Guides
Log In
Guides

Monitoring (Logging) Overview

Cyolo’s Admin Portal includes four types of logs:

  • Activity logs
  • Audit logs
  • System logs
  • Web Access logs

The Cyolo platform supports exporting logs via Syslog. Below is a description of each type of logging system.

Note: To edit columns, click the Edit Columns icon at the top right of the screen.

Log Structure

The log structure for these logs closely matches SIEM (CEF/LEEF/ECS) and IDS/IPS logs. This aligns as follows:

FieldSIEM/IDS Equivalent
Severityseverity (CEF, ECS, IDS)
Timestamptimestamp (ECS, IDS, LEEF)
Approver IDuser.id(ECS)
Actionevent.action (ECS)
Action Resultevent.outcome (ECS)
Result Descriptionmessage (CEF, ECS)
Source Typesource.type(ECS)
Source Namesource.name (ECS)
Source IPsource.ip (ECS, IDS)
Source Locationsource.geo.location (ECS)
Target Typetarget.type(ECS)
Target Nametarget.name(ECS)
Approver Typeuser.type(ECS)
Approver Nameuser.name(ECS)
User Agentuser_agent.original (ECS, IDS)
IDevent.id (ECS)

Activity Logs

Activity logs manage and reflect all actions performed by users related to applications.

Audit Logs

Audit logs manage the results of configuration changes performed by administrators.

System Logs

System logs include events related to the system health, internal statuses, etc.

Web Access Logs

Web Access logs are related to web applications. They are disabled by default; the enablement is done via API and per application.

Additional Logs

Syslog

For Syslog information, see the section Exporting Logs to Other Destinations.

Cyolo Connect Logs

There are two options for checking the Cyolo Connect logs:

  • Right-click on Cyolo Connect and then click Export Logs.
  • For Windows, open Event Viewer to display the log: