Skip to main content

Common logged events

Event typeAttributesFile
System login attempttimestamp and event ID, user login, administrator privileges (if any), LDAP URL, user IDderscanner-debug.log
Initiating DB searchtimestamp and event ID, user loginderscanner-debug.log
Session token creationtimestamp and event ID, user login, administrator privileges (if any), LDAP URL, user IDderscanner-debug.log
Getting a token from Accounttimestamp and event ID, user login, token validity period (in min.), administrator privileges (if any), LDAP URL, user IDderscanner-debug.log
Change password attempttimestamp and event ID, user login, administrator privileges (if any), LDAP URL, user IDderscanner-debug.log
Wrong password errortimestamp and event ID, user loginderscanner-debug.log
Wrong login errortimestamp and event ID, user loginderscanner-debug.log
Session token renewaltimestamp and event ID, user login, token validity period (in min.), administrator privileges (if any), LDAP URL, user IDderscanner-debug.log
Expired session token usage attempttimestamp and event ID, token expiration time, current time, time difference in msderscanner-debug.log
Projects list querytimestamp and event ID, sort order, whether to include archived or empty projects, languages for scanning, project names and statuses, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Project info querytimestamp and event ID, project UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scan info querytimestamp and event ID, scan UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scans list querytimestamp and event ID, project and scans UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Statistics querytimestamp and event ID, scan UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Vulnerability info querytimestamp and event ID, vulnerability ID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Export report querytimestamp and event ID, scan UUID, project UUID, detected vulnerabilities UUIDs, project name, link to detailed results, path to logo, number of scans, project creation date, app version, project author, hidden user settings: user ID, settings UUID, visibility restrictions, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rules list querytimestamp and event ID, filter settings: key words, language, WAF recommendations, classifications, authors, sorting, order of sorting, grouping, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rule sets list querytimestamp and event ID, sets sorting settings: key words, languages, authors; administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Users list querytimestamp and event ID, users sorting settings, vulnerability ID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
User creationtimestamp and event ID, userDto object: login, e-mail, full name, organization, position, phone number, website, account availability from - to, available scans, account (un)blocked, password expiry date, password attempts restrictions, hidden user settings: user ID, settings UUID, visibility restrictions, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
User editingtimestamp and event ID, userDto object: login, e-mail, full name, organization, position, phone number, website, account availability from - to, available scans, account (un)blocked, password expiry date, password attempts restrictions, hidden user settings: user ID, settings UUID, visibility restrictions, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
User removaltimestamp and event ID, removed user UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Project creationtimestamp and event ID, project settings, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Project editingtimestamp and event ID, project settings UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Project removaltimestamp and event ID, project UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scan launchtimestamp and event ID, project settings, path to temporary file (for archives), repository cloning command (for VCS), path to source.zip, project UUID, scan UUID, all launched tasks UUIDs, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scan pausetimestamp and event ID, scan UUID, unfinished tasks UUIDs, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scan stoptimestamp and event ID, scan UUID, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Scan removaltimestamp and event ID, scan UUID, project directory, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Detected vulnerability attributes editingtimestamp and event ID, vulnerability UUID, scan UUID, project UUID, old and new comment (if changed), old and new severity level (if changed), old and new status (if changed), administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rule creationtimestamp and event ID, severity level, description, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rule editingtimestamp and event ID, severity level, description, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rule set creationtimestamp and event ID, rule set UUID, programming language, set name, privacy settings, IDs of included rules, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rule set editingtimestamp and event ID, rule set UUID, programming language, set name, privacy settings, IDs of included rules, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Rules uploadtimestamp and event ID, archive name, administrator privileges (if any), LDAP URL, user ID, user loginderscanner-debug.log
Wrong passwordtimestamp and event IDderscanner-debug.log
Wrong logintimestamp and event IDderscanner-debug.log
Project upload by linktimestamp and event ID, linkderscanner-debug.log
Attempt to create a user that already existstimestamp and event IDderscanner-debug.log
Password change: provided values don't matchtimestamp and event IDderscanner-debug.log
Rules upload errortimestamp and event IDderscanner-debug.log
License error: license expiredtimestamp and event IDderscanner-debug.log
Not enough hard drive spacetimestamp and event IDderscanner-debug.log
Not enough RAMtimestamp and event IDderscanner-debug.log
Daemon not responsivetimestamp and event ID, task UUIDderscanner-debug.log
DB not responsivetimestamp and event IDderscanner-debug.log
Matcher errortimestamp and event ID, file pathlog.log (/opt/derscanner/files/ d/{taskuuid}/.state/log.log)
OutOfMemory for Javatimestamp and event ID/opt/derscanner/sast-daemon/ languages/{LANG}/{DATE}_ {TASK_START_TIME}_ {SCAN_UUID}.log (or .log.zip)