The humio-activity Repository
The humio-activity repository contains information about operations and activities, including debug, error, and informational messages which are relevant to users and organizations.
Basic Structure
Events within humio-activity contain a record of the specific activities across the LogScale cluster. Events within the repository contain:
Timestamp of the activity.
Category, which defines the category of the event, such as Request, Query, Alert, ScheduledSearch, and so on.
Severity, which indicates the seriousness of the event and whether action may be required.
Event-specific information, for example, for a scheduled search, the scheduled search name and ID.
Metadata about the event, such as the subcategory of the event, username, used ID, and so on.
The table below shows the category and corresponding subcategory of events shown in the humio-activity repository.
Category | Sub-Category | Availability | Description | Functionality |
---|---|---|---|---|
Action | Event for an action | |||
AggregateAlert | Alert | |||
AggregateAlert | Query | |||
Alert | Action | Event for an action from an alert | ||
Alert | Alert | Event for an alert | ||
Alert | Query | |||
Fdr | Entity | |||
Fdr | Ingest | Event for FDR ingest | ||
FilterAlert | Alert | Alert event for a filter alert | ||
FilterAlert | Query | Event for a query as part of a filter alert | ||
PermissionAssignment | groupAssignments | |||
PermissionAssignment | numberOfGroups | |||
PermissionAssignment | numberOfUsers | |||
PermissionAssignment | userAssignments | |||
PermissionAssignment | userPermissionCounts | |||
Query | Event for a query | |||
Request | Event for an ingest request | |||
ScheduledSearch | Action | Event for actions from a scheduled search | ||
ScheduledSearch | Query | Event for a query that is part of a scheduled search | ||
ScheduledSearch | Schedule | Event for schedule of a scheduled search | ||
ScheduledSearch | ScheduledSearch | Event for a scheduled search | ||
SystemPrivilege | ChangeSystemPermission | Event for user permissions change | ||
SystemPrivilege | ManageOrganizations | Event for organization permissions |