audit events to external platforms such as SIEM and MDR solutions. Currently, the system supports event streaming to Adlumin.

Common Audit Log availability

Common Audit Log is available at the Service Organization level.

The Common Audit Log is intended to provide a consistent location for audit data from supported N-able products and platform services. The available events can differ by the product and service.

Permissions

Access to Common Audit Log is controlled by the permissions configured in the source platform. N-sight users must have the audit report permission; users with this permission can view all available audit records. Common Audit Log checks the user’s permissions and returns only the records the user is entitled to access.

By default, administrators have access to view audit logs. To provide access to another user, configure the applicable permission under User Management For details, see User Management.

Audit records are maintained for 90 days.

What Common Audit Log records

The Common Audit Log can contain records for:

  • User access and authentication activity
  • Administrative and configuration changes
  • Scheduled operations
  • Automated actions performed against customer assets
  • Actions from N-zo

An action can be initiated directly by a user or indirectly by an automated process. For example, a user might modify a policy configuration or initiate a vulnerability scan. A scheduled task or policy enforcement such as patch deployment can also generate an audit event without a direct interactive action at the time the event occurs.

The specific events available depend on the product or service.

How Common Audit Log organizes activity

Common Audit Log groups audit information into three main areas:

  • Event: Describes what occurred, when it occurred, how it was initiated, and which product feature generated the record.
  • User: Identifies the user, service, or organizational context associated with the action.
  • Target: Identifies the partner, service organization, customer, site, or resource affected by the action.

Identifiers and correlation information can help distinguish objects with similar names and connect records created as part of the same operation.

Audit event lifecycle

The lifecycle of an audit event includes:

  • Generation: A supported product or service creates an event after an auditable action.
  • Ingestion: Common Audit Log receives the event.
  • Processing: The service associates the event with event, user, target, and organizational information.
  • Storage: The event is stored as an immutable audit record.
  • Retrieval: An authorized user searches for or reviews the record.
  • External delivery: If configured and supported, the event is delivered to Adlumin.
  • Retention: The record remains available for the applicable retention period.
  • Deletion: The record is removed according to the applicable retention and deletion policies.

Common Audit Log security and data integrity

Common Audit Log protects audit data through immutable records, permission-aware access, secure storage, and protected transmission. These controls support investigation, governance, and compliance evidence requirements.

  • Immutable audit records: An immutable audit record cannot be changed after it has been stored. Immutability helps preserve the integrity of the historical record. For example, an administrator cannot change a product configuration to rewrite the original audit record with the revised action.Additionally, an audit record is separate from the operational object it describes. For example, if a resource is renamed or deleted, the change to the operational resource does not rewrite the original audit record.
  • Secure audit data: Audit data can contain user, organization, network, and resource information, which is security-sensitive data. Common Audit Log protects audit data by controlling:
    • Which users can access records
    • Which organizational records a user can view
    • How records are stored
    • How records are transmitted
    • Which systems can receive audit data
  • Permission-aware record access: Common Audit Log uses role and permission controls to restrict access to audit information. A user must have the required permission to open the Common Audit Log. The records displayed must also fall within the user’s permitted organizational or resource scope.

    Permissions for the following capabilities might be separate:

    • View audit records
    • Manage audit permissions
    • Configure external event delivery