Audit Events
For administrators and auditors. Audit
Administration is at /admin/audit and needs
SystemAdmin plus step-up.
Every name on this page is a verbatim action string used by the
product. Type them into the exact-action filter as written. They are
case-sensitive.
Why you need this list
The action picker in Audit Administration is built from actions
already recorded within the time window you have selected, not from your
whole database. An action that has never occurred on your installation,
or that occurred outside the selected window, does not appear in the
picker at all. To search for one, type it.
Audit and export
AuditExported |
RedactionRegisterViewed |
RedactionRegisterExported |
Tenant and configuration
TenantCreated, TenantUpdated |
WebSecurityAdminConfigCreated,
WebSecurityAdminConfigUpdated |
StorageContinuityAdminConfigCreated,
StorageContinuityAdminConfigUpdated |
HttpsCertificateAdminConfigCreated,
HttpsCertificateAdminConfigUpdated |
Sign-in and session
LoginSucceeded, LoginFailed,
LoginRateLimited, Logout |
ExternalParticipantAuthenticated,
ExternalParticipantLoginRateLimited,
ExternalParticipantLogout |
Customer Portal SSO sign-out records plain Logout, with
the actor source set to CustomerPortalSso.
Step-up and system
protection
AdminStepUpVerificationSucceeded,
AdminStepUpVerificationFailed |
SystemAdminBootstrap |
SystemRoleGrantCreated,
SystemRoleGrantDisabled |
LastSystemAdminProtectionTriggered |
Users and groups
LocalUserCreated, LocalUserEnabled,
LocalUserDisabled, LocalUserPasswordReset |
UserTicketEmailContactUpdated,
UserLandingPreferenceUpdated |
LocalGroupCreated, LocalGroupEnabled,
LocalGroupDisabled |
UserAddedToGroup,
UserRemovedFromGroup |
Directory and LDAP
DirectoryConfigCreated,
DirectoryConfigUpdated,
DirectoryConfigSecretUpdated,
DirectoryConfigTested,
DirectoryConfigDefaultsSuggested,
DirectoryConfigSearchScopesBrowsed |
LdapSyncRequested, LdapSyncSkipped,
LdapSyncRunStarted, LdapSyncRunCompleted,
LdapSyncRunFailed,
LdapSyncGuardrailTriggered |
LdapUserCreated, LdapUserUpdated,
LdapUserEnabled, LdapUserDisabled |
LdapGroupCreated, LdapGroupUpdated,
LdapGroupEnabled, LdapGroupDisabled |
LdapUserJitCreated,
LdapUserJitUpdated |
SAML
SamlConfigCreated, SamlConfigUpdated,
SamlConfigValidated |
SamlLoginSucceeded, SamlLoginFailed |
SamlUserJitCreated, SamlUserJitUpdated,
SamlUserPreProvisioned |
SamlGroupMappingCreated,
SamlGroupMappingUpdated,
SamlGroupMappingDeleted |
SamlGroupMembershipApplied,
SamlGroupMembershipRevoked |
Customer Portal SSO
CustomerPortalSsoConfigCreated,
CustomerPortalSsoConfigUpdated,
CustomerPortalSsoSecretChanged |
CustomerPortalSsoHandoffSucceeded |
CustomerPortalSsoUserJitCreated,
CustomerPortalSsoUserJitUpdated |
CustomerPortalSsoAccessGranted,
CustomerPortalSsoAccessRevoked |
There is no event for a failed handoff. Rejected handoff traffic is
recorded as rate-limited operational telemetry, not as an audit row. Do
not search for a failure event; there is none.
