Network Management

Alert on Orion Auditing Event

This article describes how to create an alert whenever a certain audit condition occurs.

First published date

11/10/2018 2:44 AM

Last published date

9/8/2020 7:54 PM

Overview

Specific changes on the Orion Web Console can also be tracked through auditing events. This article provides steps to create an alert whenever a particular condition of audit occurs. This alert looks at the events in the AuditingEvents table and lists many of the possible audit-able events.

Product section

Orion Platform

Resolution

 
 
  • Go to Settings -> All Settings -> Manage Alerts, Add New Alert.

 

  • For the Trigger condition:
    • I want to alert on Auditing Event
    • Only on the following objects: Choose an event: Auditing Event was created
    • Choose the appropriate Auditing Event(s). If one has more than one event, make sure that one uses the "OR" condition

 

  • Reset Condition:
    • Choose:  No reset condition – Trigger this alert each time the trigger condition is met.

 

  • Trigger Action:
    • Create the appropriate actions to take.
    • The account that did the work is in the AccountID variable.
    • The person who did the work, the object that was changed, and what was changed are contained in the AuditEventMessage variable.

 

  • Reset Action:
    • This will be empty since there was no reset condition specified.

 

  • Complete the alert.