Audit Log Record Categorization

The following values are used in the Section and Action Type columns of the Audit log. The Notes column describes the action completed by the user listed in the User column.

SectionAction TypeNotes
action_profilesindexA user browsed to the MITRE ATT&CK Dashboard
actionsapproveAn Action was approved
actionscreateAn Action was created
actionscreate_sleep_actionA sleep Action (in Action Queue) was created
actionsdestroyAn Action was deleted
actionsrunA Job was run
actionsrun_queueActions from the queue were run
actionsupdate_sectech_logoThe logo on a Security Technology was updated
alert_formatscreateA Monitor Notification Format was created
alert_profilescreateA Monitor Notification Profile was created
analyzegauge_pageUser browsed to the Gauges
analyzeheat_mapUser browsed to the Heat Map
bulk_jobscreate_bulk_jobA bulk Job was created
email_profilescreateAn Email Profile was created
endpoint_filescreateA file was added to the Endpoint Library
endpoint_filesdownloadA file was download from the Endpoint Library
endpoint_productsupdateAn Endpoint Security Technology was updated
event_filter_rulescreateCreating an Event Filter Rule
event_filter_rulesdestroyDeleting an Event Filter Rule
event_filter_rulesupdateUpdating an Event Filter Rule
file_transfer_librariescreateA File was created
file_transfer_librariescreate_actionAn Action was created from a File
file_transfer_librariescreate_protected_actionA Protected Action was created from a File
file_transfer_librariesupdateA File was updated
integration_settingsupdateAn Integration was updated
integrationscreateAn Integration was added
integrationsrun_testAn Integration's test was run
integrationsupdateAn Integration was updated
job_actionsupdateThe include/excude from reports setting on a Job Action was updated
jobscancelA Job was canceled
jobsclear_queue_allThe Job Queue was cleared
jobsdestroyA Job was deleted
jobsrun_again_modalA Job was run using the Run Again option
jobsrun_nowA Job was created and is running
jobsshowA user viewed a Job
licenseverify_licenseThe License info was reviewed to verify it was still valid
messagesdestroyA Flash card from a User's Messages was deleted
monitorupdate_dataA Monitor was updated
monitor_defsv2_updateA Monitor was updated
network_devicesupdateA Network Security Technology was updated
nodesconnect_resultAn Actor was registered
nodescreateAn Actor was added
nodesdestroyAn Actor was removed
nodesdestroy_bulk_tokenA Bulk Registration token was deleted
nodesdestroy_pendingA Pending Actor token was deleted
nodesupdateAn Actor was updated
panel_dashboardsupdateA panel on the TAAM Dashboard was updated
registrationsupdateA User's password was changed
report_buildercreateA report in Report Builder was created
report_builderdestroyA report in Report Builder was deleted
report_builderupdateA report in Report Builder was updated
reportsdata_exfilA user viewed the Data Exfil Report
reportsmalicious_transferA user viewed the Malicious File Transfer Report
reportssummaryA user viewed the Summary Report
scheduled_actionscancelA scheduled Job Action was deleted
scheduled_actionsupdateA scheduled Job Action was updated
security_technologiesrun_discoveryThe "Discover Devices" option on a Job was run
security_zonescreateA Security Zone was created
security_zonesupdateA Security Zone was updated
sessionscreateA session (process run by the Director) for a user was started
sessionsdestroyA session (process run by the Director) for a user ended
sessionsloginA user logged into the Director
sessionslogin_failureA user entered the incorrect password
sessionslogoutA user logged out of the Director
settingsadvanced_updateThe Advanced Setting were updated, including changing the Event Filter type for integration event filter rules
settingscheck_updateThe Update Service was checked to see if there was a new update
settingscontent_import

Content was imported

settingscreate_backupA Backup was created
settingscreate_operational_notificationAn Operational Status Notification was created
settingscreate_update_dim_ruleA pass/fail rule for a specific Dimension was created
settingscreate_update_vid_ruleA pass/fail rule for a specific VID was created
settingsdestroy_operational_notificationAn Operation Status Notification was deleted
settingsdownload_updateAn update from the Update Service was downloaded
settingsimport_content_applyImported Content was applied
settingslogin_updateLogin Requirements were updated
settingsoperational_status_updateAn Operation Status Notifcation was updated
settingsrun_updateA Director update was applied
settingssslAn SSL certificate was added
settingsupdate_service_runningThe system checked to see if an update is running (automated check during the update process)
settingsupdate_statusA System Update status was updated
settingsverify_licenseThe License info was reviewed to verify it was still valid
settingsverify_updateAn update patch was Uploaded & check to see if it was valid
simulationscreateA Sequence or Evaluation was created
simulationsdestroyA Sequence or Evaluation was deleted
simulationsrun_all_contentRun All Actions from the Evaluation Library was used
simulationsupdateA Sequence or Evaluation was updated
template_actionscreateAn Action from a File Template was created
template_actionsupdateAn Action based on a File Template was updated
templatescreateA File Template was created
templatesupdateA File Template was updated
threat_actor_referencescreateA Threat Actor (manual and when Integration syncs) was created
threat_actor_referencesupdateA Threat Actor (manual and when Integration syncs) was updated
threat_intel_integrationscreateA TIP Integration was added
threat_intel_integrationsupdateA TIP Integration was updated
topologycheck_time_syncThe Actor's time sync (with the Director) was checked
topologypull_info_nodeRefresh Actor Info was clicked and the Actor's info was updated
topologypull_talk_info_nodeAn Actor's CTTA info was updated
uploadcancela PCAP upload during Action creation was canceled
uploadcreate_pcap_actionA PCAP Action (by uploading a PCAP) was created
uploaddestroy_allAll in-progress PCAP Actions were deleted (uploading a new PCAP during the Action creation process)
uploaddestroy_conversationsWhile creating a PCAP Action, conversations from a PCAP file were deleted
userscreateA user was added to the Director
usersdestroyA user's access was disabled or the user account was deleted
usersenable_userA user's access was enabled
usersupdateA user was updated
usersuser_prefs_updateA user updated their preferences
  • June 5, 2022
  • May 1, 2026
In This Article