Event Descriptions
Detailed ARAM Event Logs with Example data
A list of all available events captured by the Keeper Advanced Reporting and Alert Module are provided in the chart below. The Event Code is utilized in the user interface and within the Keeper Commander CLI command parameters. The "Message" field is utilized for the Alerting module.
Within each event, there may be additional attributes such as Record UID, Shared Folder UID, Team UID, Username, etc. These attributes will appear within the event description and they are also provided to the 3rd party SIEM provider in the format as specified by the destination. Below this chart are example JSON samples that are transmitted to the target SIEM.
Keeper ARAM Event JSON Samples
This document contains an example JSON payload for every audit event Keeper writes to the ARAM (Advanced Reporting & Alerts Module) stream. These are the events you can consume via the public Audit Events API or via SIEM/audit-log sync integrations (Splunk, Sumo Logic, DataDog, Azure Sentinel, Chronicle, etc.).
Base envelope
Every event includes these top-level fields, then adds event-specific fields below.
Field reference (event-specific)
record_uid
UID of a vault record
shared_folder_uid
UID of a shared folder
folder_uid
UID of a folder (user or shared)
folder_type
user or shared
team_uid
UID of a team
app_uid
UID of a KSM application / PAM resource
secret_uid
UID of a secret in a KSM app
gateway_uid
UID of a PAM/KSM gateway
agent_uid
UID of an EPM agent
deployment_uid,policy_uid,collection_uid,request_uid,link_uid
EPM entity UIDs
attachment_id
UID of a file attachment on a record
to_username / from_username
Other-party user emails
role_id / team_uid
Role / team identifiers
node_id / node
Enterprise node identifier / display name
channel
Login or comms channel (e.g. Web Vault, Browser Extension, KeeperChat)
result_code
Failure code on login_failure-style events
device_name
Friendly device label
protocol
PAM session protocol (ssh, rdp, vnc...)
plan,seats,enterprise,enterprise_new
Managed Company / MSP context
value
Enforcement value, benchmark setting, etc.
status
Generic state field (depends on event)
auth_fail_reason
EPM auth failure reason
token_id
Public-API or SCIM token id
Events by category
Category: account
account_recovery
Description: Account Recovery Requested
Alert template: User ${username} requested account recovery
alias_added
Description: Added alternative email
Alert template: User ${username} added alternative email ${email}
change_email
Description: Changed Email
Alert template: User ${username} changed email. Previous email ${email}
change_master_password
Description: Changed Master Password
Alert template: User ${username} changed master password
change_security_question
Description: Changed Security Question
Alert template: User ${username} changed security question
device_user_passkey_add
Description: Biometric passkey add
Alert template: User ${username} added a passkey for biometric login on a device '${device_name}'.
device_user_passkey_remove
Description: Biometric passkey removal
Alert template: User ${username} removed a passkey for biometric login on a device '${device_name}'.
set_alternate_master_password
Description: Alternate Master Password Set
Alert template: User ${username} set alternate Master Password
set_biometric_access
Description: Biometric Access Set
Alert template: User ${username} set biometric access
Category: admin_permission
admin_permission_added
Description: Add Administrative Permission
Alert template: User ${username} added an administrative permission '${value}' for role ${role_id} on node ${node_id}
admin_permission_removed
Description: Remove Administrative Permission
Alert template: User ${username} removed an administrative permission '${value}' for role ${role_id} on node ${node_id}
Category: breachwatch
bw_record_high_risk
Description: BreachWatch detected high-risk record password
Alert template: User ${username} was notified of a high risk password for record UID ${record_uid}
bw_record_ignored
Description: User ignored detected high-risk record password
Alert template: User ${username} ignored high risk password for record UID ${record_uid}
bw_record_resolved
Description: User resolved detected high-risk record password
Alert template: User ${username} resolved a high risk password for record UID ${record_uid}
Category: chat
chat_contact_added
Description: Added Contact on Chat
Alert template: User ${username} invited ${to_username} as contact
chat_file_attached
Description: Sent File on Chat
Alert template: User ${username} sent a file
chat_login
Description: Chat Login
Alert template: User ${username} logged in to KeeperChat (${channel})
chat_login_failed
Description: Chat Login Failure
