runZero events
runZero records system events for administrative actions, alert rule processing, scans, Explorers, API activity, and more. Use an event action below as the trigger for an alert rule, or search for it in the audit log.
207 of 207 events
Inventory queries (post-task)
asset-query-resultsRun an asset inventory query against the site after analysis completes.
Target type: asset
certificate-query-resultsRun a certificate inventory query against the site after analysis completes.
Target type: certificate
group-query-resultsRun a group inventory query against the site after analysis completes.
Target type: asset
service-query-resultsRun a service inventory query against the site after analysis completes.
Target type: asset
software-query-resultsRun a software inventory query against the site after analysis completes.
Target type: asset
user-query-resultsRun a user inventory query against the site after analysis completes.
Target type: asset
vulnerability-query-resultsRun a vulnerability inventory query against the site after analysis completes.
Target type: asset
wireless-query-resultsRun a wireless inventory query against the site after analysis completes.
Target type: asset
Asset changes (post-task)
assets-back-onlineAssets back online.
Target type: asset
assets-changedAssets changed.
Target type: asset
assets-now-offlineAssets now offline.
Target type: asset
new-assets-foundNew assets found.
Target type: asset
Explorer and scan events
agent-diagnostics-updatedExplorer diagnostics are updated.
Target type: agent
agent-forget-allAll inactive explorers are deleted.
Target type: organization
agent-offlineAn explorer goes offline for more than 30 minutes. This event repeats every four hours for offline explorers.
Target type: organization
agent-organization-reassignedAn explorer is reassigned to a different organization.
Target type: agent
agent-reconnectedAn explorer that was offline reconnects.
Target type: organization
agent-registeredA new explorer registers with runZero.
Target type: organization
agent-removedAn explorer is removed from the account.
Target type: agent
agent-removed-allAll explorers are removed from an organization.
Target type: organization
agent-removed-multipleMultiple explorers are removed from an organization.
Target type: organization
agent-set-tags-multipleExplorer tags are updated.
Target type: agent
agent-settings-updatedExplorer settings are updated.
Target type: agent
agent-site-assigned-allAll explorers are automatically assigned to sites.
Target type: organization
agent-software-updatedExplorer software is updated.
Target type: agent
agent-software-updated-allAll explorer software for an organization is updated.
Target type: organization
agent-software-updated-multipleExplorer software update is manually triggered for multiple explorers.
Target type: agent
agent-updatedAn explorer has changed its network configuration.
Target type: organization
speedtest-completedA speed test completed.
Target type: agent
speedtest-deletedA speed test report was deleted by the user.
Target type: explorer-report
speedtest-startedA speed test was manually scheduled by the user.
Target type: agent
task-failedA scan task fails to complete.
Target type: site
Security-related events
auth-login-link-completedA one-time login link is used successfully.
Target type: user
auth-login-link-requestA user requests a login link.
Target type: user
auth-mfa-addedMulti-factor authentication credentials are added to a user account.
Target type: user
auth-mfa-removedMulti-factor authentication credentials are removed from a user account.
Target type: user
auth-password-reset-completedA password reset is completed successfully.
Target type: user
auth-password-reset-requestA user requests a password reset.
Target type: user
client-switchedA user switches to a different account.
Target type: client
credential-createdA set of credentials is created.
Target type: credential
credential-removedA set of credentials is removed.
Target type: credential
credential-updatedA set of credentials is updated.
Target type: credential
group-createdA new group is created.
Target type: group
group-mapping-createdA new group mapping is created.
Target type: group-mapping
group-mapping-removedA group mapping is removed.
Target type: group-mapping
group-mapping-updatedA group mapping is updated.
Target type: group-mapping
group-removedA group is removed.
Target type: group
group-updatedA group's information is updated.
Target type: group
loginA user logs in.
Target type: client
login-failedA user fails to login.
Target type: client
login-mfaA user logs in using multi-factor authentication.
Target type: client
login-ssoA user logs in using SSO.
Target type: client
login-sso-beginA user begins logging in using SSO.
Target type: client
login-sso-enrollA new user is created via SSO enrollment.
Target type: client
role-createdA custom role is created.
Target type: role
role-deletedA custom role is deleted.
Target type: role
role-updatedA custom role's name, description or permissions are changed.
Target type: role
sso-settings-updatedThe SSO settings are changed.
Target type: client
sso-user-activatedAn SSO user activated with runZero.
Target type: client
user-activatedAn external user activated with runZero.
Target type: client
user-added-to-groupA user is added to a group.
Target type: group
user-demotedA user is demoted from superuser
Target type: user
user-invite-currentA user is invited to join the current organization.
Target type: user
user-invite-externalAn external user is invited to join a team.
Target type: user
user-invite-resentA user invitation is resent.
Target type: user
user-invite-restrictedA user is invited to join a team with restricted permissions.
