Skip to content

Audit Log

hxEASM has a dedicated append-only Audit Log for significant user and administrator actions.

The Audit Log answers:

  • who performed the action
  • when it happened
  • which action and event type occurred
  • which resource/entity was affected
  • what changed
  • which organization was involved, when applicable

Audit Log is separate from Exposure Changes and Asset History. Exposure Changes describe attack-surface and security state changes. Asset History describes what happened to one specific Asset over time. Audit Log describes user/admin actions and configuration changes.

Ordinary GET requests and background reads are not audited.

Storage

Audit events are stored in the main PostgreSQL database in audit_logs.

The table is append-only through normal application APIs. hxEASM does not expose update or delete Audit Log endpoints.

Audit rows include:

  • actor user ID
  • actor username snapshot
  • actor role snapshot
  • organization ID
  • action
  • event type
  • resource type and ID
  • old values
  • new values
  • metadata
  • IP address
  • User-Agent
  • timestamp

Audit rows may grow over time. Retention, partitioning, SIEM export, and immutable external storage are future operational options and are not implemented in this release.

Actions and Event Types

action is a broad category, such as:

  • create
  • update
  • delete
  • status_change
  • criticality_change
  • approve
  • disable
  • enable
  • role_change
  • permission_change
  • settings_change

event_type is a stable specific identifier, such as:

  • asset.created.manual
  • asset.lifecycle.updated
  • asset.criticality.updated
  • asset.bulk_approved
  • vulnerability.created.manual
  • vulnerability.status_changed
  • vulnerability.has_exploit.changed
  • scope.created
  • scope.updated
  • scope.deleted
  • scope.approved
  • scan_profile.created
  • scan_profile.updated
  • scan_profile.deleted
  • scan_settings.auto_approve_discovered_assets.changed
  • plugin.settings.updated
  • user.role_changed
  • user.organizations_changed
  • 2fa.settings_changed
  • api_key.created
  • api_key.revoked
  • notification.settings.updated

Audited Events

The current implementation records meaningful user-driven mutations for:

  • manual Asset creation
  • Asset lifecycle changes
  • Asset criticality changes
  • bulk Asset approval
  • manual vulnerability creation
  • vulnerability status changes
  • vulnerability exploit-flag changes
  • Scope create/update/delete/approve/reject
  • custom scan profile create/update/delete
  • global scan setting changes
  • plugin settings updates
  • user approval, role, status, and organization-assignment changes through existing auth audit writes
  • global 2FA policy updates
  • user 2FA enable/disable and recovery-code regeneration through existing auth audit writes
  • API key creation/revocation without storing key material
  • notification settings updates
  • vulnerability comment creation and update

Old and New Values

Update events store minimal diffs where practical.

Example:

{
  "old_values": { "status": "new" },
  "new_values": { "status": "active", "close_reason": null }
}

The Audit Log does not store entire entity snapshots when only a small field changed.

Secret Redaction

Audit records never intentionally store secrets.

Keys containing sensitive terms are redacted before insertion, including:

  • password
  • secret
  • token
  • API key
  • Authorization
  • JWT
  • OTP / TOTP
  • recovery code

Plugin and notification settings are audited through the same redaction path.

Vulnerability discussion audit entries store safe metadata and visibility/mention diffs only. Full comment bodies are not copied into audit rows.

API

Admin-only endpoint:

GET /api/v1/admin/audit

Supported filters:

  • user_id
  • action
  • event_type
  • resource_type
  • resource_id
  • organization_id
  • from
  • to
  • page
  • page_size

Default page size is 50. Maximum page size is 200.

Results are sorted newest first.

UI

The Audit Log is available in:

Settings -> Administration -> Audit Log

Only administrators can view it.

Limitations

  • Audit logging is best-effort for most domain mutations.
  • Some older auth and 2FA events were written by legacy audit helpers and may have less detailed old/new values.
  • There is no retention policy in this release.
  • There is no SIEM export in this release.
  • There is no tamper-evident hash chain in this release.