Vault GoogleWorkspace-vault

14 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'vault' without specifying an eventName attribute here.
create_investigation_beginAn eDiscovery matter (investigation) creation was initiated in Google Vault.
create_investigation_endAn eDiscovery matter (investigation) was created in Google Vault.
create_export_beginAn export job was initiated in Google Vault.
create_export_endAn export job completed in Google Vault.
exportData was exported from Google Vault.
export_file_downloadA Vault export file was downloaded.
add_litigation_hold_beginA litigation hold was initiated in Google Vault.
add_litigation_hold_endA litigation hold was established in Google Vault.
delete_investigation_beginAn eDiscovery matter deletion was initiated in Google Vault.
delete_investigation_endAn eDiscovery matter was deleted from Google Vault.
deletion_searchA deletion search was executed in Google Vault.
add_preservation_rule_beginA data preservation rule was initiated in Google Vault.
add_preservation_rule_endA data preservation rule was created in Google Vault.

any: Vault (any event)

#
Application
GoogleWorkspace-vault

Description

Source-only rules that filter on applicationName 'vault' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

create_investigation_begin: Create Investigation (Begin)

#
Application
GoogleWorkspace-vault

Description

An eDiscovery matter (investigation) creation was initiated in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

create_investigation_end: Create Investigation (End)

#
Application
GoogleWorkspace-vault

Description

An eDiscovery matter (investigation) was created in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

create_export_begin: Create Export (Begin)

#
Application
GoogleWorkspace-vault

Description

An export job was initiated in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

create_export_end: Create Export (End)

#
Application
GoogleWorkspace-vault

Description

An export job completed in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

export: Export

#
Application
GoogleWorkspace-vault

Description

Data was exported from Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

export_file_download: Export File Download

#
Application
GoogleWorkspace-vault

Description

A Vault export file was downloaded.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

add_litigation_hold_begin: Add Litigation Hold (Begin)

#
Application
GoogleWorkspace-vault

Description

A litigation hold was initiated in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

add_litigation_hold_end: Add Litigation Hold (End)

#
Application
GoogleWorkspace-vault

Description

A litigation hold was established in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

delete_investigation_begin: Delete Investigation (Begin)

#
Application
GoogleWorkspace-vault

Description

An eDiscovery matter deletion was initiated in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

delete_investigation_end: Delete Investigation (End)

#
Application
GoogleWorkspace-vault

Description

An eDiscovery matter was deleted from Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

deletion_search: Deletion Search

#
Application
GoogleWorkspace-vault

Description

A deletion search was executed in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

add_preservation_rule_begin: Add Preservation Rule (Begin)

#
Application
GoogleWorkspace-vault

Description

A data preservation rule was initiated in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

add_preservation_rule_end: Add Preservation Rule (End)

#
Application
GoogleWorkspace-vault

Description

A data preservation rule was created in Google Vault.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #