Open spokanemac opened 7 months ago
To validate: I deleted an enrolled Windows VM today that erased over the weekend & saw nothing in Activity. There also does not seem to be any way to see this activity per the docs unless I have missed it. I looked on these pages:
https://fleetdm.com/docs/using-fleet/audit-logs https://fleetdm.com/docs/rest-api/rest-api#activities
I guess I expected to see a key like deleted_host
on the audit logs page. @marko-lisica Is this design intentional? Thanks!
I guess I expected to see a key like deleted_host on the audit logs page. @marko-lisica Is this design intentional? Thanks!
Hey, @nonpunctual, the activity feed was implemented before I started, but AFAIK this isn't intentionally designed.
@spokanemac so I am completely in agreement then there should be something in the Activity feed & something in audit log when a Fleet admin user deletes a Host & enrolls a Host. I know the enroll events could get a little crazy but record deletion is definitely a critical audit function in almost every org in every system. Thanks.
Agreed there should be an activity item here.
Audibility is core to Fleet.
Bringing this through feature fest.
Hey @spokanemac, now that the story is in the current design sprint. I updated the issue description to use the user story format.
I moved your original issue description here for safekeeping:
Problem
When a host is deleted in Fleet, the Activity feed does not indicate that the deletion occurred.
Potential solutions
Include the host with an identifier and the user who deleted the host record. (bulk deletes need to be considered as well)
BE:3 FE:1
Goal
Context
What else should contributors keep in mind when working on this change?
Changes
Product
Engineering
QA
Risk assessment
Manual testing steps
Testing notes
Confirmation