
Summary
The Tines Enqueued/Retrying Job Deletion rule is designed to detect potentially unauthorized or accidental deletion of jobs that are currently in the enqueue or retry state within the Tines automation platform. This rule monitors Tines audit logs to identify specific operations that clear these jobs. The detection focuses on logs generated during operations labeled 'JobsQueuedDeletion' and 'JobsRetryingDeletion'. When such events are recorded, especially if they are unexpected or occur more frequently than allowed, it indicates a potential risk of data destruction. Therefore, the rule tracks instances where these jobs are cleared and matches the logged attempts against expected behavior to confirm if they are legitimate activities associated with user operations. If this detection is triggered, it is recommended to reach out to the user involved and confirm whether job deletions were performed for valid business reasons, given that such actions may lead to unintended or harmful data loss. The rule operates with a low severity level, indicating that although potentially significant, these events may not immediately pose a critical threat to the system.
Categories
- Cloud
- Application
- Identity Management
Data Sources
- Application Log
- User Account
Created: 2023-06-26