Alert template: User ${username} login failed to KeeperChat with code ${result_code}
chat_message_destruct
Description: Self-Destructed Chat Message
Alert template: User ${username} set a message to self destruct
chat_message_received
Description: Received Chat Message
Alert template: User ${username} received a secure message
chat_message_sent
Description: Sent Chat Message
Alert template: User ${username} sent a secure message
Category: compliance_report
compliance_report_deleted
Description: Deleted Compliance Report
Alert template: Compliance report UID ${app_uid} deleted by ${username}
compliance_report_downloaded
Description: Downloaded Compliance Report
Alert template: Compliance report UID ${app_uid} downloaded by ${username}
compliance_report_exported
Description: Exported Compliance Report
Alert template: Compliance report UID ${app_uid} exported by ${username}
compliance_report_run
Description: Generated Compliance Report
Alert template: Compliance report run by ${username}
compliance_report_saved
Description: Saved Compliance Report
Alert template: Compliance report UID ${app_uid} saved by ${username}
saved_criteria_deleted
Description: Deleted Compliance Report Criteria
Alert template: Compliance report criteria UID ${app_uid} deleted by ${username}
saved_criteria_edited
Description: Edited Compliance Report Criteria
Alert template: Compliance report criteria UID ${app_uid} edited by ${username}
saved_criteria_saved
Description: Saved Compliance Report Criteria
Alert template: Compliance report criteria UID ${app_uid} saved by ${username}
unsaved_compliance_report_exported
Description: Unsaved Compliance Report Exported
Alert template: Unsaved compliance report exported by ${username}
Category: endpoint_privilege_manager
agent_added_collection_link
Description: Agent added collection link
Alert template: Agent added resource ${link_uid} to collection ${collection_uid}
agent_added_to_collection
Description: Agent added to collection
Alert template: Agent ${agent_uid} added itself to collection ${collection_uid}
agent_authentication_failed
Description: Agent Auth Failed
Alert template: Agent ${agent_uid} auth failed. Reason: ${auth_fail_reason}
agent_created_collection
Description: Agent created collection
Alert template: Agent ${agent_uid} created collection ${collection_uid}
agent_removed
Description: Removed agent
Alert template: ${username} deleted agent ${agent_uid}
agent_removed_from_collection
Description: Agent removed from collection
Alert template: Agent ${agent_uid} removed itself from collection ${collection_uid}
agent_unregistered
Description: Agent Unregistered
Alert template: Agent ${agent_uid} unregistered
agent_updated
Description: Updated agent
Alert template: ${username} updated agent ${agent_uid}
approval_request_created
Description: Agent created approval request
Alert template: Agent ${agent_uid} created approval request ${request_uid}
approval_request_removed
Description: Removed approval request
Alert template: ${username} deleted approval request ${request_uid}
approval_request_status_changed
Description: Changed approval request status
Alert template: ${username} changed status of approval request ${request_uid} to ${request_status}
collection_created
Description: Created collection
Alert template: ${username} created collection ${collection_uid}
collection_link_added
Description: Added collection link
Alert template: ${username} added link ${link_uid} to collection ${collection_uid}
collection_link_removed
Description: Removed collection link
Alert template: ${username} removed link ${link_uid} from collection ${collection_uid}
collection_removed
Description: Removed collection
Alert template: ${username} deleted collection ${collection_uid}
collection_updated
Description: Updated collection
Alert template: ${username} updated collection ${collection_uid}
deployment_authentication_failed
Description: Deployment Auth Failed
Alert template: Deployment ${deployment_uid} auth failed. Reason: ${auth_fail_reason}
deployment_created
Description: Created deployment
Alert template: ${username} created deployment ${deployment_uid}
deployment_removed
Description: Removed deployment
Alert template: ${username} deleted deployment ${deployment_uid}
deployment_updated
Description: Updated deployment
Alert template: ${username} updated deployment ${deployment_uid}
policy_created
Description: Created policy
Alert template: ${username} created policy ${policy_uid}
policy_removed
Description: Removed policy
Alert template: ${username} removed policy ${policy_uid}
policy_updated
Description: Updated policy
Alert template: ${username} updated policy ${policy_uid}
register_agent
Description: Registered agent
