Audit Events
Audit events are tracked by Alteryx One Platform and captured in the audit trail.
Account Administration
Event | Description | Additional Metadata |
|---|---|---|
| A product has been enabled in a workspace as a result of a change to the contract. | |
| A product has been disabled in a workspace as a result of an expired contract. | |
| An API access token has been disabled as a result of an expired contract. | |
| 1 or more users have been assigned a role. | userIdsWithUnassignedSeat productPolicyId |
| Audit to cloud storage connection is created. | bucketName cloudStorageType (S3, Azure, GCS, etc) |
| Creation of a billing account. | billingAccountId billingAccount.getName() |
| Audit to cloud storage connection is deleted. | cloudStorageType (S3, Azure, GCS, etc) (if successful) bucketName |
| A product entitlement has been removed as a result of an expired contract. | productName productSKU |
| An API access token has been set up as a result of a contract change. | licenseBillingService |
| An attempt to assign 1 or more users a role was rejected because there were insufficient seats for a specific role. | productPolicyId userIdsWithUnassignedSeat |
| An attempt to assign 1 or more users a role was rejected because the users were already assigned the specified role. | productPolicyIduserIds |
| An attempt to assign 1 or more users a role was rejected because there were insufficient entitlements. | productPolicyIduserIds |
| An attempt to remove seats occurred, but it was not successful as there are no seats to be revoked. | removedProductPolicyIds removedUserIds |
| A product entitlement has been provisioned as a result of a change to the contract. | productName productSKU |
| An attempt to add assigned seats exceeded the contracted values and the seats causing overages have been revoked. | removedProductPolicyIds removedUserIds |
| Seats have been revoked. | removedProductPolicyIds removedUserIds |
| Audit to cloud storage connection is updated. | cloudStorageType (S3, Azure, GCS, etc) new: {
bucketName,
bucketRegion,
roleArn
}(if successful) old:
{
bucketName,
bucketRegion,
roleArn
} |
| A modification to the name of the billing account. | billingAccountId oldBillingAccountName newBillingAccountName |
| A modification to the number of effective entitlements. | oldEntitlementQuantity newEntitlementQuantity |
| A modification to the contract tier. | oldTierName newTierName workspaceName |
Workflow
Event | Description | Additional Metadata |
|---|---|---|
| Creating a new workflow. | assetId workflowName workflowMode |
| Importing workflow is complete. | assetId workflowName |
| Workflow is deleted. | assetId workflowName |
| Initiating Full Run execution for workflow. | assetId workflowName initiatedFrom |
| Workflow is exported. | assetId workflowName |
| Capturing any update to a workflow (when a new version was added for workflow). | assetId workflowName |
| Renaming workflow. | assetId oldWorkflowName newWorkflowName |
| Setting a name for specific workflow version. | assetId versionId versionName |
| Removing access for workflow. | assetId workflowName removedAccessUserId removedAccessUserEmail |
| Sharing access on workflow. | assetId workflowName shareeUserId shareeEmail permissionType |
Scheduling
Event | Description | Additional Metadata |
|---|---|---|
| Schedule data connection created. | asset_type asset_id(s) |
| Schedule created. | asset_type asset_id(s) |
| Schedule deleted. | asset_type asset_id(s) |
| Schedule disabled. | asset_type asset_id(s) |
| Schedule enabled. | asset_type asset_id(s) |
| Schedule modified. | asset_type asset_id(s) |
| Schedule data connection updated. | asset_type asset_id(s) |
Plans
Event | Description | Additional Metadata |
|---|---|---|
| Plan created. | assetId planName |
| Plan deleted | assetId planName |
| Email task added to a Plan. | assetId planName |
| HTTP task added to a Plan. | assetId planName |
