Waiting for engine...
Skip to main content

Audit log query construction

You construct audit log queries for specific types of account management actions by combining the type, action, and modifier filter parameters.

note

Failed login attempts and failed switch to different accounts are not captured and logged only for internal use.

For information about constructing queries for specific types of actions performed in Master Data Hub, refer to the topic REST APIs.

Action typetypeactionmodifier
Enable account features (admin level)accountEDIT
Enable, change, or disable Account Usage AgreementaccountEDITNONE
Enable, change, or disable single sign-on (SSO)accountEDITNONE
Enable or disable Session Lock and TerminateaccountEDITNONE
Enable or disable Session ConcurrencyaccountEDITNONE
Enable or disable two-factor authentication (account level)accountEDITNONE
Force sign out accountaccountLOGOUTNONE
Modify an account password policyaccountEDITNONE
Modify CORS settingsaccountEDITNONE
Log in/Switch accounts — success
Note: Because logging into the platform is technically considered an account switch, this action encompasses both account switching at initial sign in and after logging in. Additionally, failed log in attempts are not captured.
accountON_ENTRYSUCCESS
Update Assure settingaccountEDITNONE
Modify an account Support Access Roleas.account.accessEDITNONE
Add Trusted IP Address on an accountaccount-ip_addressADDTRUSTEDIP
Note: As of the January 2021 release, this audit log record shows a "TRUSTEDIP" modifier. Any historical records created prior to this date continue to show the previous WHITELISTING term.
Searching for the account IP address type without a modifier produces entries for both the new TRUSTEDIP and the retired WHITELISTING modifier.
Delete Trusted IP Address from an accountaccount-ip_addressDELETETRUSTEDIP
Note: As of the January 2021 release, the audit log record shows a TRUSTEDIP modifier. Any historical records created prior to this date continue to show the previous WHITELISTING term.
Searching for the account IP address type without a modifier produces entries for both the new TRUSTEDIP and the retired WHITELISTING modifier.
Edit Trusted IP Address in an accountaccount-ip_addressEDITTRUSTEDIP
**Note:**As of the January 2021 release, this audit log record shows a TRUSTEDIP modifier. Any historical records created before this date continues to show the previous WHITELISTING term.
Searching for the account IP address type without a modifier produces entries for both the new TRUSTEDIP and the retired WHITELISTING modifier.
Add an API applicationapi.applicationADDNONE
Update an API applicationapi.applicationUPDATENONE
Add an authentication sourceapi.authentication_sourceADDNONE
Remove an authentication sourceapi.authentication_sourceDELETENONE
Update an authentication sourceapi.authentication_sourceUPDATENONE
Add an API contractapi.contractADDNONE
Update an API contractapi.contractUPDATENONE
Add an API deploymentapi.deploymentADDNONE
Deploy or Redeploy an APIapi.deploymentDEPLOYNONE
Remove an API deploymentapi.deploymentDELETENONE
Update an API deploymentapi.deploymentUPDATENONE
Add, update, or delete API policy rulesapi.deployment_policiesADD, UPDATE, DELETENONE
Add an API Keyapi.keyADDNONE
Remove an API Keyapi.keyDELETENONE
Update an API Keyapi.keyUPDATENONE
Edit and save account propertiesas.account.propertiesSAVENONE
Add an account groupas.accountgroupADDNONE
Delete an account groupas.accountgroupDELETENONE
Add a cloud to an account groupas.accountgroup.resourceADDNONE
Delete a cloud from an account groupas.accountgroup.resourceDELETENONE
Add a connector to an account groupas.accountgroup.resourceADDNONE
Delete a connector from an account groupas.accountgroup.resourceDELETENONE
Add an integration pack to an account groupas.accountgroup.resourceADDNONE
Delete an integration pack from an account groupas.accountgroup.resourceDELETENONE
Add a published component to an account groupas.accountgroup.resourceADDNONE
Delete a published component from an account groupas.accountgroup.resourceDELETENONE
Add a role to an account groupas.accountgroup.resourceADDNONE
Delete a role from an account groupas.accountgroup.resourceDELETENONE
Add user to account groupas.accountgroup.userADDNONE
Update user roles in account groupas.accountgroup.userUPDATEROLE
Remove user from account groupas.accountgroup.userDELETENONE
Add Basic Authentication userapi-basic_auth_userADDNONE
Update Basic Authentication userapi-basic_auth_userUPDATENONE
Delete Basic Authentication userapi-basic_auth_userDELETENONE
Add Basic Authentication groupapi-basic_auth_groupADDNONE
Update Basic Authentication groupapi-basic_auth_groupUPDATENONE
Delete Basic Authentication groupapi-basic_auth_groupDELETENONE
Add Basic Authentication roleapi-basic_auth_roleADDNONE
Update Basic Authentication roleapi-basic_auth_roleUPDATENONE
Delete Basic Authentication roleapi-basic_auth_roleDELETENONE
Add a Runtimeas.atomINSTALLTOKEN or NONE
Add a Gatewayas.atomINSTALLTOKEN or NONE
Atom properties updateas.atomUPDATEMANUAL