Alert template: Agent ${agent_uid} is registered using ${deployment_uid}
Category: keeper_ai
keeper_ai_critical_risk_level_detected
Description: KeeperAI Detected Critical Risk
Alert template: KeeperAI analyzed the session and assigned an overall risk level of Critical for Record UID ${record_uid}
keeper_ai_high_risk_level_detected
Description: KeeperAI Detected High Risk
Alert template: KeeperAI analyzed the session and assigned an overall risk level of High for Record UID ${record_uid}
keeper_ai_medium_risk_level_detected
Description: KeeperAI Detected Medium Risk
Alert template: KeeperAI analyzed the session and assigned an overall risk level of Medium for Record UID ${record_uid}
keeper_ai_pam_configuration_feature_disabled
Description: Disabled KeeperAI in the PAM Config
Alert template: User ${username} disabled KeeperAI options in PAM Configuration ${record_uid}
keeper_ai_pam_configuration_feature_enabled
Description: event_keeper_ai_pam_configuration_feature_enabled
Alert template: User ${username} enabled KeeperAI options in PAM Configuration ${record_uid}
keeper_ai_recording_disabled
Description: KeeperAI Recording Disabled
Alert template: KeeperAI recording was disabled by user ${username} on Record UID ${record_uid}
keeper_ai_recording_enabled
Description: KeeperAI Recording Enabled
Alert template: KeeperAI recording was enabled by user ${username} on Record UID ${record_uid}
keeper_ai_session_locked_by_ai_critical
Description: Session Locked by KeeperAI (Critical Threat)
Alert template: Session terminated and resource locked due to a critical threat detected for Record UID ${record_uid}
keeper_ai_session_locked_by_ai_high
Description: Session Locked by KeeperAI (High Threat)
Alert template: Session terminated and resource locked due to a high threat detected for Record UID ${record_uid}
keeper_ai_session_locked_by_ai_medium
Description: Session Locked by KeeperAI (Medium Threat)
Alert template: Session terminated and resource locked due to a medium threat detected for Record UID ${record_uid}
keeper_ai_session_terminate_disabled
Description: KeeperAI Terminate Session Disabled
Alert template: User ${username} disabled KeeperAI session terminate on Record UID ${record_uid}
keeper_ai_session_terminate_enabled
Description: KeeperAI Terminate Session Enabled
Alert template: User ${username} enabled KeeperAI session terminate on Record UID ${record_uid}
keeper_ai_session_unlocked_by_user
Description: Session Unlocked by User
Alert template: User ${username} unlocked Record UID ${record_uid}
Category: ksm
app_client_access
Description: Accessed Secrets Manager from App
Alert template: ${app_client_type} ${device_name} has accessed secrets from application ${app_uid}
app_client_access_denied
Description: Denied access to Secrets Manager from Client Device
Alert template: Access denied to application ${app_uid} from ${app_client_type} ${device_name} with IP address ${ip_address}
app_client_added
Description: Added Client Device to Secrets Manager App
Alert template: User ${username} added ${app_client_type} ${device_name} to application ${app_uid}
app_client_connected
Description: Initialized Client Device on Secrets Manager App
Alert template: ${app_client_type} ${device_name} performed initial connect to application ${app_uid}
app_client_expired
Description: Secrets Manager Client Device Access Expired
Alert template: Access for ${app_client_type} ${device_name} to application ${app_uid} has expired
app_client_folder_create
Description: Created Folder from Secrets Manager device
Alert template: ${app_client_type} ${device_name} has created folder UID ${record_uid}
app_client_folder_delete
Description: Deleted Folder from Secrets Manager device
Alert template: ${app_client_type} ${device_name} has deleted folder UID ${record_uid}
app_client_folder_remove_record
Description: Record removed from shared folder by Secrets Manager device
Alert template: ${app_client_type} ${device_name} removed record ${record_uid} from shared folder
app_client_folder_update
Description: Updated Folder from Secrets Manager device
Alert template: ${app_client_type} ${device_name} has updated folder UID ${record_uid}
app_client_record_create
Description: Record created by Secrets Manager device
Alert template: ${app_client_type} ${device_name} has created record UID ${record_uid}
app_client_record_delete
Description: Record deleted by Secrets Manager device
Alert template: ${app_client_type} ${device_name} has sent record UID ${record_uid} to trash
app_client_record_update
Description: Record updated by Secrets Manager device
Alert template: ${app_client_type} ${device_name} has updated record UID ${record_uid}
app_client_removed
Description: Removed Client Device from Secrets Manager App
