Audit log events
Global configuration and administration coverage area
Global administration category
Base | Base URL changed (BaseUrlChangedEvent) |
---|---|
Advanced | Announcement banner created (AnnouncementBannerCreatedEvent) |
Full | No additional events available |
Apps category
Base | Plugin disabled (PluginDisabledEvent) Plugin enabled (PluginEnabledEvent) Plugin uninstalled (PluginUninstalledEvent) Plugin upgraded (PluginUpgradedEvent) |
---|---|
Advanced | No additional events available |
Full | Plugin container unavailable (PluginContainerUnavailableEvent) Plugin framework started (PluginFrameworkStartedEvent) Plugin module available (PluginModuleAvailableEvent) Plugin module disabled (PluginModuleDisabledEvent) Plugin module enabled (PluginModuleEnabledEvent) Plugin module unavailable (PluginModuleUnavailableEvent) |
Data pipeline category
Coverage level | Events logged |
---|---|
Base | No events available |
Advanced | Full data export cancelled |
Full | No events available |
User management coverage area
Users and groups category
Base | GPG key added (GpgKeyCreatedEvent) GPG key deleted (GpgKeyDeletedEvent) Group added to user group (GroupMembershipsCreatedEvent) Personal access token changed (AccessTokenModifiedEvent) Personal access token created (AccessTokenCreatedEvent) Personal access token deleted (AccessTokenDeletedEvent) SSH access key created for personal key (SshKeyCreatedEvent) SSH access key deleted for personal key (SshKeyDeletedEvent) User added to user group ((GroupMembershipsCreatedEvent) User automatically created (AutoUserCreatedEvent) User automatically deleted from user group (AutoGroupMembershipDeletedEvent) User created (UserCreatedEvent) User created from directory sync (UserCreatedFromDirectorySynchronisationEvent) User deleted (UserDeletedEvent) User deleted from user group (GroupMembershipDeletedEvent) User directory created (DirectoryCreatedEvent) User directory deleted (DirectoryDeletedEvent) User erased (UserErasedEvent) User group automatically created (AutoGroupCreatedEvent) User group created (GroupCreatedEvent) User group deleted (GroupDeletedEvent) User group updated (GroupUpdatedEvent) User password changed UserCredentialUpdatedEvent) Username changed (UserRenamedEvent) |
---|---|
Advanced | User details export failed (UserExportFailedEvent, extraAttribute withPermissions=false) |
Full | No additional events available |
Permission coverage area
Permissions category
Base | Global permission change request (GlobalPermissionModificationRequestedEvent) |
---|---|
Advanced | No additional events available |
Full | No additional events available |
Local configuration and administration coverage area
Personal category
Base | SSH key edited for personal key (SShKeyEditedEvent) |
---|
Projects category
Base | All project default tasks deleted (DefaultTaskBulkDeletedEvent) |
---|---|
Advanced | Project pull request merge config deleted (ProjectPullRequestMergeConfigDeletedEvent) |
Full | No additional events available |
Repositories category
Base | Repository auto-merge settings changed (AutoMergeSettingsUpdatedEvent) |
---|---|
Advanced | Pull request reviewer group created (ReviewerGroupCreatedEvent) |
Full | No additional events available |
System category
Base | No additional events available |
---|---|
Advanced | SCM pull request merge config deleted (ScmPullRequestMergeConfigDeletedEvent) |
Full | No additional events available |
Security coverage area
Auditing category
Base | Audit log configuration updated |
---|---|
Advanced | No events available |
Full | No events available |
Authentication category
Base | Websudo authentication failed |
---|---|
Advanced | User logged out (LogoutSuccessEvent) |
Full | User logged in (AuthenticationSuccessEvent) User logged in (SSH) (SshAuthenticationSuccessEvent) |
Security category
Base | Secret detected (SecretDetectedEvent) |
---|---|
Advanced | Unauthorized access to a resource (AuthorizationFailureEvent) |
Full | No events available |
End user activity coverage area
Repositories category
Base | Repository accessed by user (RepositoryAccessedEvent) Run build (AnalyticsActionRunEvent) |
---|---|
Advanced | Branch created (BranchCreatedEvent) |
Full | Changes pushed to repository (RepositoryPushEvent) Changes read from repository (RepositoryOtherReadEvent) Git hook activity (RepositoryHookEvent) Repository cloned (RepositoryCloneEvent) Repository pulled (RepositoryPullEvent) Repository written to (RepositoryOtherWriteEvent) |
Pull requests category
Base | Cascading merge failed (CascadingMergeStoppedEvent) |
---|---|
Advanced | Pull request filters used (PullRequestFilterEvent) |
Full | Pull request comment changed (PullRequestCommentEditedEvent) |
Search category
Base | No events available |
---|---|
Advanced | No events available |
Full | Code search succeeded (CodeSearchSuccessfulEvent) |
Apps category
This category is for auditing events generated by third-party apps.
Bitbucket Data Center customers can set the configuration property audit.legacy.events.logging.forced=true
to move the following events from Full to Base level:
- Plugin container unavailable, Plugin module disabled, Plugin module enabled, Plugin module available, Plugin framework started
- User log in failed, User logged in, User logged in (SSH)
- Repository read event, Repository write event, Repository pull event, Repository push event, Git hook activity, Repository cloned
Note that adding these events to Base can significantly increase the size of the audit log.
2SV configuration audit events
Events related to configuration are expected to happen rarely.
User enabled 2SV
Level | BASE |
Coverage Area |
|
Category | 2SV configuration |
Summary | 2SV enabled for user |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | Method: TOTP Enforced: |
User disabled 2SV
Level | BASE |
Coverage Area |
|
Category | 2SV configuration |
Summary | 2SV disabled for user |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | Method: TOTP |
User changed 2SV auth app
Level | BASE |
Coverage Area |
|
Category | 2SV configuration |
Summary | 2SV reset for user |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | Method: TOTP |
Recovery Key regenerated
Level | BASE |
Coverage Area |
|
Category | 2SV configuration |
Summary | 2SV recovery key regenerated |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) |
|
System admin unenrolled other user
Level | BASE |
Coverage Area |
|
Category | 2SV configuration |
Summary | 2SV disabled for user |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | Method: TOTP |
Identity verification login events
Events triggered during identity verification, such as login or elevating session, are expected to fail rarely, but they are still possible.
System admin login without 2SV
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | user (system admin/admin) |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) |
|
Failed login attempt with 2SV
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | Failed 2SV login |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | method used: |
Successful login with 2SV
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | Successful 2SV login |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | method used: |
Failed session elevation
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | Failed session elevation |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | method used: |
Successful session elevation
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | Successful session elevation |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | method used: |
User rate-limited
Level | BASE |
Coverage Area |
|
Category | Identity verification |
Summary | User rate-limited |
Affected object(s) | user |
Changed value(s) |
|
Extra attribute(s) | Number of consecutive failures: Backoff time (in seconds): Unblocked at: |