Skip to main content

Operations Tab

The Operations tab on an output Properties window is where monitoring scope by operation can be modified. These settings are initially configured when the output is added.

Select an output from the Monitored Hosts tab and click Edit to open the output Properties window. The tab varies based on the type of host selected.

For Linux Hosts

The tab contains the following settings and features:

linux

Use the options in the Operations tab to filter the list of available audit activities. The options are:

  • File Operations – Scope by file operation events: Add, Delete, Rename, Permission change, Read, Update
  • Directory Operations – Scope by directory operation events: Add, Delete, Rename, Permission change, Read / List

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For Microsoft Entra ID Hosts

The tab contains the following settings and features:

Host Properties - Azure AD Operations tab

  • Monitor Sign-Ins activity – Indicates if user sign-ins activity is monitored
  • Monitor Audit activity – Indicates if audit for all operations is monitored
  • Service – Filter the table by Service using the drop-down menu
  • Category – Filter the table by Category using the drop-down menu
  • Operation – Filter the table by Operation using the textbox

The table lists operations being monitored, displaying columns for Service, Category, and Operation.

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For Nasuni Hosts

The tab contains the following settings and features:

  • File Operations – Scope by file operation events: Add, Delete, Rename, Permission change, Read, Update
  • Directory Operations – Scope by directory operation events: Add, Delete, Rename, Permission change, Read / List
  • Link Operations – Scope by link operation events: Add, Delete
  • Suppress reporting of File Explorer's excessive directory traversal activity – When you open a folder, Windows File Explorer tends to read all sub-folders to display proper icons and meta-data. This activity occurs without the explicit intent of the user. This option tries to suppress such automatic activity. It is only available when the Read / List option for Directory Operations is selected.
  • Suppress reporting of File Explorer's excessive file read activity – When you open a folder, Windows File Explorer tends to read files in the folder to display proper icons and meta-data. This activity occurs without the explicit intent of the user. This option tries to suppress such automatic activity. It is only available when the Read option for File Operations is selected.
  • Suppress Microsoft Office operations on temporary files – Filters out events for Microsoft Office temporary files. When Microsoft Office files are saved or edited, many temporary files are created. With this option enabled, events for these temporary files are ignored.
  • Suppress operations on common temporary files – Filters out events for common temporary files. With this option enabled, events for these common temporary files are ignored.
  • Suppress duplicate operations for [VALUE] seconds

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For Nutanix Hosts

The tab contains the following settings and features:

operations

  • File Operations – Scope by file operation events: Add, Delete, Rename, Permission change, Read, Update
  • Directory Operations – Scope by directory operation events: Add, Delete, Rename, Permission change

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For Qumulo Hosts

The tab contains the following settings and features:

qumulooutputproperties

  • File Operations – Scope by file operation events: Add, Delete, Rename, Permission change, Read, Update
  • Directory Operations – Scope by directory operation events: Add, Delete, Rename, Permission change, Read / List
  • Share Operations – Scope by share operation events: Add, Delete, Update, Read / Connect
  • Suppress operations on common temporary files – Filters out events for common temporary files. With this option enabled, events for these common temporary files are ignored.

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For SharePoint Host

The tab contains the following settings and features:

Operations Tab for SharePoint

  • SharePoint operations – Scope by SharePoint operation events: Check-Out, View, Update, Child Delete, Undelete, Copy, Audit Mask Change, Child Move, Custom, Check-In, Delete, Profile Change, Schema Change, Workflow, Move, Search, File Fragment Write
  • Permission Operations – Scope by permission operation events: Creation of a user group, Addition of a new member to a group, creation of a new role, Changing a role, Changing the permissions of a user or group, Turning off inheritance of security settings, Granting App Permissions, Deletion of a group, Deletion of a member from a group, Removal of a role, Turning off inheritance of role, Turning on inheritance of security settings, Deletion of audited events, Revoking App Permissions

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For SharePoint Online Host

The tab contains a subset of tabs. Each tab has a Select All check box to include all events for that tab.

