Skip to content

Audit Journal Reference

S-Filer Portal audits all actions taken in the user interface or via the API in a journal stored in the database. Audit entries are also sent to a special logger named "AUDIT" and this allows to send them to a SIEM solution using a syslog appender.

Audit types and description

Login (1.3.6.1.4.1.7660.50.1.1)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.1.1Login succeededLogin succeeded for 'ENTRY0' at domain 'ENTRY1'.
1.3.6.1.4.1.7660.50.1.1.2Login failedLogin failed for 'ENTRY0' at domain 'ENTRY1'. Reason: ENTRY2
1.3.6.1.4.1.7660.50.1.1.3Logout successLogout succeeded for 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.1.4Password expiredPassword expired for 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.1.5Account expiredAccount expired for 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.1.6Account lockedAccount locked for 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.1.7Account temporarily lockedAccount temporarily locked for 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.1.8MFA validation succeededMFA validation succeeded for 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.1.9MFA validation failedMFA validation failed for 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.1.10System administrators are not allowed to authenticateLogin succeeded for 'ENTRY0' at domain 'ENTRY1' but system administrators are not allowed to authenticate.

User (1.3.6.1.4.1.7660.50.1.2)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.2.1User password changedUser 'ENTRY0@ENTRY1(ENTRY2)' has changed his password.
1.3.6.1.4.1.7660.50.1.2.2User addedUser 'ENTRY0@ENTRY1(ENTRY2)' added.
1.3.6.1.4.1.7660.50.1.2.3User updatedUser 'ENTRY0@ENTRY1(ENTRY2)' updated.
1.3.6.1.4.1.7660.50.1.2.4User deletedUser 'ENTRY0@ENTRY1(ENTRY2)' deleted.
1.3.6.1.4.1.7660.50.1.2.5"Quick Send" recipient deleted"Quick Send" recipient 'ENTRY0(ENTRY1)' deleted.
1.3.6.1.4.1.7660.50.1.2.6User account lockedUser account 'ENTRY0@ENTRY1(ENTRY2)' locked.
1.3.6.1.4.1.7660.50.1.2.7User account unlockedUser account 'ENTRY0@ENTRY1(ENTRY2)' unlocked.
1.3.6.1.4.1.7660.50.1.2.8User account temporarily lockedUser account 'ENTRY0@ENTRY1(ENTRY2)' is temporarily locked.
1.3.6.1.4.1.7660.50.1.2.9Lost PasswordLost password requested by user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.10Password ResetPassword reset for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.11Access token addedAccess token 'ENTRY0(ENTRY1)' added for user 'ENTRY2@ENTRY3(ENTRY4)'.
1.3.6.1.4.1.7660.50.1.2.12Access token deletedAccess token 'ENTRY0(ENTRY1)' deleted for user 'ENTRY2@ENTRY3(ENTRY4)'.
1.3.6.1.4.1.7660.50.1.2.13MFA (TOTP) enrollment startedMFA (TOTP) enrollment started for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.14MFA (TOTP) addedMFA (TOTP) added for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.15MFA (TOTP) deletedMFA (TOTP) deleted for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.16SSH key addedSSH key added for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.17SSH key updatedSSH key updated for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.18SSH key deletedSSH key deleted for user 'ENTRY0@ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.2.19Role updatedUser 'ENTRY0@ENTRY1(ENTRY2)' role has been updated (ENTRY3 -> ENTRY4).

Community (1.3.6.1.4.1.7660.50.1.3)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.3.1Community addedCommunity 'ENTRY0(ENTRY1)' added.
1.3.6.1.4.1.7660.50.1.3.2Community updatedCommunity 'ENTRY0(ENTRY1)' updated.
1.3.6.1.4.1.7660.50.1.3.3Community deletedCommunity 'ENTRY0(ENTRY1)' deleted.
1.3.6.1.4.1.7660.50.1.3.4User assigned to communityAssign member 'ENTRY0(ENTRY1)' to Community 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.3.5User unassigned from communityMember 'ENTRY0(ENTRY1)' has been unassigned from Community 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.3.6Group assigned to communityAssign group 'ENTRY0(ENTRY1)' to Community 'ENTRY2'.
1.3.6.1.4.1.7660.50.1.3.7Group unassigned from communityUser group 'ENTRY0(ENTRY1)' has been unassigned from Community 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.3.8User role updated to community memberSet user 'ENTRY0(ENTRY1)' as a member of the Community 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.3.9User role updated to community administratorSet user 'ENTRY0(ENTRY1)' as an administrator of the Community 'ENTRY2(ENTRY3)'.