Two-factor authentication
NonSamlTfaPolicyUpdated |
NonSamlTfaEnrollmentStarted,
NonSamlTfaEnrollmentCompleted,
NonSamlTfaEnrollmentReset |
NonSamlTfaChallengeSucceeded,
NonSamlTfaChallengeFailed |
Department access and
automation
DepartmentGroupAccessCreated,
DepartmentGroupAccessUpdated,
DepartmentGroupAccessEnabled,
DepartmentGroupAccessDisabled |
DepartmentAccessAutomationSettingsUpdated |
DepartmentAccessAutomationRuleCreated,
DepartmentAccessAutomationRuleUpdated,
DepartmentAccessAutomationRuleEnabled,
DepartmentAccessAutomationRuleDisabled |
DepartmentAccessAutomationApplied,
DepartmentAccessAutomationMappingApplied,
DepartmentAccessAutomationReverted |
ExternalParticipantAccessIdentityEnabled,
ExternalParticipantAccessIdentityDisabled |
Projects
ProjectCreated, ProjectUpdated,
ProjectActivated, ProjectDeactivated,
ProjectViewed, ProjectStatusTransitioned |
ProjectCustomFieldBindingCreated,
ProjectCustomFieldBindingUpdated,
ProjectCustomFieldValuesUpdated |
ProjectRoleUpserted,
ProjectRoleCleared |
ProjectManagerAssignmentUpserted,
ProjectManagerAssignmentCleared |
ServiceProjectRoleMappingUpserted,
ServiceProjectRoleMappingCleared |
DepartmentProjectRoleFallbackUpserted,
DepartmentProjectRoleFallbackCleared |
ProjectTicketContextUpserted,
WorkTicketProjectLinkUpserted,
WorkTicketProjectLinkCleared |
MetadataTagDefinitionCreated,
MetadataTagDefinitionUpdated,
MetadataTagAssigned, MetadataTagCleared |
Saved work views
AgentWorkViewCreated,
AgentWorkViewUpdated,
AgentWorkViewRemoved |
ProjectRosterViewCreated,
ProjectRosterViewUpdated,
ProjectRosterViewRemoved |
Tickets
TicketCreated, TicketSafeFieldUpdated,
TicketViewed |
TicketReferenceAssigned,
TicketReferenceBackfillCompleted |
TicketProjectAssociationUpserted,
TicketProjectAssociationCleared |
TicketRelationshipCreated,
TicketRelationshipCleared |
TicketAttachmentUploaded,
TicketAttachmentVisibilityUpdated,
TicketAttachmentViewed,
TicketAttachmentDeleted |
PortalCartCheckoutRequested,
PortalCheckoutCompleted,
PortalBuyNowCompleted |
The three Portal* names record a requester submitting
selected tickets. They have nothing to do with payment.
Ownership and assignment
TicketOwnerSet, TicketOwnerReassigned,
TicketOwnerCleared,
TicketOwnerBackfillCompleted |
HeuristicAssignmentEvaluated |
DepartmentManagerSourceUpserted,
DepartmentManagerSourceCleared |
DepartmentOnCallSourceUpserted,
DepartmentOnCallSourceCleared |
Redaction and reveal
TicketContentRedacted |
RedactionOriginalRevealRequested,
RedactionOriginalRevealApproved,
RedactionOriginalEvidenceRevealed,
RedactionOriginalRevealAttemptDenied |
RedactionRevealNotificationDeliveryAttempted,
RedactionRevealNotificationDelivered,
RedactionRevealNotificationDeliveryFailed,
RedactionRevealNotificationSuppressed |
Workflow
TicketStatusTransitioned |
WorkflowDefinitionCreated,
WorkflowDefinitionUpdated,
WorkflowDefinitionDeleted |
WorkflowActionExecuted |
Pause, Resume, NotifyWatchers,
TicketUpdated, TicketResolved, and
NoAction appear in workflow configuration screens. They are
workflow action types and notification template names, not audit
actions. Filtering on them returns nothing.