Atom response to properties update requestas.atomUPDATERESPONSE
Apply a pending Atom updateas.atomUPDATENONE
Delete Atomas.atomDELETENONE
Delete node from the Runtime cluster or Runtime cloud clusteras.atomNODE_OFFBOARDNONE
Edit Atom Countersas.atomUPDATEMANUAL
forced Atom to appear onlineas.atomFORCEONLINE
Restart Atomas.atomRESTARTNONE
Pause listenersas.atomPAUSEMANUAL
Resume listenersas.atomRESUMEMANUAL
Restart listenersas.atomSTARTMANUAL
Revert a Runtime updateas.atomROLLBACKNONE
Uninstall the runtime, Runtime cluster, or Runtime cloudas.atomUNINSTALLNONE
Retrieve disk space usage for a Runtime cloud attachmentas.atom.disk.spaceNONENONE
Download a Runtime log, Worker log, or process run artifactas.atom.logDOWNLOADNONE
Download the Shared Web Server logas.atom.logDOWNLOADSHAREDWESERVERLOG
Attach packaged component to an environment Note: Attachment happens automatically the first time a packaged component for a given component is deployed to a given environment. Entries are not created for subsequent deployments to the same environment. For general deployment-related audit information, use the Deployed Package object.as.atom.processATTACHNONE
Undeploy packaged component from an environment Note: Captures the specific "Undeploy" action for a currently deployed packaged component.as.atom.processDETACHNONE
Stop Workeras.atom.processADDRESPONSE
Edit and save Atom propertiesas.atom.propertiesSAVENONE
Start purge process using the Atom Purge objectas.atom.purgeNONENONE
Atom schedule updateas.atom.rc_scheduleSAVENONE
Delete Runtime cloudas.cloudDELETENONE
Create a private runtime cloudas.cloudCREATENONE
Update a private runtime cloudas.cloudUPDATENONE
Delete a private runtime cloudas.cloudDELETENONE
Update default cloud attachment properties for the runtime cloud clusteras.cloud.logUPDATEMANUAL
Copy componentas.componentCOPYNONE
Delete componentas.componentDELETENONE
Apply a pending Connector updateas.connectorUPDATENONE
Rollback of connector updateas.connectorROLLBACKNONE
Download document — failureas.documentDOWNLOADFAILURE
Download document — successas.documentDOWNLOADSUCCESS
View document — failureas.documentVIEWFAILURE
View document — successas.documentVIEWSUCCESS
Attach Atom to environmentas.environmentATTACHNONE
Delete environmentas.environmentDELETENONE
Detach Atom from environmentas.environmentDETACHNONE
Update environment nameas.environmentUPDATENAME
Update environment roleas.environmentUPDATEROLE
Edit and save Atom or environment extension valuesas.extensionsEDITNONE
Edit and save integration pack extension valuesas.extensions.processEDITNONE
Edit and save forked execution propertiesas.forkedexecution.propertiesSAVENONE
Generate installer tokenas.installerADDNONE
Manual integration pack updateas.ipackUPDATEMANUAL
Roll back of Java versionas.java_upgradeROLLBACKEQUALS
Upgrade Runtimes, Runtime clusters, or Runtime clouds, Authentication Brokers, and API Gateways to Boomi's latest supported version of Javaas.java_upgradeUPDATENONE
Delete a packaged component versionas.packaged.componentDELETENONE
Restore a deleted version of a packaged componentas.packaged.componentRESTORENONE
Manually run the processas.process.manual_executionEXECUTEMANUALNote: When a document is rerun, the modifier also shows the RERUN_s=true/false property.
Edit and save process propertiesas.process.propertiesSAVENONE
Manually run test processas.process.test_executionEXECUTEMANUAL
Update scheduleas.schedulesUPDATENONE
Resume scheduleas.schedulesRESUMEALL or SINGLE
Stop scheduleas.schedulesSTOPALL or SINGLE
Add a tracked fieldas.trackingADDNONE
Modify a tracked fieldas.trackingUPDATENONE
Delete a tracked fieldas.trackingDELETENONE
Add a roleroleADDNONE
Remove a roleroleDELETENONE
Update a roleroleUPDATENONE
Add new user to accountuserADDNONE
Enable or disable two-factor authentication (user level)userUPDATEAUTHENTICATION
Modify a user sign-in passworduserUPDATEAUTHENTICATION
Modify an SSO User Federation IDuserUPDATENONE
Remove user from accountuserDELETENONE
Accept Terms and ConditionsuserTC_ACCEPTSUCCESS
Lock or unlock useruserUPDATEAUTHENTICATION
Update existing user roleuserUPDATEROLE
Update user emailuserUPDATEEMAIL
Enable or disable API Token (user level)user.tokenUPDATEAUTHENTICATION
Enable or disable user API Token (admin level)user.tokenUPDATEAUTHENTICATION
Generate API Tokenuser.tokenADDAUTHENTICATION
Rename API Tokenuser.tokenUPDATEAUTHENTICATION
Revoke API Tokenuser.tokenDELETEAUTHENTICATION
Revoke API Tokens after removing a user from an account or an account group, removing an account from an account group, or deleting an account groupuser.tokenDELETEAUTHENTICATION
Create a Runtime Release schedule for a runtime, Runtime cluster, or Runtime cloudas.atom.rc_scheduleSAVENONE
Update a set Runtime Release schedule for a runtime, Runtime cluster, or Runtime cloudas.atom.rc_scheduleSAVENONE
Delete a set Runtime Release schedule for a runtime, Runtime cluster, or Runtime cloudas.atom.rc_scheduleSAVENONE
Refresh Secrets on runtime, Runtime cluster, or Runtime cloudas.atomEDITMANUAL