Current ThreatQ Version Filter
Audit Log Entries
Authentication/User Activity Logging
| Action | Message(s) | Information Logged |
|---|---|---|
| Local OAuth2 Authentication |
|
|
| Client Credential Authentication |
|
|
| LDAP Authentication |
|
|
| SAML Authentication |
|
|
| SSL Client Certificate Authentication (CAC) |
|
|
| Account Lock |
|
|
| Logout |
|
|
User Management Logging
| Action | Message(s) | Information Logged |
|---|---|---|
| Add/Delete User |
|
|
| Updates to User Information |
|
|
| Updates to Multifactor Authentication (MFA) Settings |
|
|
Integration Configuration Logging
Applies to feeds and operations.
| Action | Message(s) | Information Logged |
|---|---|---|
| Installing/uninstalling an integration |
|
|
| Enabling/disabling an integration |
|
|
| Updating integration settings |
|
|
Data Retention Policy Logging
| Action | Message(s) | Information Logged |
|---|---|---|
| Enable/Disable Data Retention Policy |
|
|
| Update Data Retention Policy |
|
|
ThreatQ Data Exchange (TQX) Logging
| Action | Message(s) | Information Logged |
|---|---|---|
| Install a TQX transport via new install or upgrade |
|
|
| Update a TQX transport |
|
|
| Create/delete an OpenDXL transport node |
|
|
| Update an OpenDXL transport node |
|
|
| Create/Delete OpenDXL data feed |
|
|
| Update OpenDXL data feed |
|
|
TAXII Server Logging
| Action | Message(s) | Information Logged |
|---|---|---|
| Install a TAXII transport via an install or upgrade that includes a TQX license |
|
|
| Create a TAXII collection |
|
|
| Delete a TAXII collection |
|
|
| Update a TAXII collection |
|
|
| Create a TAXII user – |
|
|
| Delete a TAXII user |
|
|
| Update a TAXI user |
|
|
| Create a TAXII collection user |
|
|
| Delete a TAXII collection user |
|
|
ThreatQ TDR Orchestrator (TQO) Configuration Logging
Applies to configuration driven workflows (CDWs), TQO workflows, and TQO actions.
| Action | Message(s) | Information Logged |
|---|---|---|
| TQO Component: CDW |
||
| Install/Uninstall a CDW |
|
|
| Enable/Disable a CDW |
|
|
| Update a CDW’s configuration |
|
|
| Delete a CDW’s configuration |
|
|
| TQO Component: Workflows | ||
| Install/Uninstall a workflow |
|
|
| Enable/Disable a workflow |
|
|
| Update a workflow |
|
|
| Create a workflow |
|
|
| Update a workflow’s configuration |
|
|
| Delete a workflow’s configuration |
|
|
| TQO Component: TQO Action | ||
| Configure a TQO action |
|
|
| Update a TQO action’s configuration |
|
|
| Delete a TQO action’s configuration |
|
|
| Install/Uninstall a TQO action |
|
|
| Update a TQO action |
|
|
| Create a TQO action |
|
|