The cybersecurity dictionary
160 Views •Defence : the blocked addresses
155 Views •Who is watching while you work
147 Views •The crisis room: the button never to press
143 Views •Risk analysis : a score, and why
143 Views •The help centre and the explanation bubbles
140 Views •Opening a support ticket
139 Views •Exclusions : silencing what is normal at your site
137 Views •The dashboard : ten seconds to know
137 Views •Your three habits, and what comes next
136 Views •My organisation : companies and licences
134 Views •Companies : the administrative record
133 Views •Who it is for
133 Views •Creating your workspace and accepting the terms
133 Views •Signing in : and what if I lost my password
133 Views •Vulnerabilities : the updates that are missing
133 Views •The equipment list : your machines
132 Views •Installing the agent on a machine
128 Views •The audit log : who did what
126 Views •Playbooks : ready-made responses
127 Views •The audit log : who did what
"Audit log" page
This page records the actions performed within the Security Center itself. It answers the traceability principle set out by the European personal-data regulation: being able to show who did what.
What you find there
Each line carries a timestamp, the user, the type of action, a detail, and the address the action came from. The action types are explicit and jargon-free: login, logout, registration, password change, report generation, download, deletion, emailing, user creation, playbook triggering.
How to search
Four filters: by user, you type the start of the email address, by action type, and between two dates. A Reset button clears everything. Results are read page by page, with the total at the top.
This log protects honest people first. When a document disappears or a setting has changed, the question "who?" quickly becomes heavy. Here the answer is written, dated, indisputable, and most often, it clears everybody.
Two logs not to confuse
The audit log traces actions in the Security Center: who logged in, who generated what. The Activity page, seen in the previous chapter, traces what happens on your machines. One speaks of people, the other of computers.
In practice, you come here twice a year: on audit day, and on the day someone genuinely wonders who deleted the March report.
In closing
The log is not there to watch your colleagues: it is there to prove what was done, and by whom, on the day the question arises. It is a requirement of European regulation, and a protection for everyone.
Commenting is not enabled on this course.