Navigation
This version of the documentation is archived and no longer supported. To learn how to upgrade your version of MongoDB Ops Manager, refer to the upgrade documentation.
You were redirected from a different version of the documentation. Click here to go back.

Audit Events

Ops Manager maintains an audit log of key operations that users and administrators perform in the system. Unless otherwise stated, the Events page aggregates and displays these events. You can access the Events page through the Admin link.

User Audits

JOINED_GROUP

A user joined a Group.

This audit is not supported if using LDAP authentication for Ops Manager users

REMOVED_FROM_GROUP

A user was removed from a Group.

INVITED_TO_GROUP

A user was invited to a Group

MULTI_FACTOR_AUTH_RESET_EMAIL_SENT_AUDIT

MULTI_FACTOR_AUTH_RESET_EMAIL_SENT_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user requested and was sent an email with a link that will allow them to reset their 2 factor authentication.

MULTI_FACTOR_AUTH_RESET_AUDIT

MULTI_FACTOR_AUTH_RESET_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user reset their two factor authentication.

MULTI_FACTOR_AUTH_UPDATED_AUDIT

MULTI_FACTOR_AUTH_UPDATED_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user updated their 2FA using the form in My Profile.

PASSWORD_RESET_EMAIL_SENT_AUDIT

PASSWORD_RESET_EMAIL_SENT_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user requested and was sent an email with a link that will allow them to reset their password.

PASSWORD_RESET_AUDIT

PASSWORD_RESET_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user successfully reset their password via the reset password flow.

PASSWORD_UPDATED_AUDIT

PASSWORD_UPDATED_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user successfully updated their password using the form in My Profile.

USER_EMAIL_ADDRESS_CHANGED_AUDIT

USER_EMAIL_ADDRESS_CHANGED_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user changed their email address.

USER_ROLES_CHANGED_AUDIT

A user’s roles in a particular Group were changed.

SUCCESSFUL_LOGIN_AUDIT

SUCCESSFUL_LOGIN_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user successfully authenticated with their username and password.

UNSUCCESSFUL_LOGIN_AUDIT

UNSUCCESSFUL_LOGIN_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A user entered a valid username, but an invalid password.

ACCOUNT_LOCKED_AUDIT

Ops Manager locked a user’s account from the system, as a result of manual action by the administrator, or because of a change in account locking policies.

ACCOUNT_UNLOCKED_AUDIT

An administrator unlocked a user’s account.

USER_CREATED_AUDIT

USER_CREATED_AUDIT is only visible in the Admin section in the General tab on the Audits page.

A new user was created.

Host Audits

DELETE_HOST_AUDIT

A host was suppressed by a user.

ADD_HOST_AUDIT

A new host was added by a user, or auto-discovered by the system.

UNDELETE_HOST_AUDIT

A previously suppressed host was un-suppressed by a user.

HIDE_AND_DISABLE_HOST_AUDIT

The system determined that a host was a duplicate by the system, and hid that host from the interface.

DB_PROFILER_ENABLE_AUDIT

Database profiling was enabled for a host

DB_PROFILER_DISABLE_AUDIT

Database profiling data collection was disabled for a host

HOST_IP_CHANGED_AUDIT

A change in IP address was detected for a host.

Alert Config Audits

ALERT_ACKNOWLEDGED_AUDIT

A user acknowledged an open alert.

ALERT_UNACKNOWLEDGED_AUDIT

A user un-acknowledged an open alert.

ALERT_CONFIG_DISABLED_AUDIT

An alert configuration was disabled.

ALERT_CONFIG_ENABLED_AUDIT

An alert configuration was enabled.

ALERT_CONFIG_ADDED_AUDIT

An alert configuration was added.

ALERT_CONFIG_DELETED_AUDIT

An alert configuration was deleted.

ALERT_CONFIG_CHANGED_AUDIT

An alert configuration was edited.

Backup Audits

RS_STATE_CHANGED_AUDIT

A user started, stopped, or terminated backup for a replica set. is started, stopped. or terminated by a user

CLUSTER_STATE_CHANGED_AUDIT

A user started, stopped or terminated backup for a sharded cluster.

RESTORE_REQUESTED_AUDIT

A restore was requested.

SYNC_REQUIRED_AUDIT

A user initiates a resync of a replica set or config server.

CLUSTERSHOT_DELETED_AUDIT

A user deletes a clustershot (e.g. a cluster checkpoint.)

SNAPSHOT_DELETED_AUDIT

A user delted a snapshot for a replica set.

RS_CREDENTIAL_UPDATED_AUDIT

A user updates the authentication credentials for a replica set.

CLUSTER_CREDENTIAL_UPDATED_AUDIT

A user updates the authentication credentials for a sharded cluster.

RS_BLACKLIST_UPDATED_AUDIT

A user updates the namespaces filter for a replica set.

CLUSTER_BLACKLIST_UPDATED_AUDIT

A user updates the namespaces filter for a sharded cluster.

RS_SNAPSHOT_SCHEDULE_UPDATED_AUDIT

A user updates the snapshot schedule for a replica set.

CLUSTER_SNAPSHOT_SCHEDULE_UPDATED_AUDIT

A user updates the snapshot schedule for a sharded cluster.

CLUSTER_CHECKKPOINT_UPDATED_AUDIT

A user updates the checkpoint schedule for a sharded cluster.

Group Audits

GROUP_DELETED

GROUP_DELETED is only visible in the Admin section in the General tab on the Audits page.

A Group was deleted.

GROUP_CREATED

A new Group was created.