Skip to content
Docs
foxborne.comRequest a pilot

Audit log

Foxborne records every import, view, edit, export and administrative change in an append-only log. Each entry carries the hash of the one before it, so a missing or altered entry breaks the chain.

ReferenceMarkdown
On this page14

The audit log answers who did what to which object and when. It lives in an append-only table, streams to your SIEM over syslog with TLS and is never deleted. Admins and auditors open it from Audit log in the Administration group of the sidebar.

Columns#

ColumnWhat it shows
Time, UTCDay and time, such as 26 Sep 09:44:02
PersonThe person's name, or System with a bolt icon for automated steps
ActionAn icon for the action's area, then what happened, such as Viewed evidence
ObjectWhat it happened to: an incident or run ID, a rule ID, a version, a person or a settings area
DetailThe specifics, cut short on screen
EntryThe entry number and the first 8 hexadecimal characters of its hash

The log shows 25 entries a page, newest first, with the page controls under it.

Area icons#

Each Action cell opens with the icon of the area the action belongs to, the same icon that area carries in the sidebar. Hold the pointer over it for the area's name. An action outside these areas carries the Audit log icon.

AreaIconActions, for example
EvidenceAn eyeViewed evidence, Dismissed finding, Aligned clock by hand, Removed clock alignment
Incidents and reportsIncidentsOpened incident, Changed status, Edited report, Requested review, Approved report, Commented
ReportsReportsCreated report, Changed report, Deleted report, Generated report, Downloaded report, Paused report schedule, Resumed report schedule, Exported chart data
ExportsA download arrowRequested export, Approved export, Exported case file, Exported evidence, Exported audit log
Audit logA shieldVerified audit chain
ImportsImport filesImported run, Assembled run, Parsed run, Quarantined file, Rejected file, Ran rules again
Alert rulesAlertsCreated alert rule, Enabled alert rule, Changed alert rule
AutomationsAutomationsCreated automation, Enabled automation
Detection rulesRulesCreated rule, Enabled rule, Changed rule
Sources and collectorsSourcesAdded source, Paused source, Changed collector policy, Scheduled collector update
VehiclesVehiclesAdded vehicle
IntegrationsIntegrationsConfigured integration, Enabled egress, Sent test delivery, Replayed delivery, Turned on ingest endpoint
Access and sign-inAccessInvited user, Changed role, Signed in, Acknowledged notice, Changed SSO settings
SettingsSettingsChanged settings, Changed marking, Changed retention, Changed ordering bound
HostingHostingScheduled update, Installed update, Backup completed

The icon shows the area; the Evidence, Reports, Imports and Administration filters below group the same actions more broadly.

The hash chain#

entry n − 1Edited reportprev hash of entry n − 2hash SHA-256 of prev, action, object, detail, timeentry nChanged ruleprev hash of entry n − 1hash SHA-256 of prev, action, object, detail, timeentry n + 1Exported case fileprev hash of entry nhash SHA-256 of prev, action, object, detail, timeentry n − 1Edited reportprev hash of entry n − 2hash SHA-256 of prev, action, object, detail, timeentry nChanged ruleprev hash of entry n − 1hash SHA-256 of prev, action, object, detail, timeentry n + 1Exported case fileprev hash of entry nhash SHA-256 of prev, action, object, detail, time
Each entry stores the hash of the entry before it. Its own SHA-256 covers that hash with its action, object, detail and time, so editing or removing any entry breaks every hash after it.

In the example dataset the newest Entry cell reads #18,247 852d7dc9: the entry number, then the start of its hash. Hover over the cell to see both full hashes.

Entry tooltipFormat; each hash is 64 hexadecimal charactersText
Entry 18247, sha256:<hash of this entry>, previous <hash of the entry before it>

The tooltip prints the entry number without a thousands separator. Hashes appear nowhere else on screen.

Verify the chain#

Select Verify chain. The button reads Verifying while Foxborne works. The note above the log reads Verifying with the number of entries, then Recomputing each hash from the entry and the hash before it.

When every entry matches, the console confirms Chain intact. Every entry matches. The green note returns with the new count and time.

Audit log noteExample datasetText
Chain intact
18,247 entries verified, the latest at 09:44:02 UTC on 26 Sep. Entries also stream to your SIEM over syslog with TLS.

The check is itself recorded, as Verified audit chain on Audit log with a detail such as 18,019 entries intact. A missing or altered entry breaks the chain, which makes gaps and edits detectable.

