7.8. Audit Event Log #

PPEM logs audit events (also known as audit trails) for troubleshooting, monitoring, accountability, and other purposes.

To view or delete the audit event log, a user role must have the audit_events_view or audit_events_delete privilege, respectively.

PPEM logs the following audit event types:

Table 7.1. Audit event types

Description

Severity

Name (web application interface)

Name (downloadable log)

Records were deleted from the audit event log

High

Audit events deleted

audit_events_delete

An RBAC role was created

Low

Role created

role_create

An RBAC role was edited

Low

Role edited

role_edit

An RBAC role was deleted

Low

Role deleted

role_delete

A user was created

Low

Use created

user_create

A user was edited

Low

User edited

user_edit

A user was blocked

Medium

User blocked

user_block

A user was deleted

Medium

User deleted

user_delete

A user login was attempted

Low

Login attempted

login

An instance was started

Medium

Instance started

instance_start

An instance was restarted

Medium

Instance restarted

instance_restart

An instance configuration was reloaded

Medium

Instance reloaded

instance_reload

An instance was edited

Medium

Instance edited

instance_edit

A database was created

Medium

Database created

database_create

A database was edited

Medium

Database edited

database_edit

A database was deleted

Medium

Database deleted

database_delete

A backup was created

Medium

Backup created

backup_create

A backup was restored

Medium

Backup restored

backup_restore

A backup was deleted

Medium

Backup deleted

backup_delete


For every listed event, the name from the last column is used in event log files downloaded as JSON files.