Skip to main content

SIEM events

The Trust Engine raises these events, delivered through the GELF log destination configured under Settings > Server Configuration > Logging.

Event When What it carries
TrustPolicyObserved A policy noticed something and allowed access. The user, the address, the Knoc, the policy, the outcome, and a field per signal that matched. A condition that applied its response because its provider failed is listed under MatchedProviderFailed, one whose provider refused the credential under MatchedProviderRejected, and one nobody asked about under MatchedNotEvaluated. A verdict decided on a stored answer names the sources under DecidedOnStaleAnswer and the age of the oldest under StaleAnswerOldest.
TrustPolicyChallenged A policy held a grant back pending confirmation. The same fields as TrustPolicyObserved.
TrustPolicyBlocked A policy refused a grant. The same fields as TrustPolicyObserved.
TrustChallengePassed A user confirmed who they are. The user, the address they confirmed from, how they confirmed, and how many policies the answer satisfied. No Knoc and no policy, because one confirmation answers every policy the user's Knocs use.
IpIntelCacheCleared An admin cleared the cached provider answers from the Threat intelligence page. Who did it, and how many answers the server that took the click dropped.
IpIntelLookupFailed A provider did not answer. The provider, the address it was asked about, and the error. Nothing about the user, Knoc or policy, since this is a call to a provider rather than a decision about anyone.

The three TrustPolicy* events share one field shape, so a rule written against one works unchanged against the others. IpIntelLookupFailed marks a failure that will not clear on its own, such as a rejected key or a plan gap, apart from a passing outage, so an alert can single it out.