K
Kerianne Kouassi
Please add host isolation and release events to the Portal Audit Log, including:
Who initiated the action
When it was issued
When the endpoint applied it
Status and failure details
Separate entries for repeated isolate/release actions
Currently, partners may only see login activity. Without SIEM or endpoint logs, they cannot determine who isolated a machine or reconstruct the isolation timeline.