runZero events

View as Markdown

runZero records system events for administrative actions, alert rule processing, scans, Explorers, API activity, and more. Use an event action below as the trigger for an alert rule, or search for it in the audit log.

207 of 207 events

Inventory queries (post-task)

asset-query-results
Run an asset inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery conditionCan modify assets
certificate-query-results
Run a certificate inventory query against the site after analysis completes.
Target type: certificate
Task conditionQuery condition
group-query-results
Run a group inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery condition
service-query-results
Run a service inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery conditionCan modify assets
software-query-results
Run a software inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery conditionCan modify assets
user-query-results
Run a user inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery condition
vulnerability-query-results
Run a vulnerability inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery conditionCan modify assets
wireless-query-results
Run a wireless inventory query against the site after analysis completes.
Target type: asset
Task conditionQuery condition

Asset changes (post-task)

assets-back-online
Assets back online.
Target type: asset
Task conditionThreshold condition
assets-changed
Assets changed.
Target type: asset
Task conditionThreshold condition
assets-now-offline
Assets now offline.
Target type: asset
Task conditionThreshold condition
new-assets-found
New assets found.
Target type: asset
Task conditionThreshold condition

Explorer and scan events

agent-diagnostics-updated
Explorer diagnostics are updated.
Target type: agent
agent-forget-all
All inactive explorers are deleted.
Target type: organization
agent-offline
An explorer goes offline for more than 30 minutes. This event repeats every four hours for offline explorers.
Target type: organization
agent-organization-reassigned
An explorer is reassigned to a different organization.
Target type: agent
agent-reconnected
An explorer that was offline reconnects.
Target type: organization
agent-registered
A new explorer registers with runZero.
Target type: organization
agent-removed
An explorer is removed from the account.
Target type: agent
agent-removed-all
All explorers are removed from an organization.
Target type: organization
agent-removed-multiple
Multiple explorers are removed from an organization.
Target type: organization
agent-set-tags-multiple
Explorer tags are updated.
Target type: agent
agent-settings-updated
Explorer settings are updated.
Target type: agent
agent-site-assigned-all
All explorers are automatically assigned to sites.
Target type: organization
agent-software-updated
Explorer software is updated.
Target type: agent
agent-software-updated-all
All explorer software for an organization is updated.
Target type: organization
agent-software-updated-multiple
Explorer software update is manually triggered for multiple explorers.
Target type: agent
agent-updated
An explorer has changed its network configuration.
Target type: organization
speedtest-completed
A speed test completed.
Target type: agent
speedtest-deleted
A speed test report was deleted by the user.
Target type: explorer-report
speedtest-started
A speed test was manually scheduled by the user.
Target type: agent
task-failed
A scan task fails to complete.
Target type: site

Security-related events

auth-login-link-completed
A one-time login link is used successfully.
Target type: user
auth-login-link-request
A user requests a login link.
Target type: user
auth-mfa-added
Multi-factor authentication credentials are added to a user account.
Target type: user
auth-mfa-removed
Multi-factor authentication credentials are removed from a user account.
Target type: user
auth-password-reset-completed
A password reset is completed successfully.
Target type: user
auth-password-reset-request
A user requests a password reset.
Target type: user
client-switched
A user switches to a different account.
Target type: client
credential-created
A set of credentials is created.
Target type: credential
credential-removed
A set of credentials is removed.
Target type: credential
credential-updated
A set of credentials is updated.
Target type: credential
group-created
A new group is created.
Target type: group
group-mapping-created
A new group mapping is created.
Target type: group-mapping
group-mapping-removed
A group mapping is removed.
Target type: group-mapping
group-mapping-updated
A group mapping is updated.
Target type: group-mapping
group-removed
A group is removed.
Target type: group
group-updated
A group's information is updated.
Target type: group
login
A user logs in.
Target type: client
login-failed
A user fails to login.
Target type: client
login-mfa
A user logs in using multi-factor authentication.
Target type: client
login-sso
A user logs in using SSO.
Target type: client
login-sso-begin
A user begins logging in using SSO.
Target type: client
login-sso-enroll
A new user is created via SSO enrollment.
Target type: client
role-created
A custom role is created.
Target type: role
role-deleted
A custom role is deleted.
Target type: role
role-updated
A custom role's name, description or permissions are changed.
Target type: role
sso-settings-updated
The SSO settings are changed.
Target type: client
sso-user-activated
An SSO user activated with runZero.
Target type: client
user-activated
An external user activated with runZero.
Target type: client
user-added-to-group
A user is added to a group.
Target type: group
user-demoted
A user is demoted from superuser
Target type: user
user-invite-current
A user is invited to join the current organization.
Target type: user
user-invite-external
An external user is invited to join a team.
Target type: user
user-invite-resent
A user invitation is resent.
Target type: user
user-invite-restricted
A user is invited to join a team with restricted permissions.
Target type: user
user-invite-team
A user is invited to join a team.
Target type: user
user-mfa-reset
A user resets their multi-factor authentication settings.
Target type: user
user-password-reset
A user resets their password.
Target type: user
user-promoted
A user is promoted to superuser.
Target type: user
user-registered
A new user registers with runZero.
Target type: client
user-removed
A user is deleted.
Target type: user
user-removed-from-group
A user is removed from a group.
Target type: group
users-csv-import
Multiple users are imported from a CSV file.
Target type: user

