Audit log events and metadata

View as Markdown

The Sigma Audit Log is a connection that provides metadata related to user-initiated events that occur within your Sigma organization.

This document details audit log event categories, event types, and entry metadata. For more information about audit logging with Sigma, see the following:

Audit log events are not intended to be compared with usage data. Audit logs are designed for security, compliance, and governance use cases and provide a detailed, immutable record of who did what and when in your Sigma organization. Usage data contains aggregate data about workbook queries performed in your Sigma organization and is not intended for auditing purposes.

Documentation memo

This document references the audit log with its default column settings and connection configurations. If settings and configurations were customized by an Admin user, column visibility and naming in your audit log may differ.

To confirm column visibility and identify the default columns defined in this document, refer to the Column tab in your audit log. If necessary, you can cross-reference your audit log’s custom “friendly names” with cloud data warehouse (CDW) or database management system (DBMS) column IDs provided in the event metadata tables throughout this document.

Event categories

The audit log records user events in the following categories:

CategoryDescription
ACCESS_SIGMAUser access and configurations in the Admin > Authentication page
ACCOUNT_TYPESAdmin interactions with account type configurations and member assignments
AI_CONVERSATIONSUser interactions with Sigma Assistant, Sigma agents, and warehouse agents through chat, automated actions, and more.
AI_SETTINGSAdmin configuration of AI providers and data sources used by Assistant
API_ACTIONSAPI calls made on behalf of a user or automation as part of a Call API action in Sigma. Distinct from direct calls to Sigma's public API.
AUDIT_LOGSAudit log enablement and audit log storage integration management
CONNECTIONSAdmin interactions with the CDW or DBMS connection configurations
EXPORTSUser interactions with on-demand export functionality
INPUT_TABLESUser interactions with input tables
MATERIALIZATIONUser interactions with materializations
MCPAgent interactions with configured MCP connectors, and management of MCP connectors
OBJECT_INTERACTIONSUser interactions with workbooks, data models, datasets, and workspaces
PERMISSIONSUser interactions with permissions grants on folders and documents
PUBLIC_APIUser interactions with Sigma's API endpoints
QUERY_EXECUTIONSUser interactions that trigger queries to the CDW
SCHEDULESUser interactions with scheduled export functionality
STORED_PROCEDURESStored procedure executions
TEAMSAdmin interactions with team settings and member assignments
TENANTSAdmin interactions with deployment settings for tenant organizations.
USER_ACCOUNTSAdmin interactions with member accounts and user invitations

Event types and metadata

Base entry metadata (all entries)

All audit entries—regardless of event category or type—include the following base metadata:

Column name (default "friendly name")Column ID (CDW/DBMS column ID)Description
Cloud ProviderCLOUD_PROVIDERCloud service provider for your Sigma instance
Event CategoryEVENT_CATEGORYEvent request category (primary event classification)
Event StatusEVENT_STATUSEvent response status
Event Status Reason CodeEVENT_STATUS_REASON_CODEReason code for the event response. Provided for select events when Event Status = SUCCESS, and provided for all events when Event Status = FAILURE.
Event TypeEVENT_TYPEEvent request type (secondary event classification)
Impersonating User Organization IdIMPERSONATING_USER_ORGANIZATION_IDOrganization ID of the actor when using impersonation
Impersonation User EmailIMPERSONATION_USER_EMAILEmail assigned to the impersonated user account
Impersonation User IdIMPERSONATION_USER_IDSystem-generated ID associated with the impersonated user account
Organization IdORGANIZATION_IDUUID associated with your Sigma instance
Request IdREQUEST_IDUUID associated with the event request
Request timeREQUEST_TIMEDate and time of the event request in UTC
Schema VersionSCHEMA_VERSIONDatabase schema model version
Sigma UrlSIGMA_URLURL of the application page where the event request occurred
User AgentUSER_AGENTSoftware and browser details associated with the event request
User EmailUSER_EMAILEmail assigned to the user account responsible for the event request
User IdUSER_IDSystem-generated ID associated with the user account responsible for the event request
User IpUSER_IPIP address associated with the device on which the event request occurred

Audit events reference

Select an event category to browse the available audit log events in that category, along with the metadata columns available for each.

