AuditEvent
A record of an event made for purposes of maintaining a security log. Typical uses include detection of intrusion attempts and monitoring for inappropriate usage.
- Backends
- PostgreSQLElasticsearch
- Interactions
- CreateReadUpdatePatchDelete
- Search
- 18 of 18 parameters tested
Structure
| Element | Card. | Type | Description |
|---|---|---|---|
typeRequiredΣ | 1..1 | Coding | Type/identifier of eventBinding (extensible): audit-event-type |
subtypeΣ | 0..* | Coding | More specific type/id for the eventBinding (extensible): audit-event-sub-type |
actionΣ | 0..1 | code | Type of action performed during the eventBinding (required): audit-event-action |
period | 0..1 | Period | When the activity occurred |
recordedRequiredΣ | 1..1 | instant | Time when the event was recorded |
outcomeΣ | 0..1 | code | Whether the event succeeded or failedBinding (required): audit-event-outcome |
outcomeDescΣ | 0..1 | string | Description of the event outcome |
purposeOfEventΣ | 0..* | CodeableConcept | The purposeOfUse of the eventBinding (extensible): v3-PurposeOfUse |
agentRequired | 1..* | BackboneElement | Actor involved in the event |
type | 0..1 | CodeableConcept | How agent participatedBinding (extensible): participation-role-type |
role | 0..* | CodeableConcept | Agent role in the eventBinding (example): security-role-type |
whoΣ | 0..1 | Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) | Identifier of who |
altId | 0..1 | string | Alternative User identity |
name | 0..1 | string | Human friendly name for the agent |
requestorRequiredΣ | 1..1 | boolean | Whether user is initiator |
location | 0..1 | Reference(Location) | Where |
policy | 0..* | uri | Policy that authorized event |
media | 0..1 | Coding | Type of mediaBinding (extensible): dicm-405-mediatype |
network | 0..1 | BackboneElement | Logical network location for application activity |
address | 0..1 | string | Identifier for the network access point of the user device |
type | 0..1 | code | The type of network access pointBinding (required): network-type |
purposeOfUse | 0..* | CodeableConcept | Reason given for this userBinding (extensible): v3-PurposeOfUse |
sourceRequired | 1..1 | BackboneElement | Audit Event Reporter |
site | 0..1 | string | Logical source location within the enterprise |
observerRequiredΣ | 1..1 | Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) | The identity of source detecting the event |
type | 0..* | Coding | The type of source where event originatedBinding (extensible): audit-source-type |
entity | 0..* | BackboneElement | Data or objects used |
whatΣ | 0..1 | Reference(Resource) | Specific instance of resource |
type | 0..1 | Coding | Type of entity involvedBinding (extensible): audit-entity-type |
role | 0..1 | Coding | What role the entity playedBinding (extensible): object-role |
lifecycle | 0..1 | Coding | Life-cycle stage for the entityBinding (extensible): object-lifecycle-events |
securityLabel | 0..* | Coding | Security labels on the entityBinding (extensible): security-labels |
nameΣ | 0..1 | string | Descriptor for entity |
description | 0..1 | string | Descriptive text |
queryΣ | 0..1 | base64Binary | Query parameters |
detail | 0..* | BackboneElement | Additional Information about the entity |
typeRequired | 1..1 | string | Name of the property |
value[x]Required | 1..1 | string | base64Binary | Property value |
Σ in _summary results · ?! modifier element · 1.. required · inherited elements in grey
Search parameters
Query with GET [base]/AuditEvent?[parameter]=[value]. Type decides which modifiers and prefixes apply, see search features.
| Parameter | Type | Description | PG | ES |
|---|---|---|---|---|
action | token | Type of action performed during the event AuditEvent.action | ||
address | string | Identifier for the network access point of the user device AuditEvent.agent.network.address | ||
agent | reference | Identifier of who AuditEvent.agent.who | ||
agent-name | string | Human friendly name for the agent AuditEvent.agent.name | ||
agent-role | token | Agent role in the event AuditEvent.agent.role | ||
altid | token | Alternative User identity AuditEvent.agent.altId | ||
date | date | Time when the event was recorded AuditEvent.recorded | ||
entity | reference | Specific instance of resource AuditEvent.entity.what | ||
entity-name | string | Descriptor for entity AuditEvent.entity.name | ||
entity-role | token | What role the entity played AuditEvent.entity.role | ||
entity-type | token | Type of entity involved AuditEvent.entity.type | ||
outcome | token | Whether the event succeeded or failed AuditEvent.outcome | ||
patient | reference | Identifier of who AuditEvent.agent.who.where(resolve() is Patient) | AuditEvent.entity.what.where(resolve() is Patient) | ||
policy | uri | Policy that authorized event AuditEvent.agent.policy | ||
site | token | Logical source location within the enterprise AuditEvent.source.site | ||
source | reference | The identity of source detecting the event AuditEvent.source.observer | ||
subtype | token | More specific type/id for the event AuditEvent.subtype | ||
type | token | Type/identifier of event AuditEvent.type |
PG: PostgreSQL, ES: Elasticsearch. passes its TestScript checks, fails, not tested yet. The author of the resource Logical id of this artifact When the resource version last changed Profiles this resource claims to conform to Security Labels applied to this resource Identifies where the resource comes from Tags applied to this resource Derived from the R4B DefinitionCommon parameters on every resource (8)
_haste-health-authorreference _idtoken _lastUpdateddate _profileuri _securitytoken _sourceuri _tagtoken _typetoken