Filter the log#

  • The segmented control picks a category: All, Evidence, Reports, Imports or Administration.
  • Filter by person, action or object matches those fields and the detail text. Type system to find automated entries.
  • The count reads, for example, Showing 27 of 18,247. The second number is the newest entry number.
  • The page address keeps both filters, such as /app/audit?kind=evidence&q=INC-0142, so a filtered view can be bookmarked.

The category follows the wording of the action. The tables below list every action under the category it files to.

Actions#

The Detail column shows a value from the example dataset, or the form the detail takes. Words in italics change from entry to entry.

Evidence#

ActionObjectDetail, for exampleRecorded by
Viewed evidenceINC-0142Kernel killed perception_node (out of memory)Anyone who opens the evidence
Aligned clock by handIncident IDOffset +11:03:04.916, ±1.04 sAdmin or investigator
Removed clock alignmentIncident IDCompanion clockAdmin or investigator
Dismissed findingIncident IDrule ID: reasonAdmin or investigator

Viewed evidence is written each time the evidence inspector or an event page opens, with the event's title as the detail.

Reports#

ActionObjectDetail, for exampleRecorded by
Opened incidentINC-0141Window 11:06:10 to 11:07:15. An incident opened with New incident reads run ID, count events, such as R-0930, 1 eventAdmin or investigator
Changed statusIncident IDOpen, In review or ClosedAdmin or investigator
Edited reportINC-0142Finding, revision 4Admin or investigator
Requested reviewINC-0142Reviewer: nameAdmin or investigator
Approved reportIncident IDSigned off by nameThe incident's reviewer
CommentedINC-0143Question on the lane historyAdmin, investigator or reviewer
Exported case fileIncident IDexport ID, PDF case file with CUI markings, stamped DRAFT, coordinates removedAdmin, investigator, reviewer or auditor
Requested exportIncident IDexport ID, formats, class to destination. Approver: nameThe person exporting
Exported audit logAudit logHashes includedAdmin or auditor
Created reportRP-05name, schedule, such as Weekly perception reliability, Mondays at 06:00 UTCAdmin, investigator or reviewer
Changed reportReport IDname, scheduleAdmin, investigator or reviewer
Deleted reportReport IDnameAdmin, investigator or reviewer
Generated reportRPT-0017name, start to end, such as Weekly fleet reliability, 14 Sep to 20 SepThe person who selected Generate now
Downloaded reportGenerated report IDfile name, sha256 first 16 hex digitsAnyone who downloads it
Paused report scheduleReport IDname, scheduleAdmin, investigator or reviewer
Resumed report scheduleReport IDname, scheduleAdmin, investigator or reviewer
Exported chart dataReportschart, range, vehicles, such as Rule results by rule, 27 Aug, 09:45 to 26 Sep, 09:45 UTC, All vehiclesAnyone who selects CSV

Edited report also carries details such as Sequence, added event ID and Resolved a question. Exported case file is written when the PDF case file is exported with no approval needed. Its detail adds ", stamped DRAFT" and ", coordinates removed" only when they apply.

Requested export is written when an export needs approval. Its detail names both approvers, as "Approvers:", when the export leaves the enclave. Export formats and evidence bundles sets out when each applies.

When the Generic webhook (HMAC) has egress on, Changed status also sends a case.status_changed event. When Jira Data Center has egress on and the incident has an issue, it also comments on that issue.

Imports#

ActionObjectDetail, for exampleRecorded by
Imported runR-09353 files from the fleet log archiveAdmin or investigator
Assembled runR-09343 files from 3 sourcesSystem
Parsed runRun IDcount files, rules produced count findingsSystem
Quarantined fileR-0933Truncated inside a data messageSystem
Rejected fileR-0932Encrypted logSystem
Ran rules againRun IDcount rules, same versionsThe person who ran them
Changed import limitSettings1 GBAdmin

A run imported by hand reads, for example, 1 file, manual upload.

Administration#

Sources and collectors

ActionObjectDetail, for exampleRecorded by
Added sourcesource nameAmazon S3, read-only test passedAdmin
Edited sourcesource nameConnection settingsAdmin
Synced sourcesource nameManual syncAdmin
Paused sourceLegacy journal shareShare migrationAdmin
Resumed sourcesource nameNo detailAdmin
Changed collector policyAll vehiclesUnits, processes and redactionAdmin
Added vehicleUAS-11Q4 recon quad, system ID 27Admin
Scheduled collector updateUAS-070.7.3 to 0.8.1Admin

Rules

ActionObjectDetail, for exampleRecorded by
Created rulelow_pack_voltageVersion 1.0: Below 21.0 V for 2 sAdmin
Enabled rulebattery_sagVersion 0.9Admin
Disabled rulerule IDVersion versionAdmin
Changed rulememory_pressureOverride for T4 vehicles: 24,576 MiB, version 1.1Admin

