Skip to content
LogoLogScale DocumentationFull Library Knowledge Base Release Notes Integrations Query Examples Training API GraphQL API Contacting Support
help

Versions of this Page

    • LogScale System Repository Schema Guide
    • The humio Repository
      • Query data in the humio Repository
    • The humio-activity Repository
        • Action
        • Action/Action
        • AggregateAlert/Alert
        • AggregateAlert/Query
        • Alert/Action
        • Alert/Alert
        • Alert/Query
        • Fdr/Entity
        • Fdr/Ingest
        • FilterAlert/Alert
        • FilterAlert/Query
        • PermissionAssignment/groupAssignments
        • PermissionAssignment/numberOfGroups
        • PermissionAssignment/numberOfUsers
        • PermissionAssignment/userAssignments
        • PermissionAssignment/userPermissionCounts
        • Query
        • Request
        • ScheduledSearch/Action
        • ScheduledSearch/Query
        • ScheduledSearch/Schedule
        • ScheduledSearch/ScheduledSearch
        • SystemPrivilege/ChangeSystemPermission
        • SystemPrivilege/ManageOrganizations
      • Alert, Scheduled Search, and Scheduled Report Errors and Resolutions
    • The humio-audit Repository
      • Common humio-audit Structures
        • humio-audit Actor Structure
          • Query Actor Data
        • humio-audit Query Structure
      • humio-audit Event types
      • Examples of queries for humio-audit
    • The humio-fleet Repository
    • The humio-measurements Repository
    • The humio-metrics Repository
      • Node-Level Metrics
        • archiving-bytes-per-second Metric
        • archiving-errors-per-second Metric
        • archiving-latency-max-ms Metric
        • archiving-writes-per-second Metric
        • azure-storage-read Metric
        • azure-storage-write Metric
        • bucket-storage-download-memory-allocated Metric
        • bucket-storage-download-queue-free-slots Metric
        • bucket-storage-download-requests-cap-size-hits Metric
        • bucket-storage-fetch-for-query-queue Metric
        • bucket-storage-in-progress-downloads Metric
        • bucket-storage-in-progress-uploads Metric
        • bucket-storage-max-concurrent-archive-stream-operations Metric
        • bucket-storage-max-concurrent-delete-operations Metric
        • bucket-storage-max-concurrent-download-operations Metric
        • bucket-storage-max-concurrent-listfile-operations Metric
        • bucket-storage-max-concurrent-upload-operations Metric
        • bucket-storage-max-concurrent-upload-stream-operations Metric
        • bucket-storage-pending-upload Metric
        • bucket-storage-pending-upload-underreplicated Metric
        • bucket-storage-pending-work Metric
        • bucket-storage-request-upload Metric
        • bucket-storage-request-upload-queue-overflow Metric
        • bucket-storage-segment-downloads-in-progress Metric
        • bucket-storage-total-segment-size Metric
        • bucket-storage-upload-latency-max-ms Metric
        • bucket-transfer-manager-iteration-time Metric
        • chatter-reader-occupancy Metric
        • cluster-time-skew Metric
        • compact-timestamp-found Metric
        • completion-exception-counter Metric
        • compressed-bytes-only-present-in-bucket-storage Metric
        • compressed-bytes-underreplicated-ignoring-bucket-storage Metric
        • cross-query-builder-cache-hits Metric
        • cross-query-builder-cache-misses Metric
        • cross-query-builder-cache-size Metric
        • currently-running-streaming-queries Metric
        • day-month-year-timestamp-found Metric
        • digest-active-datasources Metric
        • digest-buffer-target-latency Metric
        • digest-event-deserialization-ms Metric
        • digest-live-latency Metric
        • digest-rate-per-cpu-second Metric
        • digest-record-deserialization-ms Metric
        • digest-segment-latency Metric
        • direct-memory-allocated Metric
        • dynamic-table-reference-controller-size-of-tables-in-use-by-queries Metric
        • elastic-search-ingestion-events-in-bulk Metric
        • elastic-search-ingestion-request-errors Metric
        • elastic-search-ingestion-requests Metric
        • event-collector-request-errors Metric
        • event-latency Metric
        • failed-http-checks Metric
        • federated-merge-latency-ms Metric
        • federated-poller-latency-ms Metric
        • federated-poller-session-count Metric
        • federated-query-count Metric
        • federated-wasted-merges Metric
        • gcs-storage-read Metric
        • gcs-storage-write Metric
        • global-allocations Metric
        • global-condition-index-hit Metric
        • global-condition-index-miss Metric
        • global-publish-wait-for-value Metric
        • global-reader-occupancy Metric
        • globalsnapshot-pct-of-max-heap Metric
        • globalsnapshot-size Metric
        • handle-bucket-download-tasks-latency Metric
        • handle-bucket-upload-tasks-latency Metric
        • hashfilter-included-blocks Metric
        • hashfilter-skipped-blocks Metric
        • http-requests Metric
        • http-requests-external-size Metric
        • http-requests-external-timing Metric
        • http-requests-internal-size Metric
        • http-requests-internal-timing Metric
        • humio-ingestion-request-errors Metric
        • ingest-bytes-total Metric