Target type: user
user-invite-teamA user is invited to join a team.
Target type: user
user-mfa-resetA user resets their multi-factor authentication settings.
Target type: user
user-password-resetA user resets their password.
Target type: user
user-promotedA user is promoted to superuser.
Target type: user
user-registeredA new user registers with runZero.
Target type: client
user-removedA user is deleted.
Target type: user
user-removed-from-groupA user is removed from a group.
Target type: group
users-csv-importMultiple users are imported from a CSV file.
Target type: user
Risk management events
findings-with-instancesFindings instances found or updated (triggered when results change).
Target type: finding
rapid-response-publishedA Rapid Response query is published or updated.
Target type: query
rapid-response-with-matchesRapid Response matches are found (triggered when results change).
Target type: query
API-related events
api-clientA request was made to the Account API.
Target type: client
api-client-createdAn API client is created.
Target type: client
api-client-removedAn API client is removed.
Target type: client
api-client-secret-rotatedThe secret for an API client is rotated.
Target type: client
api-client-updatedAn API client is updated.
Target type: client
api-exportA request was made to the Export API.
Target type: organization
api-mcp-session-activeAn MCP session made calls or changed address (periodic summary).
Target type: client
api-mcp-session-endedAn MCP session ended or went idle.
Target type: client
api-mcp-session-startedAn MCP client connected with an API key or API client.
Target type: client
api-organizationA request was made to the Organization API.
Target type: organization
client-api-key-createdA client API key is created.
Target type: client
client-api-key-removedA client API key is deleted.
Target type: client
client-api-key-rotatedThe secret for a client API key is rotated.
Target type: client
custom-asset-source-createdA custom asset source is created.
Target type: custom-asset-source
custom-asset-source-removedA custom asset source is removed.
Target type: custom-asset-source
custom-asset-source-updatedA custom asset source is updated.
Target type: custom-asset-source
mcp-oauth-consent-approvedA user authorized an MCP client, creating an API client.
Target type: client
mcp-oauth-consent-deniedA user refused an MCP client's request for access.
Target type: client
organization-api-key-createdAn organization API key is created.
Target type: organization
organization-api-key-removedAn organization API key is removed.
Target type: organization
organization-api-key-rotatedThe secret for an organization API key is rotated.
Target type: organization
organization-download-token-resetThe download token for an organization is reset.
Target type: organization
organization-export-token-createdAn export token for an organization is created.
Target type: organization
organization-export-token-removedThe export token for an organization is removed.
Target type: organization
organization-export-token-resetThe export token for an organization is reset.
Target type: organization
All other events
account-ai-settings-updatedAccount AI (LLM) provider configuration is updated.
Target type: account
account-settings-updatedAccount settings are updated.
Target type: account
ai-budget-exceededAn AI daily limit was reached (platform token allowance, or a per-day input/output token cap) for the account or an organization.
Target type: account
ai-budget-warningAI usage crossed the daily-limit warning threshold (75% of the platform token allowance or a token cap) for the account or an organization.
Target type: account
ai-report-generatedAn AI report (deep analysis, organization report, or chat answer) was generated.
Target type: organization
alert-acknowledgeAn alert is acknowledged (cleared).
Target type: organization
alert-acknowledge-allAll alerts are acknowledged (cleared).
Target type: organization
alert-channel-createdAn alert channel is created.
Target type: organization
alert-channel-removedAn alert channel is removed.
Target type: organization
alert-channel-updatedAn alert channel is updated.
Target type: organization
alert-clear-allAll alerts for an organization are cleared.
Target type: organization
alert-rule-createdAn alert rule is created.
Target type: organization
alert-rule-removedAn alert rule is removed.
Target type: organization
alert-rule-updatedAn alert rule is updated.
Target type: organization
alert-template-createdAn alert template is created.
Target type: organization
alert-template-removedAn alert template is removed.
Target type: organization
alert-template-updatedAn alert template is updated.
Target type: organization
asset-clear-tags-multipleTags are cleared on multiple assets at once.
Target type: organization
asset-csv-importAsset information is exported as CSV.
Target type: organization
asset-fingerprint-submittedAn asset fingerprint is submitted to runZero, Inc.
Target type: asset
asset-merge-multipleMultiple assets are merged into a single asset.
Target type: organization
asset-owners-removedAsset owners are removed.
Target type: asset
asset-owners-updatedAsset owners are updated.
Target type: asset
asset-removedAn asset is deleted.
Target type: asset
asset-removed-multipleMultiple assets are deleted from an organization.
Target type: organization
asset-set-commentsA comment is set on an asset.
Target type: asset
asset-set-comments-multipleA comment is set on multiple assets at once.
Target type: organization
asset-set-criticalityCriticality is set on an asset.
Target type: asset
asset-set-criticality-multipleCriticality is set on multiple assets at once.
