AuditEvent
A record of an event made for purposes of maintaining a security log. Typical uses include detection of intrusion attempts and monitoring for inappropriate usage.
Structure
Search Parameters
_haste-health-author (reference)
The author of the resource
Resource.meta.extension.where(url='https://haste.health/author').value_type (token)
Derived from the R4B Definition
$this.type().name_text (string)
Search on the narrative of the resource
_content (string)
Search on the entire content of the resource
_id (token)
Logical id of this artifact
Resource.id_lastUpdated (date)
When the resource version last changed
Resource.meta.lastUpdated_profile (uri)
Profiles this resource claims to conform to
Resource.meta.profile_query (token)
A custom search profile that describes a specific defined query operation
_security (token)
Security Labels applied to this resource
Resource.meta.security_source (uri)
Identifies where the resource comes from
Resource.meta.source_tag (token)
Tags applied to this resource
Resource.meta.tagaction (token)
Type of action performed during the event
AuditEvent.actionaddress (string)
Identifier for the network access point of the user device
AuditEvent.agent.network.addressagent (reference)
Identifier of who
AuditEvent.agent.whoagent-name (string)
Human friendly name for the agent
AuditEvent.agent.nameagent-role (token)
Agent role in the event
AuditEvent.agent.rolealtid (token)
Alternative User identity
AuditEvent.agent.altIddate (date)
Time when the event was recorded
AuditEvent.recordedentity (reference)
Specific instance of resource
AuditEvent.entity.whatentity-name (string)
Descriptor for entity
AuditEvent.entity.nameentity-role (token)
What role the entity played
AuditEvent.entity.roleentity-type (token)
Type of entity involved
AuditEvent.entity.typeoutcome (token)
Whether the event succeeded or failed
AuditEvent.outcomepatient (reference)
Identifier of who
AuditEvent.agent.who.where(resolve() is Patient) / AuditEvent.entity.what.where(resolve() is Patient)policy (uri)
Policy that authorized event
AuditEvent.agent.policysite (token)
Logical source location within the enterprise
AuditEvent.source.sitesource (reference)
The identity of source detecting the event
AuditEvent.source.observersubtype (token)
More specific type/id for the event
AuditEvent.subtypetype (token)
Type/identifier of event
AuditEvent.type