Audit and Core Modules
Audit actions
Energy Logserver logs audit events for security-relevant operations across the platform. Audit actions are grouped by module.
Audit records
Audit documents go to the audit alias, which rolls over into indices named audit-<date>-<number>. A login record looks like this:
{
"@timestamp": "2026-09-25T08:58:26.883Z",
"username": "admin",
"operation": "LOGIN",
"request": "/_logserver/login",
"method": "PUT",
"params": {},
"indices": [],
"client": "10.4.2.133"
}
Since 8.1.0 client holds the address of the browser that sent the request to the GUI. Earlier versions recorded 127.0.0.1 for every GUI action. The GUI takes the address of the incoming TCP connection and ignores X-Forwarded-For, so behind a reverse proxy client shows the proxy address, and requests sent from the GUI host itself show 127.0.0.1.
Config
Action Type |
Path |
From Request |
|---|---|---|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Reports
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Alerts
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Index Management
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Archive
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Sync
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Agents
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Intelligence
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
, |
|
|
, |
|
|
, |
Network Probe
Action Type |
Path |
From Request |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
, |
|
|
|