Alert template: User ${username} removed ${app_client_type} ${device_name} from application ${app_uid}
app_folder_removed
Description: Folder removed from Secrets Manager
Alert template: User ${username} removed folder UID ${secret_uid} from KSM application ${app_uid}
app_folder_share_changed
Description: Changed folder permission to Secrets Manager
Alert template: User ${username} changed share permissions for folder UID ${secret_uid} for KSM application ${app_uid}
app_folder_shared
Description: Folder shared with Secrets Manager
Alert template: User ${username} shared folder UID ${secret_uid} with KSM application ${app_uid}
app_record_removed
Description: Record removed from Secrets Manager
Alert template: User ${username} removed record UID ${secret_uid} from KSM application ${app_uid}
app_record_share_changed
Description: Changed record permission to Secrets Manager
Alert template: User ${username} changed share permissions for record UID ${secret_uid} for KSM application ${app_uid}
app_record_shared
Description: Record Shared with Secrets Manager App
Alert template: User ${username} shared record UID ${secret_uid} with KSM application ${app_uid}
pam_configuration_created
Description: PAM Configuration Created
Alert template: User ${username} created a PAM Configuration '${record_uid}'
pam_configuration_deleted
Description: PAM Configuration Deleted
Alert template: User ${username} deleted a PAM Configuration '${record_uid}'
pam_configuration_updated
Description: PAM Configuration Updated
Alert template: User ${username} updated a PAM Configuration '${record_uid}'
pam_gateway_created
Description: Gateway Created
Alert template: User ${username} created gateway ${device_name} (UID: ${gateway_uid})
pam_gateway_max_instance_count_updated
Alert template: User ${username} updated gateway ${device_name} (UID: ${gateway_uid}) max instance count to ${max_instance_count}
pam_gateway_offline
Description: Gateway Offline
Alert template: Gateway ${device_name} (UID: ${gateway_uid}) is offline
pam_gateway_online
Description: Gateway Online
Alert template: Gateway ${device_name} (UID: ${gateway_uid}) is online
pam_gateway_removed
Description: Gateway Removed
Alert template: User ${username} removed gateway ${device_name} (UID: ${gateway_uid})
record_rotation_created
Description: Rotation Settings added to Record
Alert template: User ${username} added rotation settings to record ${record_uid}
record_rotation_disabled
Description: Rotation Disabled on Record
Alert template: User ${username} disabled rotation settings on record ${record_uid}
record_rotation_on_demand_fail
Description: On Demand Rotation Failed
Alert template: On demand rotation by user ${username} failed for record ${record_uid}
record_rotation_on_demand_ok
Description: On Demand Rotation Successful
Alert template: User ${username} successfully rotated record ${record_uid}
record_rotation_scheduled_fail
Description: Scheduled Rotation Failed
Alert template: Scheduled rotation failed for record ${record_uid}
record_rotation_scheduled_ok
Description: Scheduled Rotation Successful
Alert template: Record ${record_uid} was successfully rotated
record_rotation_updated
Description: Rotation Settings Changed on Record
Alert template: User ${username} updated rotation settings on record ${record_uid}
Category: login
login
Description: Logged In
Alert template: User ${username} logged in to vault (${channel})
login_console
Description: Console Login
Alert template: User ${username} logged into Admin Console (${channel})
login_failure
Description: Failed Login
Alert template: User ${username} login failed with code ${result_code}
Category: managed_company
enterprise_addon_added
Description: Added add-on
Alert template: User ${username} added ${plan} add-on to enterprise ${enterprise}
enterprise_addon_removed
Description: Removed add-on
Alert template: User ${username} removed ${plan} add-on from enterprise ${enterprise}
enterprise_created
Description: Created enterprise
Alert template: User ${username} created enterprise ${enterprise}
enterprise_deleted
Description: Deleted enterprise
Alert template: User ${username} deleted enterprise ${enterprise}
enterprise_file_plan_changed
Description: Changed File Plan
Alert template: User ${username} changed file plan for enterprise ${enterprise} to ${plan}
mc_pam_active_seat_count_changed
Description: Active Seat Count Changed For Managed Company (Only for active users not invited users)
Alert template: PAM active seat count XXX by ${seats}
msp_changes_mc_plan
Description: Changed MC Plan
Alert template: User ${username} changed plan for MC ${enterprise} to ${plan}
msp_changes_mc_seats
Description: Changed MC Maximum license count
Alert template: User ${username} changed MC Maximum license count for enterprise ${enterprise} to ${seats}