Operations Tab for SharePoint Online Properties

You can scope by the following events:

TabEvent
Content ExplorerAccessed item
DLPDesignated false positive
DLPMatched DLP rule
DLPUndone DLP action
File and PageAccessed File
File and PageAccessed File (ext)
File and PageChanged compliance policy label
File and PageChanged record status to locked
File and PageChanged record status to unlocked
File and PageChecked in file
File and PageChecked out file
File and PageCopied file
File and PageDeleted file
File and PageDeleted file from recycle bin
File and PageDeleted file from second-stage recycle bin
File and PageDeleted record compliance policy label
File and PageDetected document sensitivity mismatch
File and PageDetected malware in file
File and PageDiscarded file checkout
File and PageDownloaded file
File and PageModified file
File and PageModified file (ext)
File and PageMoved file
File and PagePerformed search query
File and PagePrefetched page
File and PagePreviewed file
File and PageRecycled all minor versions of file
File and PageRecycled all versions of file
File and PageRecycled version of file
File and PageRenamed file
File and PageRestored file
File and PageUploaded file
File and PageView signaled by client
File and PageViewed page
File and PageViewed page (ext)
FolderCopied folder
FolderCreated folder
FolderDeleted folder
FolderDeleted folder from recycle bin
FolderDeleted folder from second-stage recycle bin
FolderModified folder
FolderMoved folder
FolderRenamed folder
FolderRestored folder
ListCreated list
ListCreated list column
ListCreated list column
ListCreated list content type
ListCreated list item
ListCreated site column
ListCreated site content type
ListDeleted list
ListDeleted list column
ListDeleted list content type
ListDeleted list item
ListDeleted site column
ListDeleted site content type
ListRecycled list item
ListRestored list
ListRestored list item
ListUpdated list
ListUpdated list column
ListUpdated list content type
ListUpdated list item
ListUpdated site column
ListUpdated site content type
OtherOther events
Sensitive LabelApplied sensitivity label to file
Sensitive LabelApplied sensitivity label to site
Sensitive LabelChanged sensitivity label applied to file
Sensitive LabelRemoved sensitivity label from file
Sensitive LabelRemoved sensitivity label from site
Sharing and Access RequestAccepted access request
Sharing and Access RequestAccepted sharing invitation
Sharing and Access RequestAdded permission level to site collection
Sharing and Access RequestBlocked sharing invitation
Sharing and Access RequestCreated a company shareable link
Sharing and Access RequestCreated access request
Sharing and Access RequestCreated an anonymous link
Sharing and Access RequestCreated secure link
Sharing and Access RequestCreated sharing invitation
Sharing and Access RequestDeleted secure link
Sharing and Access RequestDenied access request
Sharing and Access RequestRemoved a company shareable link
Sharing and Access RequestRemoved an anonymous link
Sharing and Access RequestShared file, folder, or site
Sharing and Access RequestUnshared file, folder, or site
Sharing and Access RequestUpdated access request
Sharing and Access RequestUpdated an anonymous link
Sharing and Access RequestUpdated sharing invitation
Sharing and Access RequestUsed a company shareable link
Sharing and Access RequestUsed an anonymous link
Sharing and Access RequestUsed secure link
Sharing and Access RequestUser added to secure link
Sharing and Access RequestUser removed from secure link
Sharing and Access RequestWithdrew sharing invitation
Site AdministrationAdded allowed data location
Site AdministrationAdded exempt user agent
Site AdministrationAdded geo location admin
Site AdministrationAllowed user to create groups
Site AdministrationCanceled site geo move
Site AdministrationChanged a sharing policy
Site AdministrationChanged device access policy
Site AdministrationChanged exempt user agents
Site AdministrationChanged network access policy
Site AdministrationCompleted site geo move
Site AdministrationCreated Sent To connection
Site AdministrationCreated site collection
Site AdministrationDeleted orphaned hub site
Site AdministrationDeleted Sent To connection
Site AdministrationDeleted site
Site AdministrationEnabled document preview
Site AdministrationEnabled legacy workflow
Site AdministrationEnabled Office on Demand
Site AdministrationEnabled result source for People Searches
Site AdministrationEnabled RSS feeds
Site AdministrationJoined site to hub site
Site AdministrationRegistered hub site
Site AdministrationRemoved allowed data location
Site AdministrationRemoved geo location admin
Site AdministrationRenamed site
Site AdministrationScheduled site geo move
Site AdministrationSet host site
Site AdministrationSet storage quota for geo location
Site AdministrationUnjoined site from hub site
Site AdministrationUnregistered hub site
Site PermissionsAdded site collection admin
Site PermissionsAdded user or group to SharePoint group
Site PermissionsBroke permission level inheritance
Site PermissionsBroke sharing inheritance
Site PermissionsCreated group
Site PermissionsDeleted group
Site PermissionsModified access request setting
Site PermissionsModified 'Members Can Share' setting
Site PermissionsModified permissions level on site collection
Site PermissionsModified site permissions
Site PermissionsRemoved permission level from site collection
Site PermissionsRemoved site collection admin
Site PermissionsRemoved user or group from SharePoint group
Site PermissionsRequested site admin permissions
Site PermissionsRestored sharing inheritance
Site PermissionsUpdated group
SynchronizationAllowed computer to sync files
SynchronizationBlocked computer from syncing files
SynchronizationDownloaded file changes to computer
SynchronizationDownloaded files to computer
SynchronizationUploaded file changes to document library
SynchronizationUploaded files to document library

