Skip to content

Audit Events


Audit events are generated by user actions within a workspace. They record project usage, user behavior, and resource changes in real time. This includes but is not limited to:

  • Workspace management events: e.g., modifying basic settings, changing member permissions, deleting notification targets, license expiration, etc.
  • Feature and service usage events: e.g., creating/modifying/deleting views, creating an application detection, disabling a detection library, muting a host, creating or deleting incidents, generating metrics, etc.
  • Billing item events: e.g., project usage approaching the free quota, etc.
  • ...

Scope of Audit Events

  • User login and access behavior records
  • User operation behavior records
  • OpenAPI operation behavior records

When an incident is created or deleted successfully, a corresponding audit event is generated, recording tracking information such as the workspace, incident ID, operator, and operation time.

Querying Audit Events

In a workspace, you can retrieve audit events using the DQL query:

TAE::re(`.*`):(`*`){ `df_source` IN ['audit'] }

Managing Audit Events

Go to Management > Audit Events to view all user operation events generated in the workspace.

  • In the list, you can search, group, and aggregate events.
  • Use the Time Widget at the top of the page to view operation events within different time ranges.
  • Click Settings to create a monitor directly from the audit events or export the current audit event list as a CSV.

Group Aggregation

Group events by operator to see the total number of aggregated events triggered by a user in the workspace within a specific time range.

In group aggregation mode, you can also view Aggregated Events. On the details page, you can see all audit events triggered by a specific user (operator).

Audit Event Details

Click a single event in the operation event list to slide out the event details page, where you can view the event trigger time, tag attributes, operator, event content, etc.

You can also use the following fields for custom queries:

Field Name Type Required Description
date Integer Required Generation time, Unix timestamp, in ms
df_date_range Integer Required Time range, in seconds
df_source String Required Data source, value is audit for audit events
df_status String Required Status, default value is info for audit events
df_origin String Required Operation source, records the entry point of the current operation.
Reference values:
  • front: user operation from the frontend
  • openapi: operation via OpenAPI
  • manage: operation via the management backend
  • inner: operation via internal trusted systems
  • df_menu String Required Menu path accessed by the user, e.g., Logs-Explorer
    df_event_id String Required Unique event ID
    df_title String Required Title
    df_message String Required Description
    df_user_id String Required User ID
    df_user_name String Required User name
    df_user_email String Required User email, corresponding to the id, name, and email in Member Management
    df_user_team String Required Current team of the user
    df_role_scope String Required Current role scope of the user
    df_operation_id Str Required Unique ID of the actual operation corresponding to the current audit
    df_operation_name Str Required Menu name corresponding to the operation that generated the current audit. For example, if a notification policy operation corresponds to an audit event, this field is the name of the notification policy.
    df_query_typeDQL String Required Query type
    df_query String Required DQL query
    df_query_range String Required DQL query duration, in ms
    df_cost String Required DQL query cost
    df_hit_count String Required Query hit count
    df_workspace String Required Workspace to which the audit event belongs

    Data Storage

    Audit event data is stored independently and is not related to the event storage policy of other workspaces. The default storage duration is 2 years. You can view and adjust the storage policy by going to Management > Settings > Change Data Storage Policy.