Collaboration
TicketCommentCreated,
TicketCommentUpdated,
ExternalParticipantCommentCreated |
TicketWatcherAdded,
TicketWatcherRemoved |
TicketParticipantAdded,
TicketParticipantRemoved |
TicketExternalParticipantAdded,
TicketExternalParticipantRemoved,
TicketExternalParticipantInvitationIssued,
TicketExternalParticipantEnrollmentCompleted |
ExternalParticipantTicketViewed,
ExternalParticipantAttachmentUploaded,
ExternalParticipantAttachmentViewed |
Approvals and signatures
TicketApprovalRequestCreated,
TicketApprovalApproverAssigned,
TicketApprovalViewed,
TicketApprovalDecisionRecorded |
TicketApprovalReminderQueued,
TicketApprovalOutcomeNotificationQueued |
TicketApprovalNotificationDeliveryAttempted,
TicketApprovalNotificationDelivered,
TicketApprovalNotificationDeliveryFailed,
TicketApprovalNotificationSuppressed |
RegulatedApprovalBlocked,
RegulatedApprovalVerificationFailed,
RegulatedApprovalSatisfied |
RegulatedElectronicSignatureExecuted |
Mail
OutboundMailConfigCreated,
OutboundMailConfigUpdated,
OutboundMailConfigSecretUpdated,
OutboundMailConfigSecretProtectedAtRest |
OutboundMailConfigVerified,
OutboundMailConfigVerificationFailed,
OutboundMailConfigVerificationBlocked |
OutboundTicketMailPreviewed,
OutboundTicketMailDeliveryAttempted,
OutboundTicketMailDelivered,
OutboundTicketMailDeliveryFailed |
TicketEmailUpdateConfigCreated,
TicketEmailUpdateConfigUpdated |
TicketEmailUpdateDeliveryAttempted,
TicketEmailUpdateDelivered,
TicketEmailUpdateDeliveryFailed,
TicketEmailUpdateSuppressed |
InboundTicketMailSecretUpdated,
InboundTicketMailReceived,
InboundTicketMailBound,
InboundTicketMailClassified,
InboundTicketMailBlocked,
InboundTicketMailBindingFailed |
Licensing
ProductLicenseAgreementAcknowledged,
ProductLicenseConfigured,
ProductLicenseVerified |
ProductLicenseActivated,
ProductLicenseHeartbeat,
ProductLicenseDeactivated,
ProductLicenseCleared |
Import
ImportProfileDefinitionCreated,
ImportProfileDefinitionUpdated,
ImportProfileDefinitionEnabled,
ImportProfileDefinitionDisabled |
ImportDryRunExecuted |
ImportApplyRunStarted,
ImportApplyRunResumed,
ImportApplyRunCompleted, ImportApplyRunFailed,
ImportApplyRunReplayed |
ImportApplyRunIdempotencyConflict,
ImportApplyRunGuardrailRejected |
ImportApplyRunReconciliationGenerated,
ImportApplyRunReconciliationExported |
ImportMaterializationRecorded,
ImportUserCreated, ImportGroupCreated |
Service-level agreement
SLAPolicyCreated, SLAPolicyUpdated,
SLAPolicyDeleted |
SLAInstanceCreated, SLAInstancePaused,
SLAInstanceResumed |
SLAFirstResponseAchieved,
SLAResolutionAchieved |
SLAWarningEvent, SLABreachEvent |
Business calendar administration is recorded. Four events are written
by BusinessCalendarService:
BusinessCalendarCreated |
A calendar is created |
BusinessCalendarUpdated |
A calendar is edited, producing a new version |
BusinessCalendarActivated |
A calendar is made selectable by policies |
BusinessCalendarDeactivated |
A calendar is withdrawn from selection |
SLA timing itself is per target and may run on 24/7 wall-clock time
or a business calendar. See Limits
and scope and Business
calendars.