Group (1.3.6.1.4.1.7660.50.1.4)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.4.1Group addedUser group 'ENTRY0(ENTRY1)' added.
1.3.6.1.4.1.7660.50.1.4.2Group updatedUser group 'ENTRY0(ENTRY1)' updated.
1.3.6.1.4.1.7660.50.1.4.3Group deletedUser group 'ENTRY0(ENTRY1)' deleted.
1.3.6.1.4.1.7660.50.1.4.4User assigned to groupMember 'ENTRY0(ENTRY1)' has been assigned to User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.5User unassigned from groupMember 'ENTRY0(ENTRY1)' has been unassigned from User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.6User role updated to group memberSet user 'ENTRY0(ENTRY1)' as a member of the User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.7User role updated to group administratorSet user 'ENTRY0(ENTRY1)' as an administrator of the User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.8Password policy (user) assigned to groupPassword policy (user) 'ENTRY0(ENTRY1)' has been assigned to User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.9Password policy (quick send) assigned to groupPassword policy (quick send) 'ENTRY0(ENTRY1)' has been assigned to User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.10Password policy (user) unassigned from groupPassword policy (user) 'ENTRY0(ENTRY1)' has been unassigned from User group 'ENTRY2(ENTRY3)'.
1.3.6.1.4.1.7660.50.1.4.11Password policy (quick send) unassigned from groupPassword policy (quick send) 'ENTRY0(ENTRY1)' has been unassigned from User group 'ENTRY2(ENTRY3)'.

File Transfer (1.3.6.1.4.1.7660.50.1.5)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.5.1File uploadedFile 'ENTRY0' (ENTRY1 bytes) has been successfully uploaded.
1.3.6.1.4.1.7660.50.1.5.2File downloadedFile 'ENTRY0' (ENTRY1 bytes) has been successfully downloaded.
1.3.6.1.4.1.7660.50.1.5.3File deletedFile 'ENTRY0' (ENTRY1 bytes) has been successfully deleted.
1.3.6.1.4.1.7660.50.1.5.4Folder deletedFolder 'ENTRY0' has been successfully deleted.
1.3.6.1.4.1.7660.50.1.5.5File/Folder movedFile/Folder 'ENTRY0' has been successfully moved or renamed to 'ENTRY1'.
1.3.6.1.4.1.7660.50.1.5.6Folder createdFolder 'ENTRY0' has been successfully created.

Extension (1.3.6.1.4.1.7660.50.1.6)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.6.1Extension addedExtension 'ENTRY0' added.
1.3.6.1.4.1.7660.50.1.6.2Extension updatedExtension 'ENTRY0' updated.
1.3.6.1.4.1.7660.50.1.6.3Extension deletedExtension 'ENTRY0' deleted.
1.3.6.1.4.1.7660.50.1.6.4Extension assigned to a userExtension 'ENTRY0' assigned to the user 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.5Extension assigned to a user groupExtension 'ENTRY0' assigned to the user group 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.6Extension assigned to a communityExtension 'ENTRY0' assigned to the community 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.7Extension assigned to the applicationExtension 'ENTRY0' assigned to the application.
1.3.6.1.4.1.7660.50.1.6.8Extension unassigned from a userExtension 'ENTRY0' unassigned from the user 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.9Extension unassigned from a user groupExtension 'ENTRY0' unassigned from the user group 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.10Extension unassigned from a communityExtension 'ENTRY0' has been unassigned from the community 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.11Extension unassigned from the applicationExtension 'ENTRY0' has been unassigned from the application.
1.3.6.1.4.1.7660.50.1.6.12User extension updatedUpdate extension 'ENTRY0' of the user 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.13User group extension updatedUpdate extension 'ENTRY0' of the user group 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.14Community extension updatedUpdate extension 'ENTRY0' of the community 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.6.15Application extension updatedUpdate extension 'ENTRY0' of the application.

Authorization (1.3.6.1.4.1.7660.50.1.7)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.7.1Authorization errorAuthorization error for token 'ENTRY0'.

