Archive configuration | A user created, modified, or deleted the configuration of an archive and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:archive |
Archiving order modified | A user modified the order of archives. | @evt.name:"Log Management" @action:modified @asset.type:archive_list |
Custom metric | A user created, modified, or deleted a custom metric for logs and the previous and new values for the custom metric configuration. | @evt.name:"Log Management" @asset.type:"custom metric" |
Exclusion filter configuration | A user created, modified, or deleted the configuration of an exclusion filter and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:"exclusion filter" |
Index configuration | A user created, modified, or deleted the configuration of an index and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:index |
Index order modified | A user modified the order of indexes. | @evt.name:"Log Management" @action:modified @asset.type:index_list |
Log pipeline | A user created, modified, or deleted a log pipeline or nested pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline |
Processor | A user created, modified, or deleted a processor within a pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline_processor |
Facet | A user created, modified, or deleted a facet in the Log Explorer and the previous and new values for the facet configuration. | @evt.name:"Log Management" @asset.type:facet |
Standard attribute configuration | A user created, modified, or deleted the configuration of a standard attribute in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:standard_attribute |
Query (Public Beta) | A user ran a Log Management List query either in Log Explorer, Dashboards or through the Public API. | @evt.name:"Log Management" @asset.type:logs_query |
Restriction query configuration | A user created, modified, or deleted the configuration of a restriction query in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:restriction_query |
Download as CSV | A user exports list of logs as CSV | @evt.name:"Log Management" @asset.type:logs_csv |
Historical view | A user created, modified, aborted, or deleted a historical view for logs and the previous and new values for the historical view configuration. | @evt.name:"Log Management" @asset.type:historical_view |
Saved view | A user created, modified, or deleted a saved view. | @evt.name:"Log Management" @action:(created OR modified OR deleted) @asset.type:saved_view |
Log forwarding | A user created, modified, or deleted a custom destination. | @evt.name:"Log Management" @action:(created OR modified OR deleted) @asset.type:log_forwarding |