msp_pam_active_seat_count_changed_within_mc
Description: Active Seat Count Changed Within Managed Company, Visible to the MSP (Only for active users not invited users)
Alert template: PAM active seat count for managed company ${enterprise} XXX by ${seats}
Category: msp
gradient_connection_remove
Description: Gradient MSP remove
Alert template: User ${username} delete Gradient MSP integration succeeded
gradient_connection_setup
Description: Gradient MSP setup
Alert template: User ${username} setup connection to Gradient MSP succeeded
gradient_mappings_setup
Description: Gradient MSP mappings
Alert template: User ${username} sync mappings to Gradient MSP succeeded
gradient_sync_fail
Description: Gradient MSP sync fail
Alert template: Gradient MSP billing sync has failed
msp_activated
Description: MSP Activated
Alert template: User ${username} activated MSP for enterprise ${enterprise}
msp_attaches_mc
Description: Attached to node
Alert template: User ${username} attached enterprise ${enterprise} to node ${node}
msp_creates_mc
Description: Registered Managed Company
Alert template: User ${username} registered enterprise ${enterprise}, ${plan}
msp_deactivated
Description: MSP Deactivated
Alert template: User ${username} deactivated MSP for enterprise ${enterprise}
msp_pam_active_seat_count_changed
Description: Active Seat Count Changed For Managed Service Provider (Only for active users not invited users)
Alert template: PAM active seat count XXX by ${seats}
msp_pauses_mc
Description: Paused Managed Company
Alert template: User ${username} paused enterprise ${enterprise}, ${plan}
msp_removes_mc
Description: Removed Managed Company
Alert template: User ${username} removed enterprise ${enterprise}, ${plan}
msp_renames_mc
Description: Renamed Managed Company
Alert template: User ${username} renamed enterprise ${enterprise} to ${enterprise_new}
msp_resumes_mc
Description: Resumed Managed Company
Alert template: User ${username} resumed enterprise ${enterprise}, ${plan}
Category: policy
agent_removed_approval_request
Description: Agent Removed Approval Request
Alert template: Agent ${agent_uid} removed approval request ${request_uid}
audit_alert_created
Description: Created Alert
Alert template: Admin ${username} created audit alert "${name}"
audit_alert_deleted
Description: Deleted Alert
Alert template: Admin ${username} deleted audit alert "${name}"
audit_alert_paused
Description: Paused Alert
Alert template: Admin ${username} paused audit alert "${name}" for user ${recipient}
audit_alert_resumed
Description: Resumed Alert
Alert template: Admin ${username} resumed audit alert "${name}" for user ${recipient}
audit_sync_removed
Description: Removed Audit Log Sync
Alert template: Admin ${username} removed "${name}" audit log sync
audit_sync_setup
Description: Setup Audit Log Sync
Alert template: Admin ${username} set up "${name}" audit log sync
bridge_activated
Description: Activated AD Bridge
Alert template: User ${username} activated Keeper Bridge on node ${node}
bridge_deleted
Description: Deleted AD Bridge
Alert template: User ${username} deleted Keeper Bridge from node ${node}
bridge_updated
Description: Updated AD Bridge
Alert template: User ${username} updated Keeper Bridge on node ${node}
email_provisioning_activated
Description: Activated Email Provisioning
Alert template: User ${username} activated Email auto-provisioning for domain ${email_domain} on node ${node}
email_provisioning_deleted
Description: Deleted Email Provisioning
Alert template: User ${username} deleted Email auto-provisioning for domain ${email_domain} from node ${node}
node_created
Description: Created Node
Alert template: User ${username} created node ${node}
node_deleted
Description: Deleted Node
Alert template: User ${username} deleted node ${node}
out_of_seats
Description: License reached maximum
Alert template: License has reached the maximum allowed users for ${enterprise}
record_type_created
Description: Created Record Type
Alert template: Admin ${username} created record type ${name}
record_type_deleted
Description: Deleted Record Type
Alert template: Admin ${username} deleted record type ${name}
record_type_updated
Description: Updated Record Type
Alert template: Admin ${username} updated record type ${name}
report_created
Description: Created Report
Alert template: Admin ${username} created report ${report_name}
report_deleted
Description: Deleted Report
Alert template: Admin ${username} deleted report ${report_name}
report_modified
Description: Modified Report
Alert template: Admin ${username} modified report ${report_name}
role_created
Description: Created Role
Alert template: User ${username} created role ${role_id}
role_deleted
Description: Deleted Role
