Audit Trail Event ID reference
Use this reference to look up Audit Trail event records by Event ID. Each entry includes the category, action, and a short summary of the event.
These logs help track admin and user activity in the SessionGuardian Admin Console.
To learn how to view, filter, and export these records, see View and filter Audit Trail logs.
Event ID | Category | Action | Summary |
---|---|---|---|
SGE_CU_001 | CONSOLE USER | Create Admin | New console admin user setup: #{username} |
SGE_CU_002 | CONSOLE USER | Update Admin | Console user updated #{username} |
SGE_CU_003 | CONSOLE USER | Delete Admin | Console user deleted: #{adminUser.username} |
SGE_CU_004 | CONSOLE USER | Login: Successfully | Console user login successfully |
SGE_CU_005 | CONSOLE USER | Login: Failed | Console user login failed - invalid username |
SGE_CU_006 | CONSOLE USER | Login: Failed | Console user login failed - invalid password (attempt x of x) |
SGE_CU_007 | CONSOLE USER | Login: Failed | Console user login failed - invalid OTP (attempt x of x) |
SGE_CU_008 | CONSOLE USER | Login: Failed | Console user disabled. Too many failed login attempts (x of x) |
SGE_CU_009 | CONSOLE USER | Reset Admin MFA | Console user MFA reset sent: #{user.username} |
SGE_CU_010 | CONSOLE USER | Reset Password | Console user password reset sent: #{username} |
SGE_CU_011 | CONSOLE USER | Invite Admin User | Console user invitation sent: #{adminUser.username} |
SGE_CU_012 | CONSOLE USER | Unlock Admin User | Console user unlocked: #{adminUserDomain.username} |
SGE_CU_013 | CONSOLE USER | OIDC Login: Successfully | Console user OIDC login successfully via provider #{providerName} (#{providerId}) |
SGE_CU_014 | CONSOLE USER | OIDC Login: Failed | Console user OIDC login failed via provider #{providerName} (#{providerId}): #{username}" |
SGE_CU_015 | CONSOLE USER | Create Admin: Successfully | New console admin user created via OIDC provider #{providerName} (#{providerId}): #{username}" |
SGE_CU_016 | CONSOLE USER | Update Admin: Successfully | Console user updated via OIDC provider #{providerName} (#{providerId}): #{username}" |
SGE_EU_001 | END USER | Create End User | New end user setup: #{username} |
SGE_EU_002 | END USER | Update End User | End user account modified: #{username} |
SGE_EU_003 | END USER | Delete End User | End user deleted: #{username} |
SGE_EU_004 | END USER | View End User | End user account viewed: #{username} |
SGE_EU_005 | END USER | Assign Security Group | End user account moved to security group: #{username} |
SGE_EU_006 | END USER | Import End User | Import End User: #{username} |
SGE_EU_007 | END USER | Service: Enabled/Disabled | End user account service enabled/disabled |
SGE_EU_008 | END USER | Request User Photo Registration | End user photo registration request is sent. Reason: #{reason} |
SGE_EU_009 | END USER | Send User Invite | Invitation has been sent to user: #{username} |
SGE_EU_010 | END USER | User Registration Reset | User registration has been reset: #{username}. Reason: #{reason} |
SGE_EU_011 | END USER | Lock End User | End user has been locked: #{username} |
SGE_EU_012 | END USER | Unlock End User | End user has been unlocked: #{username} |
SGE_EU_013 | END USER | User Support Mode Enabled | End user support mode has been enabled: #{username} |
SGE_EU_014 | END USER | Disable Support Mode | End user support mode has been disabled: #{username} |
SGE_EU_015 | END USER | MFA Reset | End User MFA has been reset |
