For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 8 (SaaS)

Management audit logs

Manage audit logs in Cortex XSOAR 8 SaaS.

The management audit logs display a log of all administrative user interactions within Cortex XSOAR. By default, the logs are sorted by Timestamp and cover which users interacted in what way with system objects, and associated data.

You can filter by field, such as email, ID, user name, type, etc., and you can save filters for later use. In addition, you can adjust the appearance of the columns and add or remove columns.

To view the audit logs, go to Settings & Info → Management Audit Logs.

By default, the Object ID column is hidden. You can add the Object ID column by clicking the table settings menu button and selecting Object ID. This column displays the specific ID associated with the logged action. For example, for incident creation, the Incident ID is displayed and for user creation, the User ID is displayed. Not all actions have an associated Object ID.

To export the management audit logs as a tsv text-based file, click the Export to file button. You can also forward management audit notifications to a syslog server or an email distribution list.

Management audit logs are retained for one year.

The following table describes the log types and sub types.

Alert Notifications

Includes the following subtypes:

Subtypes
  • New Configuration

  • Edit Configuration

  • Disable Configuration

  • Delete Configuration

API Keys

Includes the following subtypes:

Subtypes
  • Add New Key

  • Edit Key

  • Delete Key

Authentication

Includes the following subtypes:

Subtypes
  • Login

  • Logout

Authentication settings

Licensing

Includes details about the license, such as expiration and ingestion violation.

Permissions

Includes user role permissions such as:

User role permissions
  • Role created

  • User permissions assigned

  • User Group created

  • Role deleted

  • User permissions revoked

Public API

Security Settings

Changes to the Cortex XSOAR security settings.

Server Settings

Changes to the Cortex XSOAR server settings.

System

Cortex Automation

Subtypes
Subtype
Description

Classifier

Incident and indicator classifier subtypes, such as add, copy, and edit subtypes.

Command

This log type records commands entered by analysts in the War Room and Playground, improving visibility into analyst actions taken during the incident response and troubleshooting processes. You can filter for these logs by subtype that contains War Room or Playground. Details include the incident type and name, the command, and any arguments.

For example:

IncidentID:3, IncidentType:Phishing, IncidentName:Phishing, Command:send-mail, Arguments:body="111" to="admin@admin.com" subject="222", ID: 3

Content

Includes content bundle subtypes, such as install and download.

ContentPack

Includes content pack subtypes, such as install and delete.

ContributionPack

Includes contribution content pack subtypes, such as add, edit, and delete.

Credentials

Includes integration credential subtypes, such as add, edit, and delete.

Dashboard

Includes dashboard subtypes such as add, edit, and delete.

Engine

Includes engine subtypes such as add, edit, and delete.

Entry

Includes the following subtypes in an incident investigation:

  • Delete

  • RemoveEntryPermanently

  • Edit

HyperProcess

Includes the add and delete subtypes for the Hyper Process.

Incident

Includes incident subtypes, such as add, edit, close, execute, and duplicate.

IncidentField

Includes incident field subtypes, such as add, edit, delete, and export

Incident Layout

Includes incident layout subtypes, such as add, duplicate, edit, attach, and detach.

IncidentType

Includes incident type subtypes, such as attach, detach, enabled, disabled, and delete.

Indicator

Includes indicator subtypes, such as edit, add, and delete.

IndicatorBulkEdit

Includes the indicator bulk edit subtype, such as edit.

Integration permissions

Includes the indicator permissions edit subtype.

Integrations

Includes integration subtypes, such as add, edit, and delete.

IntegrationsConfig

Includes integration configuration subtypes, such as add, edit, and upload.

Investigation

Includes investigation subtypes, such as add, edit, and reopen.

Jobs

Includes job subtypes, such as add, edit, delete, pause, and abort.

Layout

Includes indicator layout subtypes, such as copy, detach, edit, attach, and detach.

List

Includes list subtypes such as add, edit, and delete.

Playbook

Includes playbook subtypes such as add, edit, copy, upload, and delete.

PreprocessRule

Includes pre-processing rule subtypes such as add and edit.

Script

Includes script subtypes such as copy, upload, edit, and delete.

ServerConfiguration

Includes the server configuration edit subtype.

SyncPush - Content

Includes pushing content to a remote repository.

ThreatIntelReport

Includes the Threat Intel Report subtypes such as create, edit, and delete.

Whitelist

Includes the whitelist subtypes such as delete, batchcreate, and add.

Widget

Includes the widget subtypes such as edit add and reset.

XSOAR Migration

Includes audit information about the migration from Cortex XSOAR 6 to 8, such as whether users were migrated, the cutoff date, and whether content and integrations were resynced.

Last updated

Was this helpful?