Audit Log Event scheduled-search.create

A scheduled search has been created

This audit log type records operations for the following features:

Field TypeTypeAvailabilityDescription
actionIdsList[String]  List of action IDs
actorActorType  Actor, as defined in humio-audit Actor Structure
backfillLimitInt  Configured backfill limit
descriptionOption[String]  Description of the entity of object
enabledBoolean  Whether the entity has been enabled or not
queryString  Query string
queryEndString  End of the query span for running the search
queryOwnershipQueryOwnershipInfo  Owner information for query
queryStartString  Duration of when the query should start
repoIdString  ID of the repository
repoNameString  Name of the repository
scheduleString  Schedule
scheduledSearchIdString  Scheduled search ID
scheduledSearchNameString  Name of the scheduled search
sensitiveBoolean  Whether the audited event is marked sensitive
timestampZonedDateTime  Timestamp of the audited event
timezoneString  Time zone

For example (as JSON):

json
{
   "actionIds" : [],
   "actor" : {
      "ip" : "172.17.0.1",
      "orgRoot" : true,
      "organizationId" : "SINGLE_ORGANIZATION_ID",
      "proxyRequest" : false,
      "sessionId" : "9U1FuFGIiB0F87CvhD8j1dGlV2RleEDi",
      "type" : "orgUser",
      "user" : {
         "id" : "0O7WGPBX9YbvZbKOrBMd5fgH",
         "isRoot" : true,
         "username" : "mc"
      }
   },
   "backfillLimit" : 0,
   "description" : "",
   "enabled" : true,
   "query" : "type=\"ERROR\"",
   "queryEnd" : "now",
   "queryOwnership" : {
      "type" : "Organization"
   },
   "queryStart" : "24h",
   "repoId" : "dm5BIUWUq1NsbMxCyb1iT5EH",
   "repoName" : "humio-audit",
   "schedule" : "0 * * * *",
   "scheduledSearchId" : "U9ZW9zOdsVsbqx4hfGTMQ2V5yIrxtaWM",
   "scheduledSearchName" : "SecCheck",
   "sensitive" : true,
   "timestamp" : "2023-12-18T12:34:53.91Z",
   "timezone" : "UTC+00:00",
   "type" : "scheduled-search.create"
}