SGE_EU_016 | END USER | Assign Project | End user account moved to project |
SGE_EU_017 | END USER | Unassign Project | End user account moved from project |
SGE_EU_018 | END USER | Assign Security Group | End user account moved to security group |
SGE_EU_019 | END USER | Unassign Security Group | End user account moved from security group |
SGE_SG_001 | SECURITY GROUP | Create Security Group | Security group created: #{securityGroup.name} |
SGE_SG_002 | SECURITY GROUP | Update Security Group | Security group settings modified: #{name} |
SGE_SG_003 | SECURITY GROUP | Delete Security Group | Security group deleted: #{securityGroup.name} |
SGE_SS_001 | SCREENSHOT | View Screen Capture | Screenshot viewed for event: #{key} |
SGE_SS_002 | SCREENSHOT | Delete Screen Capture | Screenshot deleted : #{key} |
SGE_SETTINGS_001 | GLOBAL SETTINGS | Save Auto Update Configuration | Auto Update configuration has been modified |
SGE_SETTINGS_002 | GLOBAL SETTINGS | Update SG Client Settings | Client settings has been updated |
SGE_SETTINGS_003 | GLOBAL SETTINGS | Update SG Agent Settings | Agent Settings has been updated |
SGE_SETTINGS_004 | GLOBAL SETTINGS | Update SG Confidential Agreement | Confidential Agreement settings has been updated |
SGE_SETTINGS_005 | GLOBAL SETTINGS | Save Default Settings | Client Default Settings has been updated |
SGE_SETTINGS_006 | GLOBAL SETTINGS | Update Support Mode Settings | Support Mode settings has been modified |
SGE_SETTINGS_007 | GLOBAL SETTINGS | Save Lock Screen Template | Lock Screen Template has been saved. Event: #{eventId} |
SGE_SETTINGS_008 | GLOBAL SETTINGS | Save Email Template | Email template has been updated: #{name} |
SGE_SETTINGS_009 | GLOBAL SETTINGS | Save Global Settings | Global Settings has been updated |
SGE_SETTINGS_010 | GLOBAL SETTINGS | Create WhiteList URL | WhiteListed URL has been created |
SGE_SETTINGS_011 | GLOBAL SETTINGS | Update WhiteList URL | WhiteListed URL has been updated |
SGE_SETTINGS_012 | GLOBAL SETTINGS | Delete WhiteList URL | WhiteListed URL has been deleted: ${name} |
SGE_EXPORT_001 | END USER | Export Users | Users exported |
SGE_EXPORT_002 | END USER | Export Users Logs | Users Logs exported |
SGE_EXPORT_003 | SECURITY GROUP | Export Security Groups | Security Groups exported |
SGE_EXPORT_004 | END USER | Export Timekeeping Record | Timekeeping report has been exported |
SGE_EXPORT_005 | END USER | Export Dashboard | Dashboard exported |
SGE_EXPORT_006 | AUDIT LOGS | Export Audit Logs | Audit Logs exported |
SGE_INST_001 | INSTANCE | Create Instance | Instance created: #{name} |
SGE_INST_002 | INSTANCE | Update Instance | Instance updated: #{name} |
SGE_INST_003 | INSTANCE | Delete Instance | Instance Deleted: #{name} |
SGE_INST_004 | INSTANCE | Save RDP File | Instance RDP file has been updated: #{instanceName} |
SGE_INST_005 | INSTANCE | Delete RDP File | Instance RDP file has been removed: #{instanceName} |
SGE_PRJ_001 | PROJECT | Create Project | Project created: #{projectName} |
SGE_PRJ_002 | PROJECT | Update Project | Project updated: #{projectName} |
SGE_PRJ_003 | PROJECT | Delete Project | Project deleted: #{projectName} |
SGE_ROLE_001 | ROLE | Create Role | Role has been created: #{roleName} |
SGE_ROLE_002 | ROLE | Update Role | Role has been updated: #{roleName} |
SGE_ROLE_003 | ROLE | Delete Role | Role has been deleted: #{roleName} |
SGE_EAC_001 | ESCALATED ALERTS | Save Escalated Alerts Configuration | Escalated Alerts Configuration has been updated |