Views:

TrendAI Vision One™ maintains system logs that provide summaries about system events that occurred.

System logs record events reported by the apps and services activated in your environment, such as report generation, data collector changes, and scan activity. To view system logs, go to AdministrationAudit Logs and select the System tab.
The following table outlines the available system log information.
Data
Description
Logged
The date and time the activity occurred
Category
The app or service that reported the event
The Category filter lists the categories available in your environment.
Categories include:
  • Account Management
  • Code Security
  • Data Source and Log Management
  • Reports
Activity
The type of event that occurred, such as generating a report, adding or deleting a data collector, or completing a scan
The activities recorded depend on the category of the entry. Use the Activity filter to see the activities available for a category.
Details
The fields recorded for the event, listed as semicolon-separated name and value pairs
The fields shown vary by category and activity. For example, a Generate report activity in the Reports category records the ID, status, name, format, and type of the report:
Report ID: 4b8e21a0-3c7d-4f19-9a52-6de07c1b8f34; Report final status: OK; Report name: Security Configuration; Report format: csv; Report type: scheduled;

Collect system logs outside the console

To retain or analyze system logs outside the console, forward them to a syslog server or SIEM solution. When you configure the syslog connector, select the Audit logs data type and the System log type. For the field names and formats used in forwarded entries, see CEF system audit logs.