Alert template: User ${username} deleted role ${role_id}
role_enforcement_changed
Description: Changed Role Policy
Alert template: User ${username} changed enforcement ${enforcement} to ${value} for role ${role_id}
scim_activated
Description: Activated SCIM
Alert template: User ${username} activated SCIM provisioning on node ${node}
scim_deleted
Description: Deleted SCIM
Alert template: User ${username} deleted SCIM provisioning from node ${node}
scim_updated
Description: Activated SCIM
Alert template: User ${username} updated SCIM provisioning on node ${node}
set_2fa_configuration
Description: Set 2FA Configuration
Alert template: Set global 2FA configuration ${value} for node ${node}
set_custom_email_content
Description: Set Custom Email
Alert template: User ${username} set custom email content
set_custom_email_logo
Description: Set Email Logo
Alert template: User ${username} set custom email logo
set_custom_header_logo
Description: Set Vault Logo
Alert template: User ${username} set custom header logo
ssh_agent_approved
Description: Approved the SSH agent
Alert template: User ${username} used SSH Agent with record ${record_uid}
ssh_agent_started
Description: Started the SSH agent
Alert template: User ${username} started SSH Agent
ssh_agent_stopped
Description: Stopped the SSH agent
Alert template: User ${username} stopped SSH Agent
sso_activated
Description: Activated SSO Connect
Alert template: User ${username} activated Keeper SSO Connect on node ${node}
sso_deleted
Description: Deleted SSO Connect
Alert template: User ${username} deleted Keeper SSO Connect from node ${node}
sso_updated
Description: Updated SSO Connect
Alert template: User ${username} updated Keeper SSO Connect configuration on node ${node}
team_created
Description: Created Team
Alert template: User ${username} created team ${team_uid}
team_deleted
Description: Deleted Team
Alert template: User ${username} deleted team ${team_uid}
team_provisioned_by_scim
Description: SCIM Provisioned Team
Alert template: SCIM provisioned team ${team_uid}
Category: public_api
access_resource_public_api
Description: Resource Access with Public API Token
Alert template: API with token ${token_id} with resource ${app_uid} executed
create_public_api_token_in_days
Description: Admin created an API token
Alert template: User ${username} created an API token ${token_id} for type ${app_uid} with an expiration of ${feature_id} days
revoke_public_api_token
Description: Deleted Public API Token
Alert template: User ${username} deleted API token ${token_id}
Category: role_node_management
role_managed_node_added
Description: Add A Manage Node To A Role
Alert template: User ${username} added manage nodes permission for role ${role_id} on node ${node_id} with cascade set to ${value}
role_managed_node_removed
Description: Remove A Manage Node From A Role
Alert template: User ${username} removed manage nodes permission for role ${role_id} on node ${node_id}
role_managed_node_updated
Description: Change Cascade Node Permission
Alert template: User ${username} changed the cascade node permission on node ${node_id} for role ${role_id} to ${value}
Category: security
accept_invitation
Description: Accepted Invitation
Alert template: User ${username} accepted invitation
accept_transfer
Description: Accepted Transfer Consent
Alert template: User ${username} accepted account transfer consent
account_recovery_decline
Description: Recovery Phrase Set Declined
Alert template: User ${username} declined to set a recovery phrase for their account
account_recovery_setup
Description: Recovery Phrase Set
Alert template: User ${username} set a recovery phrase for their account
add_security_key
Description: Added Security Key
Alert template: User ${username} added security key
added_admin_key
Description: Granted Admin Permissions
Alert template: User ${to_username} was provided admin permissions by admin ${username}
added_to_role
Description: Added User to Role
Alert template: User ${to_username} was added to Role ${role_id} by admin ${username}
auto_invite_user
Description: Auto-Invited User
Alert template: User ${email} was added by an automated provisioning method (SCIM, SSO or AD Bridge)
clear_security_data
Description: Cleared security audit data
Alert template: User ${username} cleared security audit data from the Admin Console
create_user
Description: Created User
Alert template: User ${username} created
decline_invitation
Description: Declined Invitation
Alert template: User ${username} declined invitation
delete_pending_user
Description: Deleted Pending User
Alert template: Pending user ${email} was deleted by ${username}
delete_security_key
Description: Deleted Security Key
Alert template: User ${username} removed security key
