| Historical view | A user created, modified, aborted, or deleted a historical view for logs and the previous and new values for the historical view configuration. | @evt.name:"Log Management" @asset.type:historical_view |
| Download as CSV | A user exports list of logs as CSV. | @evt.name:"Log Management" @asset.type:logs_csv |
| Index order modified | A user modified the order of indexes. | @evt.name:"Log Management" @action:modified @asset.type:index_list |
| Log pipeline | A user created, modified, or deleted a log pipeline or nested pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline |
| Processor | A user created, modified, or deleted a processor within a pipeline and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:pipeline_processor |
| Facet | A user created, modified, or deleted a facet in the Log Explorer and the previous and new values for the facet configuration. | @evt.name:"Log Management" @asset.type:facet |
| Standard attribute configuration | A user created, modified, or deleted the configuration of a standard attribute in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:standard_attribute |
| Query (Public Beta) | A user ran a Log Management List query either in Log Explorer, Dashboards or through the Public API. | @evt.name:"Log Management" @asset.type:logs_query |
| Restriction query configuration | A user created, modified, or deleted the configuration of a restriction query in logs and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:restriction_query |
| Archiving order modified | A user modified the order of archives. | @evt.name:"Log Management" @action:modified @asset.type:archive_list |
| Exclusion filter configuration | A user created, modified, or deleted the configuration of an exclusion filter and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:"exclusion filter" |
| Custom metric | A user created, modified, or deleted a custom metric for logs and the previous and new values for the custom metric configuration. | @evt.name:"Log Management" @asset.type:"custom metric" |
| Archive configuration | A user created, modified, or deleted the configuration of an archive and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:archive |
| Log forwarding | A user created, modified, or deleted a custom destination. | @evt.name:"Log Management" @action:(created OR modified OR deleted) @asset.type:log_forwarding |
| Saved view | A user created, modified, or deleted a saved view in the Log Explorer. | @evt.name:"Log Management" @action:(created OR modified OR deleted) @asset.type:saved_view |
| Index configuration | A user created, modified, or deleted the configuration of an index and the previous and new values for the configuration. | @evt.name:"Log Management" @asset.type:index |