Risk management events

findings-with-instances
Findings instances found or updated (triggered when results change).
Target type: finding
rapid-response-published
A Rapid Response query is published or updated.
Target type: query
rapid-response-with-matches
Rapid Response matches are found (triggered when results change).
Target type: query

API-related events

api-client
A request was made to the Account API.
Target type: client
api-client-created
An API client is created.
Target type: client
api-client-removed
An API client is removed.
Target type: client
api-client-secret-rotated
The secret for an API client is rotated.
Target type: client
api-client-updated
An API client is updated.
Target type: client
api-export
A request was made to the Export API.
Target type: organization
api-mcp-session-active
An MCP session made calls or changed address (periodic summary).
Target type: client
api-mcp-session-ended
An MCP session ended or went idle.
Target type: client
api-mcp-session-started
An MCP client connected with an API key or API client.
Target type: client
api-organization
A request was made to the Organization API.
Target type: organization
client-api-key-created
A client API key is created.
Target type: client
client-api-key-removed
A client API key is deleted.
Target type: client
client-api-key-rotated
The secret for a client API key is rotated.
Target type: client
custom-asset-source-created
A custom asset source is created.
Target type: custom-asset-source
custom-asset-source-removed
A custom asset source is removed.
Target type: custom-asset-source
custom-asset-source-updated
A custom asset source is updated.
Target type: custom-asset-source
mcp-oauth-consent-approved
A user authorized an MCP client, creating an API client.
Target type: client
mcp-oauth-consent-denied
A user refused an MCP client's request for access.
Target type: client
organization-api-key-created
An organization API key is created.
Target type: organization
organization-api-key-removed
An organization API key is removed.
Target type: organization
organization-api-key-rotated
The secret for an organization API key is rotated.
Target type: organization
organization-download-token-reset
The download token for an organization is reset.
Target type: organization
organization-export-token-created
An export token for an organization is created.
Target type: organization
organization-export-token-removed
The export token for an organization is removed.
Target type: organization
organization-export-token-reset
The export token for an organization is reset.
Target type: organization

