Skip Navigation

CylanceON-PREM
audit logs

You can review the audit log for information on various actions performed from the
CylanceON-PREM
console. You can view audit logs by clicking
Audit Logs
on the menu bar of the console.
When you deploy
CylanceON-PREM
for the first time, it creates a system account (First Name=system and Email=system@onprem.local) that is used in Audit Logs to identify actions taken by the system versus actions taken by a
CylanceON-PREM
user. For example, the system account is used when the system applies a policy to a device as a result of a policy rules match.
Event
Actions
Agent Update
Edit
Device
Edit, delete
Global List
Create, delete
Login
Success, failure
Logout
Success, failure
Policy
Create, edit, delete
Policy Rule
Create, edit, delete, auto policy applied
The Audit Log will have one entry per device when a rule is automatically applied because conditions were met.
Role
Create, update, delete
Tag
Create, update, delete, assigned
Tag Rule
Create, update, delete, auto tag applied
The Audit Log will have one entry per device when a rule is automatically applied because conditions were met.
Threat
Quarantine, waive, global quarantine, safe list
User
Create, edit, delete, assigned
Virtual Appliance Update
Enable or disable maintenance mode
  • To filter entries in this list to find information faster, click icon .
  • To export entries in this list to use in other applications, click icon.