Audit logs
The audit log provides audit records for actions that are performed in IBM Storage Insights. Audit logs are retained for 15 days from the date of action performed by the user and are downloaded in Cloud Auditing Data Federation (CADF) standard format. For privacy, the audit logs contain masked email addresses of the users who perform the actions.
Table 2 shows the user actions which are included in the logs. Users with administrator role can download and view the events that are captured in the audit log. Users with monitor role cannot download the audit logs.
Downloading audit logs from IBM Storage Insights GUI
You can download the audit logs in the modern UI by clicking the Settings icon at the upper-right in the menu bar and then click Export audit log in the modern UI. From classic UI, click to download the audit logs.
Downloading audit logs using IBM Storage Insights REST API
- To generate the REST API key, see Generating a REST API key.
- To generate the REST API token, see Generate an API Token.
For more information about auditlogs API, see Swagger documentation.
Security aspects
The following table describes which user can see which audit messages:
| User role | Access to download audit logs |
|---|---|
| Administrator role | Yes |
| Monitor role | No |
Audit actions
The following table describes the user actions which are included in the logs:
| Feature | Action | Action String |
|---|---|---|
| Alert management |
|
|
| Alert definition management |
|
|
| Hosts |
|
|
| IBM Storage Defender integration | When user tries to Approve/Deny device integration with IBM Storage Defender. | DEFENDER_USER_DEVICE_ACTION |
| Resolve ransomware false positive alerts and submit feedback | Resolve alert as false positive:
|
FEEDBACK_ALERTS |
| Inline threat detection configuration |
|
|
| Login or Logout |
|
|
| Permission management | This action is logged when the administrator user updates partition management permission for any user. | PARTITION_MANAGEMENT_PERMISSION |
| Report management |
|
|
| REST API token management |
|
|
| Settings |
|
|
| Storage partition migration | Any orchestration request or process or orchestration response from Call Home. Actions are
logged as requests and responses
|
SI_AIOPS_ORCHESTRATION |
| Storage systems |
|
|
| Switch or Fabric |
|
|
| Ticket management |
|
|
| User actions from IBM Storage Insights |
|
|
| Webhook management |
|
|
| Carbon emission management |
|
EDIT_CO2E_CONSTANTS |
| Marking the storage system for maintenance | Starting and stopping the storage system maintenance | UPDATE_DEVICE_MAINTENANCE |