Component startup (1.3.6.1.4.1.7660.50.1.8)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.8.1Server startedServer 'ENTRY0' started.
1.3.6.1.4.1.7660.50.1.8.2Server stoppedServer 'ENTRY0' stopped.
1.3.6.1.4.1.7660.50.1.8.3Gateway startedGateway 'ENTRY0' started.
1.3.6.1.4.1.7660.50.1.8.4Gateway stoppedGateway 'ENTRY0' stopped.
1.3.6.1.4.1.7660.50.1.8.5Gateway keys renewalGateway keys renewal 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.8.6Web Client keys renewalWeb Client keys renewal 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.8.7Update licenseUpdate license 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.8.8Reset instance passwordReset instance password 'ENTRY0'.
1.3.6.1.4.1.7660.50.1.8.9Domain information updatedDomain 'ENTRY0(ENTRY1)' has been updated to 'ENTRY2(ENTRY3)'
1.3.6.1.4.1.7660.50.1.8.10Entity keys createdKeys (ENTRY0) created for entity 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.8.11Entity keys deletedKeys (ENTRY0) deleted for entity 'ENTRY1(ENTRY2)'.
1.3.6.1.4.1.7660.50.1.8.12File re-encryptedFile 'ENTRY0' (UUID=ENTRY1) has been re-encrypted.

Batch process (1.3.6.1.4.1.7660.50.1.9)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.9.1Batch process startedBatch process 'ENTRY0' started.
1.3.6.1.4.1.7660.50.1.9.2Batch process stoppedBatch process 'ENTRY0' stopped.

Integrity Check (1.3.6.1.4.1.7660.50.1.10)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.10.1Integrity check succeedIntegrity check succeeded.
1.3.6.1.4.1.7660.50.1.10.2Integrity check failedIntegrity check failed.

System Event Audit (1.3.6.1.4.1.7660.50.1.11)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.11.1Event auditing enabledEvent 'ENTRY0' auditing is enabled.
1.3.6.1.4.1.7660.50.1.11.2Event auditing disabledEvent 'ENTRY0' auditing is disabled.

Task (1.3.6.1.4.1.7660.50.1.12)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.12.1Task failedTask 'ENTRY0' failed. A backup of the task has been kept in the TASKFAILED table (id=ENTRY1).

Template (1.3.6.1.4.1.7660.50.1.13)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.13.1Template addedTemplate 'ENTRY0(ENTRY1)' added.
1.3.6.1.4.1.7660.50.1.13.2Template updatedTemplate 'ENTRY0(ENTRY1)' updated.
1.3.6.1.4.1.7660.50.1.13.3Template deletedTemplate 'ENTRY0(ENTRY1)' deleted.

Password Policy (1.3.6.1.4.1.7660.50.1.14)

OIDDescriptionMessage
1.3.6.1.4.1.7660.50.1.14.1Password policy addedPassword policy 'ENTRY0(ENTRY1)' added.
1.3.6.1.4.1.7660.50.1.14.2Password policy updatedPassword policy 'ENTRY0(ENTRY1)' updated.
1.3.6.1.4.1.7660.50.1.14.3Password policy deletedPassword policy 'ENTRY0(ENTRY1)' deleted.

Surveillance use case examples

This section describes a few example use cases that can be configured in a SIEM system around S-Filer audits.

Use CaseOIDMessageDetails
Brute force password1.3.6.1.4.1.7660.50.1.1.2Login failed for 'ENTRY0' at domain 'ENTRY1'. Reason: ENTRY2Aggregate entries in a time frame by user account
Password Spray1.3.6.1.4.1.7660.50.1.1.2Login failed for 'ENTRY0' at domain 'ENTRY1'. Reason: ENTRY2Aggregate entries in a time frame
Audit deactivation1.3.6.1.4.1.7660.50.1.11.2Event 'ENTRY0' auditing is disabled.As soon as entry is detected
Data exfiltration1.3.6.1.4.1.7660.50.1.5.2File 'ENTRY0' (ENTRY1 bytes) has been successfully downloaded.Anomaly detection with respect to normal usage globally or per user
Mass deletion1.3.6.1.4.1.7660.50.1.5.3File 'ENTRY0' (ENTRY1 bytes) has been successfully deleted.Anomaly detection with respect to normal usage globally
Suspicious activity1.3.6.1.4.1.7660.50.1.7.1Authorization error for token 'ENTRY0'.Aggregate entries in a time frame by user account

These cases relate to specific communities or groups.

CasOIDMessageDétails
Access granted to a sensitive community1.3.6.1.4.1.7660.50.1.3.4Assign member 'ENTRY0(ENTRY1)' to Community 'ENTRY2(ENTRY3)'.As soon as entry is detected
Access granted to a sensitive group1.3.6.1.4.1.7660.50.1.4.4Member 'ENTRY0(ENTRY1)' has been assigned to User group 'ENTRY2(ENTRY3)'.As soon as entry is detected