delete_user
Description: Deleted User
Alert template: User ${email} was deleted by admin ${username}
device_admin_account_locked
Description: Admin locked device account
Alert template: Admin ${username} locked account on a device for ${to_username}
device_admin_account_unlocked
Description: Admin unlocked device account
Alert template: Admin ${username} unlocked account on a device for ${to_username}
device_admin_approval_requested
Description: Admin approval for device requested
Alert template: User ${username} requested admin approval for device ${device_name}
device_admin_locked
Description: Admin locked device
Alert template: Admin ${username} locked a device
device_admin_loggedout
Description: Admin Logged Out device
Alert template: Admin ${username} Removed a device
device_admin_removed
Description: Admin removed device
Alert template: Admin ${username} Removed a device
device_admin_unlocked
Description: Admin unlocked device
Alert template: Admin ${username} unlocked a device
device_approved
Description: Device approved
Alert template: Device ${device_name} is approved for user ${username}
device_approved_by_admin
Description: Device approved by admin
Alert template: Admin ${username} approved device ${device_name} for user ${to_username}
device_user_approval_requested
Description: User requested self approval for device
Alert template: User ${username} requested self approval for device ${device_name}
device_user_blocked
Description: User Blocked Device
Alert template: User ${username} blocked login on a device
device_user_linked
Description: User Linked Devices
Alert template: User ${username} linked two or more devices
device_user_locked
Description: User Locked Device
Alert template: User ${username} locked a device for all accounts
device_user_loggedout
Description: User Logged Out Device
Alert template: User ${username} forced logout on a device
device_user_removed
Description: User Removed Device
Alert template: User ${username} removed a device
device_user_renamed
Description: User Renamed Device
Alert template: User ${username} renamed a device
device_user_unblocked
Description: User Unblocked Device
Alert template: User ${username} unblocked a device
device_user_unlinked
Description: User Unlinked Devices
Alert template: User ${username} unlinked two or more devices
device_user_unlocked
Description: User Unlocked Device
Alert template: User ${username} unlocked a device
enable_user
Description: Enabled User
Alert template: User ${to_username} was enabled by admin ${username}
enterprise_2fa_disabled_by_admin
Description: Disabled 2FA By Admin
Alert template: Admin ${username} disabled 2FA for user ${to_username}
enterprise_product_changed
Description: Changed plan
Alert template: User ${username} changed plan for enterprise ${enterprise} to ${plan}
enterprise_to_consumption_billing
Description: Converted to Consumption billing
Alert template: Consumption billing start date: ${app_uid}
expire_password
Description: Expired Master Password
Alert template: User ${to_username} master password was reset by admin ${username}
lock_user
Description: Locked User
Alert template: User ${to_username} was locked by admin ${username}
login_failed_console
Description: Failed Console Login
Alert template: User ${username} failed login to Admin Console
login_failed_ip_whitelist
Description: IP Blocked
Alert template: User ${username} has been blocked from IP ${ip_address}
payment_method_updated
Description: Payment Method Updated
Alert template: User ${username} updated payment method to ${plan} for enterprise ${enterprise}
pending_added_to_role
Description: Added Pending User to Role
Alert template: Pending user ${value} was added to Role ${role_id} by admin ${username}
pending_removed_from_role
Description: Removed Pending User from Role
Alert template: Pending user ${value} was removed from Role ${role_id} by admin ${username}
reauthentication_reprompt_success
Description: Master password reprompt success
Alert template: User ${username} re-authentication succeeded
reauthentication_reprompt_throttle
Description: Re-authentication prompt throttled
Alert template: User ${username} re-authentication throttled
removed_from_role
Description: Removed User from Role
Alert template: User ${to_username} was removed from Role ${role_id} by admin ${username}
role_team_add
Description: Added Role to Team
Alert template: ${username} added role ${role_id_status} to team ${team_uid}
role_team_remove
Description: Removed Role from Team
Alert template: ${username} removed role ${role_id_status} from team ${team_uid}
scim_access_failure
Description: SCIM access failure
Alert template: SCIM provisioning on node ${node} failed to authenticate ${failure_count} times. Token ${token_id}..