        • ingest-kafka-timeouts Metric
        • ingest-listener-tcp-available Metric
        • ingest-reader-occupancy Metric
        • ingest-reader-polltime Metric
        • ingest-request-delay Metric
        • ingest-request-time-ms Metric
        • ingest-writer-bulksize Metric
        • ingest-writer-compressed-bytes Metric
        • ingest-writer-jobs Metric
        • ingest-writer-queue-add Metric
        • ingest-writer-queue-empty Metric
        • ingest-writer-queue-full Metric
        • ingest-writer-threads Metric
        • ingest-writer-uncompressed-bytes Metric
        • internal-poll-rate Metric
        • internal-queryjobs-timing Metric
        • internal-throttled-poll-rate Metric
        • internal-throttled-poll-wait-time Metric
        • jvm-NON-heap-max-usage Metric
        • jvm-NON-heap-usage Metric
        • jvm-heap-usage Metric
        • jvm-heap-usage-percent Metric
        • jvm-hiccup-latency Metric
        • kafka-chatter-bytes Metric
        • kafka-chatter-put Metric
        • kafka-ingestqueue-put Metric
        • kafka-request-bytes Metric
        • kafka-request-events Metric
        • kafka-request-queue-fill-percentage Metric
        • lars-assets-cache-calls-to-get Metric
        • lars-assets-cache-calls-to-load Metric
        • lars-assets-cache-keys-size Metric
        • lars-assets-cache-values-size Metric
        • lars-get-table-diff-request-duration Metric
        • lars-get-table-diff-request-time-to-first-message Metric
        • lars-thread-pool-active-threads-count Metric
        • lars-thread-pool-queue-size Metric
        • lars-thread-pool-queue-wait-time Metric
        • live-dashboard-query-count Metric
        • livequeries-canceled-due-to-digest-delay Metric
        • livequeries-rate Metric
        • livequeries-rate-canceled-due-to-digest-delay Metric
        • livequery-count Metric
        • load-segment-total Metric
        • local-query-jobs-queue Metric
        • local-query-jobs-queue-exports-part Metric
        • local-query-jobs-wait Metric
        • local-query-segments-queue Metric
        • local-query-segments-queue-exports-part Metric
        • logplex-ingestion-request-errors Metric
        • lookup-tables-loading-tasks Metric
        • lookup-tables-number-of-files Metric
        • lookup-tables-number-of-index-structures Metric
        • lookup-tables-number-of-lookup-tables Metric
        • lookup-tables-number-of-queries Metric
        • lookup-tables-size-of-cached-files Metric
        • mapsegment Metric
        • max-ingest-delay Metric
        • min-ingest-timestamp Metric
        • min-unacked-ingest-timestamp Metric
        • mini-segment-created Metric
        • minisegment-blocks Metric
        • minisegment-compressed-size Metric
        • minisegment-merge-cpu-time Metric
        • minisegment-uncompressed-size Metric
        • missing-cluster-nodes Metric
        • missing-cluster-nodes-stateful Metric
        • mitre-annotation-exact-match-uses Metric
        • mitre-annotation-featurecheck-rejection-ratio Metric
        • mitre-annotation-instruction-evaluations Metric
        • mitre-annotation-rate Metric
        • mitre-annotation-read-field-uses Metric
        • mitre-annotation-regex-check-uses Metric
        • mitre-annotation-time Metric
        • mitre-annotation-useless-featuresets-ratio Metric
        • month-day-year-last-timestamp-found Metric
        • month-day-year-timestamp-found Metric
        • primary-disk-usage Metric
        • proxied-query-polls Metric
        • queries Metric
        • query Metric
        • query-compiler-mapper-task-time Metric
        • query-compiler-parse-time Metric
        • query-compiler-preprocess-time Metric
        • query-coordinator-latency Metric
        • query-delta-total-cost Metric
        • query-delta-total-memory-allocation Metric
        • query-deserialization-bytes Metric
        • query-deserialization-tasks Metric
        • query-fsm-snapshot-refresh-time Metric
        • query-live-delta-cpu-usage Metric
        • query-result-calculation-latency-ms Metric
        • query-segments-count Metric
        • query-segments-count-from-remote Metric
        • query-static-cost-cache-hit Metric
        • query-static-cost-cache-miss Metric
        • query-static-cost-total Metric
        • query-static-delta-cpu-usage Metric
        • query-thread-limit Metric
        • query-time-spent-starved-waiting-for-bucket-storage-avg Metric
        • query-time-spent-starved-waiting-for-bucket-storage-max Metric
        • query-worker-queue-full Metric
        • querycache-disk-usage Metric
        • querycache-max-age Metric
        • read-compressed-bytes Metric
        • read-prefilter-bytes Metric
        • reader-buffer-state-latency-ms Metric
        • recompress-millis Metric
        • reversedns-cache-evictions Metric
        • reversedns-cache-lookups Metric
        • reversedns-cache-misses Metric
        • reversedns-highest-concurrent-requests Metric
        • reversedns-time-spend-on-external-calls Metric
        • reversedns-time-spend-waiting Metric
        • s3-aws-bucket-available-concurrency Metric
        • s3-aws-bucket-concurrency-acquire-duration Metric
        • s3-aws-bucket-leased-concurrency Metric
        • s3-aws-bucket-max-concurrency Metric
        • s3-aws-bucket-pending-concurrency-acquires Metric
        • s3-storage-read Metric
        • s3-storage-write Metric