Audit events

Event categoryEvent typeEvent statusEntry triggerAdditional metadata columnsNotes
ACCESS_SIGMALOGINSUCCESSSuccessful SAML authentication or OAuth authorization → successful loginAuth Type = SamlLogin or OAuthLoginApplicable when SAML or OAuth is enabled
ACCESS_SIGMAPASSWORD_RESETFAILUREFailed password reset request using Forgot Password feature in sign-in page → password reset email failed to sendAuth Type = PasswordResetRequest, Target User Ids = a list of user ids whose password are reset
ACCESS_SIGMAIMPERSONATESUCCESSAdmins impersonate other non-admins by clicking the 'Impersonate' button when viewing their profile → successful impersonateAuth Type = ImpersonationLogin, Impersonation User ID
ACCESS_SIGMAPASSWORD_RESETFAILURENew password submitted through page linked in password reset email → failed password resetAuth Type = PasswordReset
ACCESS_SIGMANEW_USER_SIGNUPSUCCESSNew user registration submitted through page linked in user invite email → successful loginAuth Type = PasswordLogin, SamlLogin, OAuthLogin
ACCESS_SIGMALOGINSUCCESSValid email and password entered in sign-in page → successful loginAuth Type = PasswordLoginApplicable when password authentication is enabled and 2FA is disabled
ACCESS_SIGMAIMPERSONATEFAILUREAdmins impersonate other non-admins by clicking the 'Impersonate' button when viewing their profile → failed impersonateAuth Type = ImpersonationLogin, Impersonation User ID
ACCESS_SIGMALOGINSUCCESS2FA code entered and verified → successful loginAuth Type = PasswordLoginMfaVerifyApplicable when password authentication and 2FA are both enabled
ACCESS_SIGMALOGINFAILUREInvalid email or password entered in sign-in page → failed loginAuth Type = PasswordLoginApplicable when password authentication is enabled and 2FA is enabled or disabled
ACCESS_SIGMAPASSWORD_UPDATEFAILURENew password submitted through Change Password modal in Your Profile > Details page → failed password updateAuth Type = PasswordUpdate
ACCESS_SIGMANEW_USER_SIGNUPFAILURENew user registration submitted through page linked in user invite email → failed loginAuth Type = PasswordLogin, SamlLogin, OAuthLoginFailed logins using SAML or OAuth may be logged as the LOGIN event type
ACCESS_SIGMAPASSWORD_RESETSUCCESSNew password submitted through page linked in password reset email → successful password resetAuth Type = PasswordReset
ACCESS_SIGMALOGINSUCCESSValid email and password entered in sign-in page → 2FA email successfully sentAuth Type = PasswordLoginMfaTriggeredApplicable when password authentication and 2FA are both enabled
ACCESS_SIGMAPASSWORD_UPDATESUCCESSNew password submitted through Change Password modal in Your Profile > Details page → successful password updateAuth Type = PasswordUpdate
ACCESS_SIGMALOGINFAILUREFailed SAML authentication or OAuth authorization → failed loginAuth Type = SamlLogin, OAuthLoginApplicable when SAML or OAuth is enabled
ACCESS_SIGMAPASSWORD_RESETSUCCESSSuccessful password reset request using Forgot Password feature in sign-in pageAuth Type = PasswordResetRequest, Target User Ids = a list of user ids whose password are reset
ACCESS_SIGMALOGINFAILURE2FA code entered but not verified → failed loginAuth Type = PasswordLoginMfaVerifyApplicable when password authentication and 2FA are both enabled
ACCOUNT_TYPESACCOUNT_TYPE_UPDATEDFAILUREAccount type permissions edited in Administration > Account Types > {account_name} page → failed account type updateAccount Type Id, Features Enabled, Features Disabled
ACCOUNT_TYPESACCOUNT_TYPE_DELETEDFAILUREDelete selected in account type action menu in Administration > Account Types page → failed account type deletionAccount Type Id, Delegate Account Type Id
ACCOUNT_TYPESACCOUNT_TYPE_CREATEDFAILURENew account type configured in Administration > Account Types > New Account Type page → failed account type creationFeatures Enabled, Features Disabled