Hosting

ActionObjectDetail, for exampleRecorded by
Scheduled update1.4.3Signature and SBOM verifiedAdmin
Installed update1.4.2Signature verified, SBOM storedAdmin
Backup completedBackup vaultSnapshot of 18.4 GB, verifiedSystem

Access and sign-in

ActionObjectDetail, for exampleRecorded by
Acknowledged noticeSign-inSystem use noticeEveryone, at each sign-in
Signed inLocal accountBreak-glass admin with hardware keyThe break-glass account
Invited userwork emailInvestigatorAdmin
Changed rolenameReviewerAdmin
Removed usernameAccess revokedAdmin
Synced usersSCIM9 users, 5 groups, no changesSystem
Changed SSO settingsAccessMetadata refreshedAdmin
Changed session policyAccess30 minutes idle, 12 hours maxAdmin

Audit log and settings

ActionObjectDetail, for exampleRecorded by
Verified audit chainAudit log18,019 entries intactAdmin or auditor
Changed settingsOrganizationNameAdmin
Changed settingsSystem use noticeText updatedAdmin
Changed markingSettingsBanner shownAdmin
Changed markingSettingsCUI, EXPTAdmin
Changed retentionSettings2 years after importAdmin
Changed redactionSettingsCoordinates on export: removedAdmin
Changed redactionSettings4 patternsAdmin
Changed ordering boundSettings1.0 sAdmin

Integrations

ActionObjectDetail, for exampleRecorded by
Configured integrationdestination, such as Mattermostfirst host, protocol, class: chat.hfr.internal:443, Incoming webhook, HTTPS POST, L0The person who saves the settings
Sent test deliverydestinationDelivered to host, response, or Failed to reach host, responseThe person who sends the test
Enabled egressdestination, such as Splunk HECL1 to splunk-hec.hfr.internal:8088, plus ", confirmed by" the admin when another admin confirmedAn admin, or the person at the keyboard with an admin confirming
Disabled egressdestinationStopped deliveries to hostThe person who turns it off
Turned on ingest endpointendpoint, such as journald receiverListening on HTTPS 19532Admin
Turned off ingest endpointendpointNo longer listeningAdmin
Replayed deliverydestination, such as Generic webhook (HMAC)delivery, delivered on attempt number: run.closed_out, R-0934, delivered on attempt 6The person who replays it

Alerts and automations

ActionObjectDetail, for exampleRecorded by
Created alert ruleR7Low pack voltage in flight, MediumThe person who creates it
Enabled alert ruleR1Vibration above threshold (tracked-UGV profile), version 1.0The person who switches it on
Disabled alert rulerule IDrule name, version versionThe person who switches it off
Changed alert ruleR1Version 1.1: condition, severity and routing, destinationsThe person who saves the edit
Created automationA5Jamming report to range safetyThe person who creates it
Enabled automationA1Sortie closeout triageThe person who switches it on
Disabled automationautomation IDautomation nameThe person who switches it off

Changed alert rule lists only the parts that changed. With every part changed, it reads condition, severity and routing, destinations. In the example dataset, one admin configured and tested each destination, and a second admin turned on its egress.

Export the audit log#

Select Export. The Export the audit log dialog notes The export includes each entry’s hash and the hash before it, so it can be verified offline.

FieldChoices
FormatJSON Lines, the default, or CSV
RangeLast 7 days, Last 30 days or Everything

Select Export. The console confirms Audit log exported with hashes, and the export is itself recorded as Exported audit log with the detail Hashes included.

Each exported entry carries its own hash and the one before it. A reviewer holding the file can check the chain away from the deployment.

Stream to your SIEM#

When the Syslog over TLS destination has egress on, Foxborne forwards each entry as it is written, one syslog message per entry. Each message carries the entry's marking, number, time, person, action, object and detail, with its hash and the prev hash before it.

The Hosting page lists the stream under Outbound connections as Your SIEM, for example "Audit log and delivery ledger, syslog over TLS to logs.soc.hfr.internal:6514. Data class L1." The Delivery ledger tab of Integrations lists each forwarded entry under Audit stream, such as Audit entry 18,247, Viewed evidence.

Forward logs to your SIEM covers the setup and the message format.

Storage and retention#

PropertyValue
WhereAn append-only table in PostgreSQL, streamed to your SIEM
EncryptionYour customer-managed key
RetentionNever deleted
ReadersAdmins and auditors