Skip to main content

AuditEvent

ResourceFoundation · SecurityTrial useMaturity 3

A record of an event made for purposes of maintaining a security log. Typical uses include detection of intrusion attempts and monitoring for inappropriate usage.

Tested supportFull test results →
Backends
PostgreSQLElasticsearch
Interactions
CreateReadUpdatePatchDelete
Search
18 of 18 parameters tested

Structure​

ElementCard.TypeDescription
typeRequiredΣ
1..1CodingType/identifier of eventBinding (extensible): audit-event-type
subtypeΣ
0..*CodingMore specific type/id for the eventBinding (extensible): audit-event-sub-type
actionΣ
0..1codeType of action performed during the eventBinding (required): audit-event-action
period
0..1PeriodWhen the activity occurred
recordedRequiredΣ
1..1instantTime when the event was recorded
outcomeΣ
0..1codeWhether the event succeeded or failedBinding (required): audit-event-outcome
outcomeDescΣ
0..1stringDescription of the event outcome
purposeOfEventΣ
0..*CodeableConceptThe purposeOfUse of the eventBinding (extensible): v3-PurposeOfUse
agentRequired
1..*BackboneElementActor involved in the event
type
0..1CodeableConceptHow agent participatedBinding (extensible): participation-role-type
role
0..*CodeableConceptAgent role in the eventBinding (example): security-role-type
whoΣ
0..1Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson)Identifier of who
altId
0..1stringAlternative User identity
name
0..1stringHuman friendly name for the agent
requestorRequiredΣ
1..1booleanWhether user is initiator
location
0..1Reference(Location)Where
policy
0..*uriPolicy that authorized event
media
0..1CodingType of mediaBinding (extensible): dicm-405-mediatype
network
0..1BackboneElementLogical network location for application activity
address
0..1stringIdentifier for the network access point of the user device
type
0..1codeThe type of network access pointBinding (required): network-type
purposeOfUse
0..*CodeableConceptReason given for this userBinding (extensible): v3-PurposeOfUse
sourceRequired
1..1BackboneElementAudit Event Reporter
site
0..1stringLogical source location within the enterprise
observerRequiredΣ
1..1Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson)The identity of source detecting the event
type
0..*CodingThe type of source where event originatedBinding (extensible): audit-source-type
entity
0..*BackboneElementData or objects used
whatΣ
0..1Reference(Resource)Specific instance of resource
type
0..1CodingType of entity involvedBinding (extensible): audit-entity-type
role
0..1CodingWhat role the entity playedBinding (extensible): object-role
lifecycle
0..1CodingLife-cycle stage for the entityBinding (extensible): object-lifecycle-events
securityLabel
0..*CodingSecurity labels on the entityBinding (extensible): security-labels
nameΣ
0..1stringDescriptor for entity
description
0..1stringDescriptive text
queryΣ
0..1base64BinaryQuery parameters
detail
0..*BackboneElementAdditional Information about the entity
typeRequired
1..1stringName of the property
value[x]Required
1..1string | base64BinaryProperty value

Σ in _summary results · ?! modifier element · 1.. required · inherited elements in grey

Search parameters​

Query with GET [base]/AuditEvent?[parameter]=[value]. Type decides which modifiers and prefixes apply, see search features.

ParameterTypeDescriptionPGES
actiontoken

Type of action performed during the event

AuditEvent.action
addressstring

Identifier for the network access point of the user device

AuditEvent.agent.network.address
agentreference

Identifier of who

AuditEvent.agent.who
agent-namestring

Human friendly name for the agent

AuditEvent.agent.name
agent-roletoken

Agent role in the event

AuditEvent.agent.role
altidtoken

Alternative User identity

AuditEvent.agent.altId
datedate

Time when the event was recorded

AuditEvent.recorded
entityreference

Specific instance of resource

AuditEvent.entity.what
entity-namestring

Descriptor for entity

AuditEvent.entity.name
entity-roletoken

What role the entity played

AuditEvent.entity.role
entity-typetoken

Type of entity involved

AuditEvent.entity.type
outcometoken

Whether the event succeeded or failed

AuditEvent.outcome
patientreference

Identifier of who

AuditEvent.agent.who.where(resolve() is Patient) | AuditEvent.entity.what.where(resolve() is Patient)
policyuri

Policy that authorized event

AuditEvent.agent.policy
sitetoken

Logical source location within the enterprise

AuditEvent.source.site
sourcereference

The identity of source detecting the event

AuditEvent.source.observer
subtypetoken

More specific type/id for the event

AuditEvent.subtype
typetoken

Type/identifier of event

AuditEvent.type

PG: PostgreSQL, ES: Elasticsearch. passes its TestScript checks, fails, not tested yet.

Common parameters on every resource (8)
_haste-health-authorreference

The author of the resource

_idtoken

Logical id of this artifact

_lastUpdateddate

When the resource version last changed

_profileuri

Profiles this resource claims to conform to

_securitytoken

Security Labels applied to this resource

_sourceuri

Identifies where the resource comes from

_tagtoken

Tags applied to this resource

_typetoken

Derived from the R4B Definition