Resmo Documentation
SupportStatuspageTwitterLinkedIn
  • Welcome!
  • Getting Started
    • Quick Start Guide for Admins
    • SaaS Security Guide for Employees
    • Glossary
    • FAQ
    • Support
    • Resources documentation (automated)
  • Guides
    • Query Your First Resources
    • Create Your First Rule
  • Resources
    • Resources
    • Resource Changes
  • Notebooks
    • Notebooks
  • Audit Logs
    • Audit Logs
  • API
    • Basics
    • Query API
  • Resource Tags
    • Tag Rules
    • Manual Tagging
  • Queries
    • Query Types
    • Standard SQL Queries
    • Change SQL Queries
  • SaaS Discovery
    • SaaS Discovery Methods
    • Browser Extension Admin Guide
    • AI Email Scanning
    • Resmo Agent (Beta)
    • Apps Page
    • Users Page
  • Rules
    • Rules
    • Suppression
    • AWS Config Rules vs Resmo Rules
  • Dashboards
    • Dashboards
  • Packs (Compliance and Security Best Practices)
    • Packs
    • Pack Exports
  • Alerts
    • Alerts
  • Variables
    • Variables
  • integrations
    • Integrations Guide
    • Custom Data Integration
    • AWS Integration
    • Azure Integration
    • GCP Integration
    • Google Drive Integration
    • Kubernetes Integration
    • Google Workspace Integration
    • GitHub Integration
    • Slack Integration
    • GitLab Integration
    • New Relic Integration
    • Jira Integration
    • PagerDuty Integration
    • Opsgenie Integration
    • MongoDB Atlas Integration
    • Azure Active Directory Integration
    • Cloudflare Integration
    • Confluence Integration
    • Bitbucket Integration
    • Okta Integration
    • Datadog Integration
    • Gandi Integration
    • Snyk Integration
    • Duo Integration
    • Jamf Integration
    • Snowflake Integration
    • Heroku Integration
    • Fastly Integration
    • Hubspot Integration
    • BambooHR Integration
    • Azure DevOps Integration
    • Kolide Integration
    • Flyio Integration
    • Upstash Integration
    • Qualys Integration
    • Sentry Integration
    • Brex Integration
    • JumpCloud Integration
    • Webflow Integration
    • Tenable Integration
    • SonarCloud Integration
    • Salesforce Integration
    • LastPass Integration
    • Microsoft Teams Integration
    • Zendesk Integration
    • Segment Integration
    • Terraform Cloud Integration
    • Tailscale Integration
    • Vercel Integration
    • GoDaddy Integration
    • Kandji Integration
    • LaunchDarkly Integration
    • PlanetScale Integration
    • Zoom Integration
    • Jotform Integration
    • Auth0 Integration
    • Wizer Integration
    • Linear Integration
    • Figma Integration
    • Trello Integration
    • Mixpanel Integration
    • Trivy Integration
    • CSV Integration
    • DocuSign Integration
    • Tinybird Integration
    • MonoSign Integration
    • DigitalOcean Integration
    • Sophos Integration
    • Firebase Integration
    • MySQL Integration
    • PostgreSQL Integration
    • MongoDB Integration
    • ClickHouse Integration
    • Help Scout Integration
    • Intercom Integration
    • Atlassian Integration
    • Drata Integration
    • Hetzner Cloud Integration
    • Vanta Integration
    • Microsoft Intune Integration
    • Microsoft Defender Integration
    • Microsoft 365 Integration
    • NPM Integration
    • CrowdStrike Integration
    • 1Password Integration
    • Lucid Integration
    • OneDrive Integration
    • JetBrains Integration
    • Google Analytics Integration
    • Hexnode Integration
    • SendGrid Integration
    • WordPress Integration
  • Notifications
    • Notification Channels
    • Email Notification Channel
    • Slack Notification Channel
    • Webhook Notification Channel
    • Opsgenie Notification Channel
    • PagerDuty Notification Channel
    • Amazon SNS Notification Channel
    • Parny Notification Channel
    • Linear Notification Channel
    • Jira Notification Channel
    • Microsoft Teams Notification Channel
  • Plugins
    • Raycast
  • Users and Permissions
    • User
    • User Roles
    • RBAC (Role-Based Access Control)
      • Custom Roles and Policies
    • SSO - Social Login
  • Settings
    • Accounts
    • Billing Policy
    • Pricing
      • Resource Count Calculation
Powered by GitBook
On this page
  • What is audit logging?
  • Basic features of Resmo Audit Logs
  • How do Audit Logs work?
  • Current list of integrations that support Audit Logs

Was this helpful?

  1. Audit Logs

Audit Logs

Monitor system activities and changes by reviewing audit logs

What is audit logging?

Audit logging, also referred to as an audit trail, is a security-relevant chronological record or set of records that provide documentary evidence of the sequence of activities that have affected at any time a specific operation, procedure, or event. Audit logs typically serve to document what activities were performed, when they were performed, and by whom.

These logs are crucial in various fields, especially in IT, where they are used to:

  • Track changes to the system

  • Detect anomalies or security incidents

  • Troubleshoot issues

  • Support forensic investigations.

Audit logging is critical to cybersecurity, enabling organizations to detect, prevent, mitigate, and trace back security threats.

Audit logs capture the following types of activity information:

  • Activity dates

  • Activity types

  • Actions

  • Actors

  • Locations

Basic features of Resmo Audit Logs

  • Detailed log entries: Every log entry includes thorough details such as timestamps, event descriptions, event types, and the identities of the users or systems involved.

  • Centralized logging: Collect all logs in one place for easy access and analysis.

  • Real-time monitoring: Real-time tracking of events to promptly detect and respond to potential security incidents.

  • Activity Graph: Visually monitor all activities and track system events in a specific time period with an activity graph. Group activities based on activity type, integration, action type, and actor.

  • Log integrity: Once logs are recorded, they can't be modified or deleted.

  • Search and filter: Search logs and filter them based on various attributes, such as activity type, action, actor, and integration.

How do Audit Logs work?

Initially, Resmo polls the added integration's audit logs to maintain retention for each supported integration in your account. Once the initial polling is completed, we implement smart polling to retrieve real-time updates. If the integration supports webhook events for audit logs, Resmo also listens for them.

  • Set a time range: You can set a specific time range from the top right to see all activities and events that happened during that period.

  • Group by: The Group by button allows you to group activities based on Activity Type, Integration, Action Type, and Actor to better visualize your activity data on the graph.

  • Search bar: Search your audit logs to quickly find what you're looking for.

  • Filters: Filter all activities and system events based on Integrations, Actors, Activities, and Actions. You can click the "X" on each set filter to turn it off.

  • Each activity row is clickable. If you click on an activity row, it will show you detailed information such as an IP address, and the result of an action, i.e., success, category, and metadata.

Current list of integrations that support Audit Logs

Integrations supporting Resmo Audit Logs

Office 365

PreviousNotebooksNextBasics

Last updated 1 year ago

Was this helpful?

Atlassian Access
Cloudflare
Okta
Opsgenie
Google Workspace
JumpCloud
Azure Active Directory