SIEM events
The Trust Engine raises these events, delivered through the GELF log destination configured under Settings > Server Configuration > Logging.
| Event | When | What it carries |
|---|---|---|
TrustPolicyObserved |
A policy noticed something and allowed access. | The user, the address, the Knoc, the policy, the outcome, and a field per signal that matched. A condition that applied its response because its provider failed is listed under MatchedProviderFailed, one whose provider refused the credential under MatchedProviderRejected, and one nobody asked about under MatchedNotEvaluated. A verdict decided on a stored answer names the sources under DecidedOnStaleAnswer and the age of the oldest under StaleAnswerOldest. |
TrustPolicyChallenged |
A policy held a grant back pending confirmation. | The same fields as TrustPolicyObserved. |
TrustPolicyBlocked |
A policy refused a grant. | The same fields as TrustPolicyObserved. |
TrustChallengePassed |
A user confirmed who they are. | The user, the address they confirmed from, how they confirmed, and how many policies the answer satisfied. No Knoc and no policy: one confirmation answers every policy the user's Knocs use. |
IpIntelCacheCleared |
An admin cleared the cached provider answers from the Threat intelligence page. | Who did it, and how many answers the server that took the click dropped. |
IpIntelLookupFailed |
A provider did not answer. | The provider, the address it was asked about, and the error. Nothing about the user, Knoc or policy: this is a call to a provider, not a decision about anyone. |
The three TrustPolicy* events share one field shape, so a rule written against one works unchanged against the others. IpIntelLookupFailed marks a failure that will not clear on its own, such as a rejected key or a plan gap, apart from a passing outage, so an alert can single it out.