Archive configuration | A user created, modified, or deleted the configuration of an archive and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:archive |
Custom metric | A user created, modified, or deleted a custom metric for logs and the previous and new values for the custom metric configuration. | @evt.name:"Log Management" @asset.type:"custom metric" |
Exclusion filter configuration | A user created, modified, or deleted the configuration of an exclusion filter and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:"exclusion filter" |
Facet | A user created, modified, or deleted a facet in the Log Explorer and the previous and new values for the facet configuration. | @evt.name:"Log Management" @asset.type:facet |
Historical view | A user created, modified, aborted, or deleted a historical view for logs and the previous and new values for the historical view configuration. | @evt.name:"Log Management" @asset.type:historical_view |
Index configuration | A user created, modified, or deleted the configuration of an index and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:index |
Log pipeline | A user created, modified, or deleted a log pipeline or nested pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline |
Processor | A user created, modified, or deleted a processor within a pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline_processor |
Query (Public Beta) | A user ran a Log Management List query either in Log Explorer, Dashboards or through the Public API. | @evt.name:"Log Management" @asset.type:logs_query |
Restriction query configuration | A user created, modified, or deleted the configuration of a restriction query in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:restriction_query |
Standard attribute configuration | A user created, modified, or deleted the configuration of a standard attribute in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:standard_attribute |
Download as CSV | A user exports list of logs as CSV | @evt.name:"Log Management" @asset.type:logs_csv |