We would like to have more audit log information available in elastic about recent changes in the configuration of provisioning target systems.
The following actions should be audited in elastic as user actions
  • When a user changes the configuration of a target system
  • Configuration changes will be included from the following areas:
  • Mapping
Add or remove fields
Import mapping
Change of current mapped fields
Rename field
Change type (text, array)
Change of description
Change of applicable entitlement action configuration(s)
Change of mapping configuration when type or value of a mapped field is changed
- Options
Enable/disable use in notifications
Enable/disable store in account data
  • Scripting
User lifecycle for PowerShell V2
Permission configuration changes for PowerShell V2
Retrieve permissions script
Grant, revoke, update, or all in one script changes scripting
  • Resource configuration
Add or remove resource configuration sets
Resource creation script
  • Post actions scripting for Active Directory
  • Uniqueness validation
Scripting changed
Changes in the applicable action selection
  • Correlation configuration
  • Thresholds
Enable or disable a threshold
Configured threshold value change
  • System configuration
Configuration of fields (Custom connector configuration)
Configured field values (from configuration TAB)
Execute on-premises or cloud changed
For target system changes the functionality will be limited to only include the following systems:
Active Directory (builtin)
PowerShell V2