[Yandex Cloud documentation](../index.md) > [Yandex Security Deck](index.md) > Audit Trails events

# Yandex Audit Trails event reference

Audit Trails supports monitoring of both [control plane](../audit-trails/concepts/format.md) (configuration level) and [data plane](../audit-trails/concepts/format-data-plane.md) (service level) events for Yandex Security Deck.

The general format of the `event_type` value is as follows:

```text
yandex.cloud.audit.securitydeck.<module_name><event_name>
```

## Control plane event reference {#control-plane-events}

### Cloud Security Posture Management (CSPM) {#sd-cspm}

Module name: `cspm`.

Event name | Description
--- | ---
`CreateScanJob` | Creating a scan job
`CreateScopeFilter` | Creating a scope filter
`DeleteScanJob` | Deleting a scan job
`DeleteScopeFilter` | Deleting a scope filter
`UpdateScanJob` | Updating a scan job
`UpdateScopeFilter` | Updating a scope filter

### Kubernetes® Security Posture Management (KSPM) {#sd-kspm}

Module name: `kspm`.

Event name | Description
--- | ---
`CreateException` | Creating an exception
`CreateProject`   | Creating a project
`DeleteException` | Deleting an exception
`DeleteProject`   | Deleting a project
`EnableProject`   | Enabling a project
`EnableSDProject` | Enabling a Security Deck project
`UpdateException` | Updating exception parameters
`UpdateProject`   | Updating project parameters

### Alerts module {#sd-alerts}

Module name: `alerts`.

Event name | Description
--- | ---
`CreateAlertSink` | Creating an alert sink
`DeleteAlertSink` | Deleting an alert sink
`UpdateAlertSink` | Updating an alert sink

### Security Deck workspaces {#sd-orchestrator}

Module name: `orchestrator`.

Event name | Description
--- | ---
`CreateConnector` | Creating a [connector](concepts/workspace.md#connectors)
`CreateScope` | Creating a scope
`CreateWorkspace` | Creating a [workspace](concepts/workspace.md)
`DeleteConnector` | Deleting a connector
`DeleteScope` | Deleting a scope
`DeleteWorkspace` | Delete the environments.
`UpdateConnector` | Updating a connector
`UpdateScope` | Updating a scope
`UpdateWorkspace` | Updating a workspace

## Data plane event reference {#data-plane-events}

### Access Transparency module {#sd-access-transparency-dp}

Module name: `accesstransparency`.

Event name | Description
--- | ---
`ComputeNodeAccess` | Connecting the Access Transparency [module](concepts/access-transparency.md) to the Yandex Data Processing [subcluster](../data-proc/concepts/index.md#resources)
`MDBClusterAccess` | Connecting the Access Transparency module to a database cluster

### Cloud Security Posture Management (CSPM) {#sd-cspm-dp}

Module name: `cspm`.

Event name | Description
--- | ---
`AssetFailedRuleCheck` | [CSPM](concepts/cspm.md) failed object check report
`AssetPassedRuleCheck` | CSPM passed object check report
`AssetRuleCheckCouldNotBeExecuted` | CSPM object check error report
`AssetRuleCheckNoLongerInScope` | CSPM report about excluding a rule from a scope

### Kubernetes® Security Posture Management (KSPM) {#sd-kspm-dp}

Module name: `kspm`.

Event name | Description
--- | ---
`TriggerAdmissionControl` | Triggering of [KSPM](concepts/kspm.md) when checking newly created and updated resources
`TriggerRuntimeControl` | Triggering of KSPM when monitoring workload security
`TriggerRuntimeProcessInfo` | Triggering of KSPM when getting process information

### Alerts module {#sd-alerts-dp}

Module name: `alerts`.

Event name | Description
--- | ---
`CreateAlert` | Creating an alert