Target type: organization
asset-set-risk-multipleRisk is set on multiple assets at once.
Target type: organization
asset-set-tagsTags are set on assets.
Target type: asset
asset-set-tags-multipleTags are set on multiple assets at once.
Target type: organization
assets-expiredOne or more assets have expired and have been removed.
Target type: organization
assets-purgedAll asset data is deleted from an organization.
Target type: organization
directory-group-removed-multipleDirectory groups are been removed from the directory groups inventory.
Target type: directory-group
directory-user-removed-multipleDirectory users are been removed from the directory users inventory.
Target type: directory-user
findings-suppressedFindings were suppressed.
Target type: finding
findings-unsuppressedFindings were unsuppressed.
Target type: finding
goal-completedA goal is completed.
Target type: client
goal-createdA goal is created.
Target type: organization
goal-lapsedA goal is no longer completed.
Target type: client
goal-removedA goal is removed.
Target type: organization
goal-updatedA goal is updated.
Target type: organization
insight-clearA computed insight result is cleared.
Target type: insight
insight-clear-allAll computed insight results are cleared.
Target type: insight
instance-registeredA new self-hosted instance has been registered.
Target type: client
issue-closedAn issue is closed.
Target type: issue
issue-openedAn issue is opened.
Target type: issue
issue-status-updatedAn issue's status is updated.
Target type: issue
issues-overdueOne or more open issues are past their due date.
Target type: issue
issues-reoccurredOne or more issues have recently re-occurred.
Target type: issue
license-changedThe runZero license entitlement changes.
Target type: client
license-limit-exceededThe asset count has exceeded the runZero license limit.
Target type: client
nessus-importNessus data is imported.
Target type: organization
nexpose-importNexpose data is imported.
Target type: organization
org-ai-settings-updatedOrganization AI (LLM) provider configuration is updated.
Target type: organization
organization-createdA new organization is created.
Target type: client
organization-purgedAll assets for an organization are purged.
Target type: organization
organization-removedAn organization is deleted.
Target type: client
organization-updatedAn organization is modified.
Target type: organization
ownership-type-createdAn ownership type is created.
Target type: client
ownership-type-removedAn ownership type is removed.
Target type: client
ownership-type-updatedAn ownership type is updated.
Target type: client
packet-importPcap data is imported.
Target type: organization
query-createdA saved query is created.
Target type: client
query-importedA saved query is imported.
Target type: client
query-removedA saved query is deleted.
Target type: client
query-updatedA saved query is modified.
Target type: client
report-removedA computed insight report is removed.
Target type: report
scan-completedScan completed.
Target type: asset
scan-createdA new scan task is created.
Target type: site
scan-importScan data is imported.
Target type: organization
scan-template-createdA scan template is created.
Target type: client
scan-template-removedA scan template is removed.
Target type: client
scan-template-updatedA scan template is updated.
Target type: client
scan-updatedA scan task is modified.
Target type: site
service-removed-multipleMultiple service records are deleted.
Target type: organization
site-createdA new site is created.
Target type: organization
site-importedSite data is imported as CSV.
Target type: organization
site-removedA site is deleted.
Target type: organization
site-updatedA site is updated.
Target type: site
software-removed-multipleMultiple software records are deleted.
Target type: organization
task-completedA scan task completes.
Target type: site
task-createdA task is created.
Target type: task
task-hiddenA (failed) task is hidden.
Target type: task
task-last-started-ts-clearedA task's last started at timestamp is cleared.
Target type: task
task-pausedA task is paused.
Target type: task
task-reprocessedA completed task is queued to have its data processed again.
Target type: task
task-startedA task is started.
Target type: site
task-stoppedA task is stopped.
Target type: task
task-stopped-allAll tasks are stopped.
Target type: organization
task-unpausedA task is unpaused.
Target type: task
user-password-disabledA user disabled password authentication.
Target type: user
user-settings-updatedA user updates their settings.
Target type: user
user-unlockedA user's account is unlocked.
Target type: user
user-updatedA user's information is updated.
Target type: user
vulnerabilities-suppressedVulnerabilities were suppressed.
Target type: vulnerabilities
vulnerabilities-unsuppressedVulnerabilities were unsuppressed.
Target type: vulnerabilities
vulnerability-groups-suppressedVulnerability groups were suppressed.
Target type: vulnerability-groups
vulnerability-groups-unsuppressedVulnerability groups were unsuppressed.
Target type: vulnerability-groups
vulnerability-owners-removedVulnerability owners are removed.
Target type: vulnerability
vulnerability-owners-updatedVulnerability owners are updated.
Target type: vulnerability
vulnerability-set-riskRisk is set on a vulnerability.
Target type: organization
vulnerability-set-risk-multipleRisk is set on multiple vulnerabilities at once.
Target type: organization
wireless-removed-multipleMultiple discovered wireless LANs are deleted.
Target type: organization