Audit log

This page includes:

About the audit log

You can view the FortiMail Workspace Security audit log. The audit log lets you see what actions were performed by your admin users - and by the FortiMail Workspace Security IR Team - in FortiMail Workspace Security, in your organization. Some actions that are performed by the system - with a System label - are also recorded in the Audit log. The audit log includes actions such as changing a verdict, previewing an email, and viewing a screenshot. Transparency is important to Fortinet. The audit log enhances transparency by enabling you to see the actions that were performed on the data in your organization.

  • You can use the filter feature in the audit log to show all the actions that include the specified text in the Description or Action columns of the Audit log. For example, you could look for events performed by a specific user, "John".

  • Data retention: Data in the audit log is maintained for 180 days.

The Audit Log page is available to admin users with the "Administrator" role only.

[See Admin-User Role Permissions]

Showing the audit log

To show an audit log:

  1. In FortiMail Workspace Security, in the left navigation menu, select Security Operations > Audit Log.

    All actions that were performed in the last day will be shown.

  2. Use the Date Range selector and the Search feature [see below] to change the list of displayed actions.

Searching the audit log

When you use the Search functionality to filter the log entries that are displayed, the following fields are included in the search:

  • Action

  • Description

  • Admin

Downloading the audit log

You can download the audit log - in csv format. This is typically done for investigation purposes. The downloaded file will include all events and data currently displayed in the audit log - based on the current Date Range and Search settings.

Note:

  • In the downloaded CSV files, all dates and times are in UTC format. This can't be changed. Times may therefore differ from the times that appear in the UI of the Audit Log page.

  • You can include a maximum of 5,000 events in any download of the audit log.

To download the audit log:

  1. In FortiMail Workspace Security, in the left navigation menu, select Security Operations > Audit Log.

  2. Use the Date Range selector and the Search feature to change the list of displayed actions.

  3. Click Download CSV - in the top-right corner.

Action types

Below are the available action-types that may appear in the audit log, in alphabetic order.

Note:

  • The action types will appear slightly modified in the Audit log in FortiMail Workspace Security. For example, export-scans will appear as Export Scans.

  • When filtering the Audit log entries that are displayed, it is recommended that you use the versions of the action types as they appear in the table below [and not as they appear in the UI].

 

Available action types

 

  1. acronis-login

  2. acronis-user-created

  3. add-screenshot-to-blacklist

  4. analyze-sample

  5. changes-monitor

  6. contarct-alert

  7. copy-scan-to-demo

  8. create-new-organization-domain

  9. delete-email-from-inbox

  10. delete-user

  11. disable-decision

  12. django-admin

  13. download-scans

  14. download-scan-sample

  15. enable-decision

  16. export-scans

  17. handle-case

  18. handle-event

  19. handle-scan

  20. highlight-scan

  21. login

  22. logout

  23. malicious-file-reported-by-endpoint,30

  24. modify-user

  25. organization-change-audit

  26. organization-created

  1. organization-domain-deleted

  2. organization-mailboxes-billing-method-changed

  3. organization-number-of-mailboxes-changed

  4. organization-number-of-seats-changed

  5. organization-seats-billing-method-changed

  6. organization-organization-name-changed

  7. organization-organization-type-changed

  8. organization-was-changed-on-organization-domain

  9. protected-user-added

  10. protected-user-changed

  11. protected-user-deleted

  12. release-email

  13. report-sent

  14. request-investigation

  15. rescan

  16. resend-email

  17. resend-user-invitation

  18. saml-token-created

  19. send-user-invitation

  20. setup-email

  21. settings-add

  22. settings-change

  23. settings-delete

  24. update-smtp-record

  25. watch-scan-screenshots