Event metadata

Event categoryColumn friendly nameColumn IDDescriptionNotes
ACCESS_SIGMAAuth TypeAUTH_TYPEType of authentication or authorization request associated with the event
ACCESS_SIGMATarget User IdsTARGET_USER_IDSSystem-generated IDs associated with affected user accounts
ACCOUNT_TYPESDelegate Account Type IdDELEGATE_ACCOUNT_TYPE_IDNew UUID associated with the account type
ACCOUNT_TYPESFeatures EnabledFEATURES_ENABLEDPermissions included in the account type
ACCOUNT_TYPESFeatures DisabledFEATURES_DISABLEDPermissions excluded from the account type
ACCOUNT_TYPESAccount Type IdACCOUNT_TYPE_IDUUID associated with the account type
AI_CONVERSATIONSConversation IdCONVERSATION_IDUUID associated with the AI conversation
AI_CONVERSATIONSConversation Turn IdCONVERSATION_TURN_IDUUID associated with a single turn in the conversationUniquely identifies the user message
AI_CONVERSATIONSConversation ContextCONVERSATION_CONTEXTWhere in the product the conversation happened
AI_CONVERSATIONSConversation AgentCONVERSATION_AGENTWhich agent the conversation was with
AI_CONVERSATIONSConversation Owner IdCONVERSATION_OWNER_IDSystem-generated ID associated with the user account that owns the conversation
AI_CONVERSATIONSSource Conversation IdSOURCE_CONVERSATION_IDUUID of the conversation this conversation was forked from
AI_CONVERSATIONSFork Turn IdFORK_TURN_IDUUID of the turn in the source conversation the fork started from
AI_SETTINGSAI Restrict to Configured SourcesAI_RESTRICT_TO_CONFIGURED_SOURCESWhether Sigma Assistant is limited to search only the sources admins selected by default
AI_SETTINGSAI Source UpdatesAI_SOURCE_UPDATESThe sources added, changed, or removed from the specific sources configured for Assistant, each with its inodeID and the change made.
AI_SETTINGSAI Provider Config TypeAI_PROVIDER_CONFIG_TYPEWhich AI provider was configured: openai, azure_openai, warehouse, external_embeddings, gemini, anthropic, bedrock, or warehouse_embeddings
AI_SETTINGSAI Provider Connection IdAI_PROVIDER_CONNECTION_IDThe ID of the warehouse connection used (warehouse-hosted models only)
API_ACTIONSHostHOSTHostname the API action request was sent to
API_ACTIONSStatus CodeSTATUS_CODEHTTP status code returned by the API action call
API_ACTIONSAuth Inode IdAUTH_INODE_IDInode ID of the stored credential used to authenticate the call

Sigma Shared metadata reference

Select a table name to view the columns available in the SIGMA_SHARED audit tables.

The DOCUMENT_REFERENCES table is only populated for tenant organizations with audit logging enabled.

Table nameColumn nameTypeDescription
COMMENTSConversation UuidTextThe UUID of the conversation
COMMENTSOrganization UuidTextThe UUID of the organization
COMMENTSInode UuidTextThe UUID of the inode
COMMENTSConversation TypeTextThe type of element the conversation happens on (workbook or element)
COMMENTSElement IdTextThe ID of the element
COMMENTSConversation Is ResolvedLogicalBoolean value describing if the conversation has been resolved
COMMENTSConversation Created at UtcDateThe timestamp in UTC when the conversation was created
COMMENTSConversation Updated at UtcDateThe timestamp in UTC when the conversation was last updated
COMMENTSConversation TranscriptTextThe transcript of the conversation in the comments section of the workbook
COMMENTSUsers Mentioned ListTextA comma-separated list of users mentioned in a comment
COMMENTSNum Users MentionedNumberThe number of users mentioned in this conversation
COMMENTSComment Attachments ListArrayAn array of the attachments uploaded in the comments section of the workbook
COMMENTSNum AttachmentsNumberThe number of attachments in this conversation
COMMENTSNum CommentsNumberThe number of comments in this conversation
CONNECTIONSConnection UuidTextUniversally unique identifier associated with the connection
CONNECTIONSConnection TypeTextWarehouse associated with connection
CONNECTIONSConnection NameTextThe name of the connection
CONNECTIONSOrganization UuidTextUniversally unique identifier of the organization associated with this connection
CONNECTIONSConnection Created at UtcDateThe timestamp in UTC when this connection was created
CONNECTIONSConnection Updated at UtcDateThe timestamp in UTC when this connection was last updated