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For SQL Server Hosts

The tab contains the following settings and features:

sql

  • DML operations – Scope by DML operation events: Select, Update, Merge, Insert, Delete, Execute
  • Audit operations – Scope by audit operation events: Login, Logout, Login Failed, Error
  • Permission operations – Scope by permission operation events: Grant, Deny, Revoke, Alter Role
  • Suppress subsequent logon/logout events from the same user in [VALUE] minutes interval

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

For Windows File Server Hosts

The tab contains the following settings and features:

Operations Tab for File System

  • Operation Type – Scope events by operation type:

    • All – Both allowed and denied operations
    • Allowed only – Only allowed operations
    • Denied only – Only denied operations
  • File Operations – Scope by file operation events: Add, Delete, Rename, Permission change, Read, Update

  • Directory Operations – Scope by directory operation events: Add, Delete, Rename, Permission change, Read / List

  • Share Operations – Scope by share operation events: Add, Delete, Update, Permission change

  • VSS Operations – Scope by VSS operation events: Snapshot add, Snapshot delete, Read

  • Suppress reporting of File Explorer's excessive directory traversal activity – When you open a folder, Windows File Explorer tends to read all sub-folders to display proper icons and meta-data. This activity occurs without the explicit intent of the user. This option tries to suppress such automatic activity. It is only available when the Read / List option for Directory Operations is selected.

  • Suppress reporting of File Explorer's excessive file read activity – When you open a folder, Windows File Explorer tends to read files in the folder to display proper icons and meta-data. This activity occurs without the explicit intent of the user. This option tries to suppress such automatic activity. It is only available when the Read option for File Operations is selected.

  • Suppress Permission Change operations with reordered ACL – Prevents tracking events where permission updates occurred resulting in reordered ACEs, but with no other changes in the ACL

  • Suppress Inherited Permissions Changes – Prevents tracking events where changes for inherited permissions occurred. This option is provided to improve overall performance and reduce output log volume.

  • Suppress Microsoft Office operations on temporary files – Filters out events for Microsoft Office temporary files. When Microsoft Office files are saved or edited, many temporary files are created. With this option enabled, events for these temporary files are ignored.

  • Suppress operations on common temporary files – Filters out events for common temporary files. With this option enabled, events for these common temporary files are ignored.

  • Suppress duplicate operations for [VALUE] seconds

Click OK to commit the modifications. Click Cancel to discard the modifications. The output Properties window closes.

SeeSuppress Windows Explorer Activity topic for more information.