send_invitation
Description: Invited User
Alert template: User ${email} was invited to join by admin ${username}
set_two_factor_off
Description: Disabled Two-Factor Auth
Alert template: User ${username} set 2FA method OFF
set_two_factor_on
Description: Enabled Two-Factor Auth
Alert template: User ${username} set 2FA method ON
two_factor_code_invalid
Description: The Two-Factor code is invalid
Alert template: User ${username} entered invalid two-factor authentication code
two_factor_disabled_by_support
Description: Disabled 2FA By Keeper Support
Alert template: Two-Factor Auth was disabled for user ${username} by Keeper Support
unusual_location_activity_logout
Alert template: KeeperAI logged out device ${device_name} for user ${username} due to unusual location activity
vault_transferred
Description: Transferred Vault
Alert template: User ${email} (${from_username}) vault was transferred to user ${to_username} by admin ${username}
Category: security_benchmark
sb_configure_ip_allowlisting
Description: Configure IP Allowlisting
Alert template: Security Benchmark Configure IP Allowlisting set to ${value} by ${username}
sb_create_alerts
Description: Create alerts
Alert template: Security Benchmark Create Alerts set to ${value} by ${username}
sb_create_at_least_two_keeper_administrators
Description: Create at least two Keeper Administrators
Alert template: Security Benchmark Create At Least Two Keeper Administrators set to ${value} by ${username}
sb_deploy_across_entire_organization
Description: Deploy Across Your Entire Organization
Alert template: Security Benchmark Deploy Across Entire Organization set to ${value} by ${username}
sb_disable_account_recovery
Description: Disable Account Recovery
Alert template: Security Benchmark Disable Account Recovery set to ${value} by ${username}
sb_disable_browser_password_managers
Description: Disable Browser Password Managers
Alert template: Security Benchmark Disable Browser Password Managers set to ${value} by ${username}
sb_enable_account_transfer_policy
Description: Enable Account Transfer Policy
Alert template: Security Benchmark Enable Account Transfer Policy set to ${value} by ${username}
sb_enforce_least_privilege_policy
Description: Enforce Least Privileged Policy
Alert template: Security Benchmark Enforce Least Privilege Policy On Managed Devices set to ${value} by ${username}
sb_enforce_strong_master_password
Description: Enforce a strong Master Password
Alert template: Security Benchmark Enforce Strong Master Password set to ${value} by ${username}
sb_ensure_outside_sso_administrator_exists
Description: Ensure Outside SSO Administrator Exists
Alert template: Security Benchmark Ensure Outside SSO Administrator Exists set to ${value} by ${username}
sb_ensure_two_factor_authentication_admin_users
Description: Ensure Two-Factor Authentication For Admin Users
Alert template: Security Benchmark Ensure Two-Factor Authentication For Admin Users set to ${value} by ${username}
sb_ensure_two_factor_authentication_for_end_users
Description: Ensure Two-Factor Authentication For End Users
Alert template: Security Benchmark Ensure Two-Factor Authentication For End Users set to ${value} by ${username}
sb_lock_down_sso_provider
Description: Lock down your SSO provider
Alert template: Security Benchmark Lock Down SSO Provider set to ${value} by ${username}
sb_prevent_installation_of_untrusted_extensions
Description: Prevent Installation of Untrusted Extensions
Alert template: Security Benchmark Prevent Installation Of Untrusted Extensions set to ${value} by ${username}
sb_reduce_administrator_privilege
Description: Reduce Administrator Privilege
Alert template: Security Benchmark Reduce Administrator Privilege set to ${value} by ${username}
Category: share
accept_share
Description: Accepted Share Request
Alert template: User ${username} accepted share from user ${to_username}
added_shared_folder
Description: Added Shared Folder
Alert template: User ${username} created shared folder UID ${shared_folder_uid}
added_to_team
Description: Added User to Team
Alert template: User ${to_username} was added to Team ${team_uid} by admin ${username}
cancel_share
Description: Rejected Share Request
Alert template: User ${username} canceled share from user ${to_username}
change_share
Description: Changed Record Share
Alert template: User ${username} changed share permissions for record UID ${record_uid} to user ${to_username}
deleted_shared_folder
Description: Deleted Shared Folder
Alert template: User ${username} deleted shared folder UID ${shared_folder_uid}
ext_share_access
Description: One-Time Share Re-opened
Alert template: A user re-opened the One-Time Share link for 'Record UID:${app_uid}' created by ${username}
ext_share_added
Description: One-Time Share Added
Alert template: User ${username} generated a One-Time Share link to Record UID:${app_uid}
ext_share_connected
Description: One-Time Share Opened
Alert template: A user opened the One-Time Share link for 'Record UID:${app_uid}' created by ${username}
ext_share_expired
Description: One-Time Share Expired
Alert template: A One-Time Share link for 'Record UID:${app_uid}' has expired
ext_share_removed
Description: One-Time Share Removed
Alert template: User ${username} removed a One-Time Share link to 'Record UID:${app_uid}'
folder_add_outside_user
Description: Folder Shared Outside
Alert template: User ${username} added outside the company user ${to_username} to shared folder UID ${shared_folder_uid}"
folder_add_record
Description: Added Record to Shared Folder

