Enterprise

actionDescriptionSampleRule
enterprise.configure_self_hosted_jit_runnerA new just-in-time GitHub Actions self-hosted runner was configuredNN
enterprise.register_self_hosted_runnerA new GitHub Actions self-hosted runner was registered.YY
enterprise.remove_self_hosted_runnerA GitHub Actions self-hosted runner was removed.NN
enterprise.runner_group_createdA GitHub Actions self-hosted runner group was created.NN
enterprise.runner_group_removedA GitHub Actions self-hosted runner group was removed.NN
enterprise.runner_group_renamedA GitHub Actions self-hosted runner group was renamed.NN
enterprise.runner_group_runner_removedThe REST API was used to remove a GitHub Actions self-hosted runner from a group.NN
enterprise.runner_group_runners_addedA GitHub Actions self-hosted runner was added to a group.NN
enterprise.runner_group_runners_updatedA GitHub Actions runner group's list of members was updated.NN
enterprise.runner_group_updatedThe configuration of a GitHub Actions self-hosted runner group was changed.NN
enterprise.runner_group_visiblity_updatedThe visibility of a GitHub Actions self-hosted runner group was updated via the REST API.NN
enterprise.self_hosted_runner_offlineThe GitHub Actions runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NN
enterprise.self_hosted_runner_onlineThe GitHub Actions runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NN
enterprise.self_hosted_runner_updatedThe GitHub Actions runner application was updated. This event is not included in the JSON/CSV export.NN

enterprise.configure_self_hosted_jit_runner

#
Category
enterprise

Description

A new just-in-time GitHub Actions self-hosted runner was configured

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.register_self_hosted_runner

#
Category
enterprise

Description

A new GitHub Actions self-hosted runner was registered.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1736846446162,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDA2Mg==",
  "action": "enterprise.register_self_hosted_runner",
  "actor": "entadmin01",
  "actor_id": 9000003,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9500001,
  "created_at": 1736846446162,
  "operation_type": "create",
  "request_access_security_header": null,
  "user_agent": "GitHubActionsRunner-linux-x64/2.321.0 ClientId/00000000-0000-0000-0000-000000000000 CommitSHA/e249007931b7c8e857797fa259c167f0bd4f997a Pid/266051 CreationTime/2025-01-14T09%3A20%3A45.5913104Z (Runner)"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

References #

enterprise.remove_self_hosted_runner

#
Category
enterprise

Description

A GitHub Actions self-hosted runner was removed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_created

#
Category
enterprise

Description

A GitHub Actions self-hosted runner group was created.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_removed

#
Category
enterprise

Description

A GitHub Actions self-hosted runner group was removed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_renamed

#
Category
enterprise

Description

A GitHub Actions self-hosted runner group was renamed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_runner_removed

#
Category
enterprise

Description

The REST API was used to remove a GitHub Actions self-hosted runner from a group.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_runners_added

#
Category
enterprise

Description

A GitHub Actions self-hosted runner was added to a group.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_runners_updated

#
Category
enterprise

Description

A GitHub Actions runner group's list of members was updated.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_updated

#
Category
enterprise

Description

The configuration of a GitHub Actions self-hosted runner group was changed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.runner_group_visiblity_updated

#
Category
enterprise

Description

The visibility of a GitHub Actions self-hosted runner group was updated via the REST API.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.self_hosted_runner_offline

#
Category
enterprise

Description

The GitHub Actions runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.self_hosted_runner_online

#
Category
enterprise

Description

The GitHub Actions runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

enterprise.self_hosted_runner_updated

#
Category
enterprise

Description

The GitHub Actions runner application was updated. This event is not included in the JSON/CSV export.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.