TrendAI Vision One™ maintains system logs that provide summaries about system events that occurred.
System logs record events reported by the apps and services activated in your environment,
such as report generation, data collector changes, and scan activity. To view system
logs, go to and select the System tab.
The following table outlines the available system log information.
|
Data
|
Description
|
|
Logged
|
The date and time the activity occurred
|
|
Category
|
The app or service that reported the event
The Category filter lists the categories available in your environment.
Categories include:
|
|
Activity
|
The type of event that occurred, such as generating a report, adding or deleting a data
collector, or completing a scan
The activities recorded depend on the category of the entry. Use the Activity filter to see the activities available for a category.
|
|
Details
|
The fields recorded for the event, listed as semicolon-separated name and value pairs
The fields shown vary by category and activity. For example, a Generate report activity in the Reports category records the ID, status, name, format, and type of the report:
Report ID: 4b8e21a0-3c7d-4f19-9a52-6de07c1b8f34; Report final status: OK; Report name: Security Configuration; Report format: csv; Report type: scheduled; The Search field on the System tab matches partial text in the Details column only.
|
Collect system logs outside the console
To retain or analyze system logs outside the console, forward them to a syslog server
or SIEM solution. When you configure the syslog connector, select the Audit logs data type and the System log type. For the field names and formats used in forwarded entries, see CEF system audit logs.