| Recipients added/deleted from an email task (To, CC, BCC). | assetId planName |
| Configuration of an HTTP task in a plan edited. | assetId planName |
| Plan renamed. | assetId planName assetId initiatedFrom |
| Plan shared. As a successful event is considered only plan shared, not dependencies. | assetId planName shareeUserId shareeEmail permissionType |
| Plan exported. | assetId planName |
| Plan imported. | assetId planName |
| Plan ownership transferred to another user. | assetId planName planOldOwner planNewOwner |
| Output downloaded as part of a plan . | assetId planName |
Auto Insights
Event | Description | Additional Metadata |
|---|---|---|
| Mission created | name ulid |
| Mission sent | name ulid |
| Mission deleted | name ulid |
| Mission subscription created | name ulid |
| Mission subscription deleted | name ulid |
| Report created | name ulid |
| Report published | name ulid |
| Report sent | name ulid |
| Report downloaded | name ulid |
| Report deleted | name ulid |
| Report subscription created | name ulid |
| Report subscription deleted | name ulid |
| Generate list of Playbooks use cases from scenario. | aaiService, sessionID |
| Generate list of Playbooks Reports using synthetic data. | aaiService, reportID |
| Generate list of Playbooks Reports using Dataset X. | aaiService, reportID |
| Generate list of Playbooks use cases on Dataset X. | aaiService, sessionID |
身份验证
事件键 | 事件说明 | 其他元数据字段 |
|---|---|---|
| 用户 <userId> 在工作区|账户 <workspaceId>|<accountId> 中创建 OAuth 2.0 API 令牌。 | |
| 使用 <browser> 在位置 <location> 创建会话 <sessionId>。 | |
| 用户 <userId> 在工作区|账户 <workspaceId>|<accountId> 中创建访问令牌。 | |
| 创建用户 <email>。 | |
| 删除工作区|账户 <workspaceId>|<accountId> 中的 OAuth 2.0 API 令牌 <tokenId>。 | |
| 从工作区 <workspaceId>|<accountId> 中删除访问令牌 <tokenId>。 | |
| 已触发导出状态域重新扫描。 | emailDomain |
| 登录时,用户的导出状态已被重新扫描。 | exportStatus |
| 已触发导出状态重新扫描。 | |
| 用户的导出状态已由 Amber Road 事件更新。 | exportStatus、updatedStatus |
| 强制用户 <userId> 在登录时重置密码。 | |
| 重置用户 <userId> 的密码。 | |
| 撤销工作区|账户 <workspaceId>|<accountId> 中的 OAuth 2.0 API 令牌 <tokenId>。 | |
| 撤销用户 <userId> 的会话 <sessionId> 。 | |
| 为账户 <accountId> 创建 IP 列表。 | |
| 在工作区|账户 <workspaceId>|<accountId> 中创建 SSO 配置。 | |
| 在工作区|账户 <workspaceId>|<accountId> 中更新 SSO 配置。 | |
| 为账户 <accountId> 更新 IP 列表。 | existingIpAddresses、updatedIpAddresses |
| 更新用户 <userId> 的密码。 | |
| 更新用户 <userId>。 | |
| 验证电子邮件 <email> 的 OTP。 |
授权
事件键 | 事件说明 | 其他元数据字段 |
|---|---|---|
| 将角色 [roleId] 添加到用户组 [groupId]。 | 用户组对象、[user objects]、[role objects] |
| 将用户 [userGid] 添加到用户组 [groupId]。 | 用户组对象、[user objects]、[role objects] |
| <assets> 的所有权已转移至 PersonId-<PersonId> PersonEmail-<personEmail>。 | assets、toPersonId、toPersonEmail |
| 将角色 <roleId> 分配给工作区 <workspaceId> 中的用户 <userIds>。 | |
| 在工作区 <workspaceId> 中创建角色 <roleName>。 | |
| SCIM 连接已由用户 [email] 禁用。 | |
| 禁用工作区 <workspaceId> 中的用户 <personId>。 | |
| 在工作区 <workspaceId> 中启用用户 <personId>。 | |
| SCIM 令牌由用户 [email] 生成。 | |
| 邀请用户 <email> 加入工作区|账户 <workspaceId>|<accountId>。 | |
| 重新邀请用户 <personIds> 到账户 <workspaceId>|<accountId>。 | |
| 从用户组 [groupId] 中移除角色 [roleId]。 | group object]、[user objects]、[role objects] |
| 从用户组 [groupId] 中移除用户 [userGid]。 | group object]、[user objects]、[role objects] |
| 已从账户 <accountId> 中移除用户 <personIds>。 或 已从工作区 <workspaceId> 中移除用户 <personIds>。 | |
| 从工作区 <workspaceId> 中的用户 <userId> 取消分配角色 <roleId>。 | |
| 将用户 [email] 添加到用户组 [groupId]。 | |
| 从用户组 [groupId] 中移除用户 [email]。 | |
| SCIM 连接已由用户 [email] 启用。 | |
| 用户组显示名称已更改为 [name]。 | |
| 更新工作区 <workspaceId> 中的角色 <roleId>。 |
工作区管理
事件键 | 事件说明 | 其他元数据字段 |
|---|---|---|
| 为 billingAccountId <accountId> 创建名为 <name>,最大用户数为 <max_user_number> 的工作区。 或 为层级 <tier> 创建名为 <name>,最大用户数为 <max_user_number> 的工作区。 | |
| 删除工作区 <workspaceId>。 | |
| 已将 workspaceId <workspaceId> 和 billingAccountId <accountId> 的工作区详细信息名称更新为 <name>,最大用户数更新为 <maxUserNumber>。 | |
| 更新工作区 <workspaceId> 中的配置:<configurationName>。 | configurationName、configurationValue、workspaceName |