All other events

account-ai-settings-updated
Account AI (LLM) provider configuration is updated.
Target type: account
account-settings-updated
Account settings are updated.
Target type: account
ai-budget-exceeded
An AI daily limit was reached (platform token allowance, or a per-day input/output token cap) for the account or an organization.
Target type: account
ai-budget-warning
AI usage crossed the daily-limit warning threshold (75% of the platform token allowance or a token cap) for the account or an organization.
Target type: account
ai-report-generated
An AI report (deep analysis, organization report, or chat answer) was generated.
Target type: organization
alert-acknowledge
An alert is acknowledged (cleared).
Target type: organization
alert-acknowledge-all
All alerts are acknowledged (cleared).
Target type: organization
alert-channel-created
An alert channel is created.
Target type: organization
alert-channel-removed
An alert channel is removed.
Target type: organization
alert-channel-updated
An alert channel is updated.
Target type: organization
alert-clear-all
All alerts for an organization are cleared.
Target type: organization
alert-rule-created
An alert rule is created.
Target type: organization
alert-rule-removed
An alert rule is removed.
Target type: organization
alert-rule-updated
An alert rule is updated.
Target type: organization
alert-template-created
An alert template is created.
Target type: organization
alert-template-removed
An alert template is removed.
Target type: organization
alert-template-updated
An alert template is updated.
Target type: organization
asset-clear-tags-multiple
Tags are cleared on multiple assets at once.
Target type: organization
asset-csv-import
Asset information is exported as CSV.
Target type: organization
asset-fingerprint-submitted
An asset fingerprint is submitted to runZero, Inc.
Target type: asset
asset-merge-multiple
Multiple assets are merged into a single asset.
Target type: organization
asset-owners-removed
Asset owners are removed.
Target type: asset
asset-owners-updated
Asset owners are updated.
Target type: asset
asset-removed
An asset is deleted.
Target type: asset
asset-removed-multiple
Multiple assets are deleted from an organization.
Target type: organization
asset-set-comments
A comment is set on an asset.
Target type: asset
asset-set-comments-multiple
A comment is set on multiple assets at once.
Target type: organization
asset-set-criticality
Criticality is set on an asset.
Target type: asset
asset-set-criticality-multiple
Criticality is set on multiple assets at once.
Target type: organization
asset-set-risk-multiple
Risk is set on multiple assets at once.
Target type: organization
asset-set-tags
Tags are set on assets.
Target type: asset
asset-set-tags-multiple
Tags are set on multiple assets at once.
Target type: organization
assets-expired
One or more assets have expired and have been removed.
Target type: organization
assets-purged
All asset data is deleted from an organization.
Target type: organization
directory-group-removed-multiple
Directory groups are been removed from the directory groups inventory.
Target type: directory-group
directory-user-removed-multiple
Directory users are been removed from the directory users inventory.
Target type: directory-user
findings-suppressed
Findings were suppressed.
Target type: finding
findings-unsuppressed
Findings were unsuppressed.
Target type: finding
goal-completed
A goal is completed.
Target type: client
goal-created
A goal is created.
Target type: organization
goal-lapsed
A goal is no longer completed.
Target type: client
goal-removed
A goal is removed.
Target type: organization
goal-updated
A goal is updated.
Target type: organization
insight-clear
A computed insight result is cleared.
Target type: insight
insight-clear-all
All computed insight results are cleared.
Target type: insight
instance-registered
A new self-hosted instance has been registered.
Target type: client
issue-closed
An issue is closed.
Target type: issue
issue-opened
An issue is opened.
Target type: issue
issue-status-updated
An issue's status is updated.
Target type: issue
issues-overdue
One or more open issues are past their due date.
Target type: issue
issues-reoccurred
One or more issues have recently re-occurred.
Target type: issue
license-changed
The runZero license entitlement changes.
Target type: client
license-limit-exceeded
The asset count has exceeded the runZero license limit.
Target type: client
nessus-import
Nessus data is imported.
Target type: organization
nexpose-import
Nexpose data is imported.
Target type: organization
org-ai-settings-updated
Organization AI (LLM) provider configuration is updated.
Target type: organization
organization-created
A new organization is created.
Target type: client
organization-purged
All assets for an organization are purged.
Target type: organization
organization-removed
An organization is deleted.
Target type: client
organization-updated
An organization is modified.
Target type: organization
ownership-type-created
An ownership type is created.
Target type: client
ownership-type-removed
An ownership type is removed.
Target type: client
ownership-type-updated
An ownership type is updated.
Target type: client
packet-import
Pcap data is imported.
Target type: organization
query-created
A saved query is created.
Target type: client
query-imported
A saved query is imported.
Target type: client
query-removed
A saved query is deleted.
Target type: client
query-updated
A saved query is modified.
Target type: client
report-removed
A computed insight report is removed.
Target type: report
scan-completed
Scan completed.
Target type: asset
Task condition
scan-created
A new scan task is created.
Target type: site
scan-import
Scan data is imported.
Target type: organization
scan-template-created
A scan template is created.
Target type: client
scan-template-removed
A scan template is removed.
Target type: client
scan-template-updated
A scan template is updated.
Target type: client
scan-updated
A scan task is modified.
Target type: site
service-removed-multiple
Multiple service records are deleted.
Target type: organization
site-created
A new site is created.
Target type: organization
site-imported
Site data is imported as CSV.
Target type: organization
site-removed
A site is deleted.
Target type: organization
site-updated
A site is updated.
Target type: site
software-removed-multiple
Multiple software records are deleted.
Target type: organization
task-completed
A scan task completes.
Target type: site
task-created
A task is created.
Target type: task
task-hidden
A (failed) task is hidden.
Target type: task
task-last-started-ts-cleared
A task's last started at timestamp is cleared.
Target type: task
task-paused
A task is paused.
Target type: task
task-reprocessed
A completed task is queued to have its data processed again.
Target type: task
task-started
A task is started.
Target type: site
task-stopped
A task is stopped.
Target type: task
task-stopped-all
All tasks are stopped.
Target type: organization
task-unpaused
A task is unpaused.
Target type: task
user-password-disabled
A user disabled password authentication.
Target type: user
user-settings-updated
A user updates their settings.
Target type: user
user-unlocked
A user's account is unlocked.
Target type: user
user-updated
A user's information is updated.
Target type: user
vulnerabilities-suppressed
Vulnerabilities were suppressed.
Target type: vulnerabilities
vulnerabilities-unsuppressed
Vulnerabilities were unsuppressed.
Target type: vulnerabilities
vulnerability-groups-suppressed
Vulnerability groups were suppressed.
Target type: vulnerability-groups
vulnerability-groups-unsuppressed
Vulnerability groups were unsuppressed.
Target type: vulnerability-groups
vulnerability-owners-removed
Vulnerability owners are removed.
Target type: vulnerability
vulnerability-owners-updated
Vulnerability owners are updated.
Target type: vulnerability
vulnerability-set-risk
Risk is set on a vulnerability.
Target type: organization
vulnerability-set-risk-multiple
Risk is set on multiple vulnerabilities at once.
Target type: organization
wireless-removed-multiple
Multiple discovered wireless LANs are deleted.
Target type: organization