Catalogue, fields,
departments, demo data
ServiceCreated, ServiceUpdated,
ServiceEnabled, ServiceDisabled |
ServiceCatalogIconAssetUploaded,
ServiceCatalogIconAssetRetired |
ServiceCategoryCreated,
ServiceCategoryUpdated,
ServiceCategoryActivated,
ServiceCategoryDeactivated,
ServiceCategoryReordered |
StatusDefinitionCreated,
StatusDefinitionUpdated,
StatusDefinitionActivated,
StatusDefinitionDeactivated,
StatusDefinitionReordered |
CustomFieldDefinitionCreated,
CustomFieldDefinitionUpdated,
CustomFieldDefinitionDeleted,
CustomFieldDefinitionReordered |
SharedCustomFieldDefinitionCreated,
SharedCustomFieldDefinitionUpdated,
SharedCustomFieldDefinitionBound |
DepartmentCreated, DepartmentUpdated,
DepartmentEnabled, DepartmentDisabled |
DemoDataSeeded, DemoDataPurged |
Names that do not work as
filters
OutboxEventProcessed,
OutboxEventFailed |
Never recorded. No such events exist. Outbox handlers record domain
events instead — SLABreachEvent,
SLAWarningEvent, and the notification-delivery families.
Outbox processing and retries go to the logs, not the audit
history. |
EvaluationLicenseAcknowledged |
Not an action. It is a field inside a
SystemAdminBootstrap record. Filter on
SystemAdminBootstrap instead. |
SLABreachDetected |
Old name. Use SLABreachEvent. |
LdapConfigUpdated |
Old name. Use DirectoryConfigUpdated. |
LdapSyncStarted, LdapSyncCompleted |
Old names. Use LdapSyncRunStarted,
LdapSyncRunCompleted. |
DepartmentGroupAccessRemoved |
Old name. Use DepartmentGroupAccessDisabled or
DepartmentGroupAccessUpdated, depending on what
happened. |
The old names never appear in stored records. Typing one returns zero
rows — which is not evidence that nothing happened.
Ticket History shows only
these 36
Ticket History on a ticket is a fixed subset of the audit record, not
a filtered view of it. It shows exactly:
TicketCreated, TicketSafeFieldUpdated,
TicketStatusTransitioned,
TicketCommentCreated, TicketCommentUpdated,
ExternalParticipantCommentCreated,
TicketAttachmentUploaded,
TicketAttachmentVisibilityUpdated,
TicketAttachmentViewed,
TicketAttachmentDeleted,
ExternalParticipantAttachmentUploaded,
ExternalParticipantAttachmentViewed,
TicketContentRedacted, TicketWatcherAdded,
TicketWatcherRemoved, TicketParticipantAdded,
TicketParticipantRemoved,
TicketRelationshipCreated,
TicketRelationshipCleared, TicketOwnerSet,
TicketOwnerReassigned, TicketOwnerCleared,
TicketProjectAssociationUpserted,
TicketProjectAssociationCleared,
TicketExternalParticipantAdded,
TicketExternalParticipantRemoved,
TicketExternalParticipantInvitationIssued,
TicketExternalParticipantEnrollmentCompleted,
TicketApprovalDecisionRecorded,
SLAInstanceCreated, SLAWarningEvent,
SLABreachEvent, SLAInstancePaused,
SLAInstanceResumed, SLAFirstResponseAchieved,
SLAResolutionAchieved.
TicketViewed is recorded but deliberately excluded from
Ticket History. TicketReferenceAssigned,
TicketApprovalRequestCreated,
TicketApprovalViewed, WorkflowActionExecuted,
the approval notification events, and the ticket email events are also
excluded. Use Audit Administration for those. ProjectViewed
is excluded from project history in the same way.
What this list does not tell
you
- It does not prove every change in the product records an event.
There is no single registry of action names in the product; they are
written individually at each place that records one.
- Event payloads vary. Some are metadata only, some are redacted, some
are withheld.
- Absence of an event in one search does not prove the action never
happened. Widen the window and check the spelling first.
See Limits and scope for what
append-only does and does not mean.
Related pages