        • schedulesegments Metric
        • secondary-disk-usage Metric
        • segment-changes-job-trigger-full-global-scan-counter Metric
        • segment-entity-compact Metric
        • segment-entity-full Metric
        • segment-fetch-requested-but-already-in-progress Metric
        • segment-fetch-requested-but-upstream-has-been-deleted Metric
        • segment-fetching-trigger-queue-hit-full-after-global-scan-counter Metric
        • segment-fetching-trigger-queue-hit-full-counter Metric
        • segment-fetching-trigger-queue-offer-counter Metric
        • segment-fetching-trigger-queue-offer-from-global-scan-counter Metric
        • segment-fetching-trigger-queue-retry-offer-counter Metric
        • segment-fetching-trigger-queue-size Metric
        • segment-merge-cpu-time Metric
        • segment-merge-latency-ms Metric
        • segment-merger-threads Metric
        • segment-validator-threads Metric
        • serialize-state-bytes Metric
        • serialize-state-time Metric
        • start-new-bucket-tasks-latency Metric
        • table-cache-calls-to-get Metric
        • table-cache-calls-to-load Metric
        • table-cache-calls-to-put Metric
        • table-cache-disk-usage Metric
        • table-cache-number-of-cached-tables-on-Disk Metric
        • table-cache-reads-from-disk Metric
        • table-cache-writes-to-disk Metric
        • table-coordinator-calls-to-getTableFromCluster Metric
        • table-coordinator-calls-to-getTableFromNode Metric
        • table-coordinator-calls-to-hasTableOnCluster Metric
        • table-coordinator-calls-to-hasTableOnNode Metric
        • table-coordinator-calls-to-putTableOnCluster Metric
        • table-coordinator-calls-to-putTableOnNode Metric
        • table-coordinator-calls-to-putTableOnRemoteCluster Metric
        • table-registry-number-of-queries Metric
        • tables-loading-parser-tasks Metric
        • target-segment-blocks Metric
        • target-segment-compressed-size Metric
        • target-segment-created Metric
        • target-segment-uncompressed-size Metric
        • temp-disk-usage-bytes Metric
        • time-digest Metric
        • time-livequery Metric
        • time-only-timestamp-found Metric
        • timestamp-parsing-failed Metric
        • unix-epoch-timestamp-found Metric
        • uploaded-files-cache-entries Metric
        • user-permissions-lookup Metric
        • user-permissions-lookup-cache-miss Metric
        • written-events-after-queue Metric
        • year-month-day-timestamp-found Metric
      • Object-Level Metrics
        • actions Metric
        • auxiliary-service-availability Metric
        • check-permission Metric
        • create-requester-time Metric
        • data-ingester-errors Metric
        • data-ingester-parser-errors Metric
        • datasource-count Metric
        • entity-store-operation-rate Metric
        • event-forwarding-errors Metric
        • event-forwarding-events Metric
        • event-forwarding-kafka-egress-enabled Metric
        • event-forwarding-logscale-disabled Metric
        • event-latency-partition Metric
        • event-latency-repo Metric
        • events-enriched Metric
        • events-parsed Metric
        • external-ingest-delay Metric
        • fdr-inflight-message-count Metric
        • fdr-ingest-events Metric
        • fdr-message-count Metric
        • find-timestamp-failed Metric
        • garbage-collection-time Metric
        • global-operation-rate Metric
        • global-operation-time Metric
        • ingest-bytes Metric
        • ingest-consumer-group-offset Metric
        • ingest-consumer-group-offset-lag Metric
        • ingest-eventsize Metric
        • ingest-offset-lowest Metric
        • ingest-parsing Metric
        • ingest-parsing-allocation Metric
        • ingest-queue-consumer Metric
        • ingest-queue-latency Metric
        • ingest-queue-lowest-offset-lag Metric
        • ingest-queue-read-offset Metric
        • ingest-queue-write-offset Metric
        • ingest-reader-occupancy Metric
        • ingest-reader-partition-bytes Metric
        • ingest-reader-partition-events Metric
        • ingest-writer-partition-bytes Metric
        • kafka-chatter-by-kind-bytes Metric
        • kafka-chatter-by-kind-serialize Metric
        • lars-job-elapsed-time Metric
        • lars-resolve-assets-calls Metric
        • lars-resolve-assets-request-duration Metric
        • lars-resolve-assets-request-including-deserialization-duration Metric
        • lars-resolve-assets-request-time-to-first-asset Metric
        • live-events Metric
        • losable-node-count-before-storage-over-capacity Metric
        • no-timestamp-found Metric
        • no-timezone-found Metric
        • parser-cache-added Metric
        • parser-cache-removed Metric
        • parser-compilation-success Metric
        • parser-compilation-time Metric
        • query-delta-cost Metric
        • query-millis Metric
        • repo-queries Metric
        • s3-aws-bucket-retry-count Metric
        • tcp-ingest-bytes Metric
        • thread-pool-occupancy Metric
        • thread-pool-queue-size Metric
        • udp-ingest-bytes Metric
        • written-events Metric
      • Example queries
    • The humio-usage Repository
      • humio-organization-usage View
Falcon LogScale Documentation
/ LogScale System Repository Schema Guide
/ The humio-audit Repository
/ humio-audit Event types

