Events

The Events screen provides a comprehensive audit trail of identity-based activities across your environment. Events captured here include user and administrator sign-ins, authentication steps, Legacy ZTNA policy enforcement outcomes, and behavior-based triggersβ€”giving you full visibility into who did what, when, and from where.

This screen is essential for enforcing Zero Trust principles, monitoring anomalies, and investigating incidents across both workforce and administrative actions.

πŸ“ Insights β†’ Events


Event Types

Events are classified into two core types:

  • User Events – Generated by end users accessing systems or applications
  • Administrator Events – Triggered by administrative actions on the Timus platform

Each entry in the table includes:

ColumnDescription
User / AdministratorThe account associated with the event
Public IPThe source IP address from which the action originated
TypeThe type of event
AuthenticationMethod and step (e.g., Password, idP)
ResultThe event outcome
Risk LevelRisk rating assigned to the event based on contextual signals
LocationGeographic location inferred from the public IP
DateTimestamp of the event

Event Details

Click the β€’β€’β€’ β†’ View next to any event.

FieldDescription
User / AdministratorIdentity associated with the event
Public IPSource IP of the connection
OriginWhere the event occurred (e.g., Connect app, Manager portal)
Risk LevelFinal risk score assigned
Event TypeCategory of activity
Policy NameThe access policy that was evaluated (if applicable)
BehaviorsBehavior(s) that caused the policy to trigger (if applicable)
AuthenticationMethods used in the authentication flow
LocationGeolocation of the IP
DateExact timestamp of the event

If the event includes Untrusted IP behavior, additional IP Intelligence fields are shown:

FieldDescription
ProxyIndicates if a proxy service was used
VPNFlags traffic from known VPN providers
TORDetects traffic from the TOR network
Fraud ScoreThird-party fraud risk score
Abuse VelocityRate of abuse history from this IP
Recent AbuseWhether recent malicious activity was reported
Bot ActivityIndicates known bot-related behavior

πŸ“€ Export Event Logs

Click Export to download the current table view as a CSV file. 
Applied filters and sorting are reflected in the export.

Updated

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.