Activity tracking events for Security and Compliance Center
IBM Cloud services, such as IBM Cloud® Security and Compliance Center, generate activity tracking events.
Activity tracking events report on activities that change the state of a service in IBM Cloud. You can use the events to investigate abnormal activity and critical actions and to comply with regulatory audit requirements.
You can use IBM Cloud Activity Tracker Event Routing, a platform service, to route auditing events in your account to destinations of your choice by configuring targets and routes that define where activity tracking events are sent. For more information, see About IBM Cloud Activity Tracker Event Routing.
You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.
As of 28 March 2024, the IBM Cloud Activity Tracker service is deprecated and will no longer be supported as of 30 March 2025. Customers will need to migrate to IBM Cloud Logs before 30 March 2025. During the migration period, customers can use IBM Cloud Activity Tracker along with IBM Cloud Logs. Activity tracking events are the same for both services. For information about migrating from IBM Cloud Activity Tracker to IBM Cloud Logs and running the services in parallel, see migration planning.
Locations where activity tracking events are generated
Security and Compliance Center generates activity tracking events to IBM Cloud Activity Tracker hosted event search in the regions that are indicated in the following table.
Dallas (us-south ) |
Washington (us-east ) |
Toronto (ca-tor ) |
Sao Paulo (br-sao ) |
---|---|---|---|
Yes | No | Yes | No |
Tokyo (jp-tok ) |
Sydney (au-syd ) |
Osaka (jp-osa ) |
Chennai (in-che ) |
---|---|---|---|
No | No | No | No |
Frankfurt (eu-de ) |
London (eu-gb ) |
Madrid (eu-es ) |
---|---|---|
Yes | No | Yes |
Locations where activity tracking events are sent by IBM Cloud Activity Tracker Event Routing
Security and Compliance Center sends activity tracking events by IBM Cloud Activity Tracker Event Routing in the regions that are indicated in the following table.
Dallas (us-south ) |
Washington (us-east ) |
Toronto (ca-tor ) |
Sao Paulo (br-sao ) |
---|---|---|---|
Yes | No | Yes | No |
Tokyo (jp-tok ) |
Sydney (au-syd ) |
Osaka (jp-osa ) |
Chennai (in-che ) |
---|---|---|---|
No | No | No | No |
Frankfurt (eu-de ) |
London (eu-gb ) |
Madrid (eu-es ) |
---|---|---|
Yes | No | Yes |
Enabling activity tracking events for Security and Compliance Center
You must use a paid plan for the IBM Cloud Activity Tracker Event Routing service to see events for Security and Compliance Center.
Viewing activity tracking events for Security and Compliance Center
You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.
Launching IBM Cloud Logs from the Observability page
For information on launching the IBM Cloud Logs UI, see Launching the UI in the IBM Cloud Logs documentation.
List of events
Action | Description |
---|---|
compliance.posture-management-profiles.list |
An event is generated when a user lists all of the available profils. |
compliance.posture-management-profiles.create |
An event is generated when a user creates a profile. |
compliance.posture-management-profiles.read |
An event is generated when a user views the details of a profile. |
compliance.posture-management-profiles.update |
An event is generated when a user updates a profile. |
compliance.posture-management-profiles.delete |
An event is generated when a user deletes a profile. |
compliance.posture-management-profiles-attachments.list |
An event is generated when a user views the attachments related to a specific profile. |
compliance.posture-management-profiles-attachments.create |
An event is generated when a user creates a new attachment. |
compliance.posture-management-profiles-attachments.read |
An event is generated when a user views the details of an attachment. |
compliance.posture-management-profiles-attachments.update |
An event is generated when a user updates an attachment. |
compliance.posture-management-profiles-attachments.delete |
An event is generated when a user deletes an attachment. |
compliance.posture-management-profiles-attachments-parameters.list |
An event is generated when a user views the parameters that are associated with a profile attachment. |
compliance.posture-management-profiles-attachments-parameters.create |
An event is generated when a user sets a parameter variable for an attachment. |
compliance.posture-management-profiles-attachments-parameters.read |
An event is generated when a user views the parameter details. |
compliance.posture-management-profiles-attachments-parameters.update |
An event is generated when a user updates a parameter value for an attachment. |
compliance.posture-management-control-libraries.list |
An event is generated when a user views the available control libraries in your account. |
compliance.posture-management-control-libraries.create |
An event is generated when a user creates a new control library. |
compliance.posture-management-control-libraries.read |
An event is generated when a user views the details of a control library. |
compliance.posture-management-control-libraries.update |
An event is generated when a user updates a control library. |
compliance.posture-management-control-libraries.delete |
An event is generated when a user deletes a control library. |
compliance.posture-management-scans.create |
An event is generated when a user initiates a scan. |
compliance.posture-management-reports.list |
An event is generated when a user views all available results. |
compliance.posture-management-reports.create |
An event is generated when a user generates a new report. |
compliance.posture-management-reports.read |
An event is generated when a user views detailed results. |
compliance.posture-management-reports.delete |
An event is generated when a user deletes results. |
compliance.posture-management.integrations-create |
An event is generated when a user creates an instance of a provider. |
compliance.posture-management.integrations-read |
An event is generated when a user lists all providers. |
compliance.posture-management.integrations-update |
An event is generated when a user removes a provider. |
compliance.posture-management.integrations-delete |
An event is generated when a user updates an instance of a specific provider. |
compliance.configuration-governance-rules.list |
An event is generated when a user views the available rules in Security and Compliance Center. |
compliance.configuration-governance-rules.create |
An event is generated when a user creates a new rule. |
compliance.configuration-governance-rules.read |
An event is generated when a user views the details of a rule. |
compliance.configuration-governance-rules.update |
An event is generated when a user updates a rule. |
compliance.configuration-governance-rules.delete |
An event is generated when a user deletes a rule. |
compliance.admin-settings.list |
An event is generated when a user views Security and Compliance Center settings for your account. |
compliance.admin-settings.update |
An event is generated when a user updates Security and Compliance Center settings for your account. |
compliance.admin-test-event.send |
An event is generated when a user sends a test event to a connected Event Notifications service instance. |