Audit Log Event organizations.users

Organization users have been updated

Field TypeTypeValueAvailabilityDescription
actionNameString   The name of the action, for example create, delete or update
actorActorType   Actor, as defined in humio-audit Actor Structure
organizationIdString   Organization ID
sensitiveBoolean   Whether the audited event is marked sensitive
targetUserInfo   Target for permissions
timestampZonedDateTime   Timestamp of the audited event
Support
  • Twitter
  • LinkedIn
  • Youtube

© 2025 CrowdStrike All other marks contained herein are the property of their respective owners.

  • Other articles on this topic

    • General information about triggers
    • Organization Query Monitor (Cloud)
    • Organization Query Monitor (Self-Hosted)
    • Understanding Your Organization (Cloud)
    • Understanding Your Organization (Self-Hosted)
  • Security Audit Entries

    • Audit Log Event action
    • Audit Log Event flushingstate.org.update
    • Audit Log Event limit.delete
    • Audit Log Event org.datasources.import
    • Audit Log Event org.metadata.import.rollback
    • Audit Log Event org.metadata.import
    • Audit Log Event org.segments.import
    • Audit Log Event organization.userdefaults.update
    • Audit Log Event organizations.link.unlink.child
    • Audit Log Event organizations.link.unlink
    • Audit Log Event organizations.subscription.change
    • Audit Log Event organizations.transfer.user
    • Audit Log Event organizations.update.foreignkey
    • Audit Log Event organizations.users.batch
    • Audit Log Event organizations
    • Audit Log Event sessions.change.config
    • Audit Log Event subdomain.remove
    • Audit Log Event subdomain.set

Enter search term