Event Reporting gives System Admins visibility into how their organization interacts with Smartsheet data. It logs detailed actions, such as sheet downloads, deletions, and permission changes, from the past six months, starting when it's enabled.
USM Content
What's Event Reporting?
Event Reporting is a feed of activity events. System Admins retrieve it using the Smartsheet Events API, or Smartsheet streams it directly to a security information and event management (SIEM) system via a SIEM integration. Both methods deliver the same underlying event data.
Term | Definition |
|---|---|
Event | A single recorded action in your Smartsheet account, such as a sheet download or a permission change. |
Events API | The Smartsheet API endpoint that System Admins or developers use to retrieve Event Reporting data on demand. |
SIEM integration | A built-in option that streams Event Reporting data directly to your organization's SIEM or syslog server. |
Event Reporting is available and configured the same way for both the user model and the legacy model. Learn how to determine the model your plan is on.
What Event Reporting tracks
Event Reporting captures the following event types:
- Sheet and report views
- Sheet downloads
- Sheet shares, unshares, and permission changes
- Attachment uploads and downloads
- Form submissions
- Row and column deletions
- Calls to the Smartsheet API
- Admin Center changes
- User logins and authentication events
When to use Event Reporting
Use Event Reporting to investigate and monitor account activity you can't see elsewhere, for example:
- Track which users downloaded sensitive sheets over a set period.
- Identify who deleted a critical item, and when.
- Feed a security team's SIEM with a continuous activity stream for real-time monitoring, using SIEM integration.
Access Event Reporting data
To retrieve Event Reporting data on demand, use the Smartsheet Events API. The Events API documentation covers available endpoints, required authentication, supported filters, and response formats.
If you're pulling Event Reporting data programmatically, use date range filters to avoid timeouts. If you'd rather not poll the API at all, set up SIEM integration instead.
Send Event Reporting data to a SIEM
You can send Event Reporting data to a SIEM in two ways. Use the built-in SIEM integration, or a supported third-party integration.
SIEM integration is available only to Enterprise plans on Safeguard or Advance Platinum.
SIEM integration
SIEM integration streams Event Reporting data directly to your organization's SIEM or syslog server. Smartsheet delivers it over a TLS-secured connection, in OCSF format. Events typically arrive within a few minutes of the activity happening.
SIEM integration is included with Event Reporting at no extra cost. If your organization already has Event Reporting enabled, find it on the Audit page in Admin Center. Learn how to set up a SIEM integration.
Third-party SIEM integrations
Event Reporting data can also be routed to third-party SIEM tools. If your organization has integrated Skyhigh Security or Microsoft Defender for Cloud Apps, see the support contacts below.
Skyhigh Security
If you need assistance with your Skyhigh Security integration, contact Skyhigh Security support directly.
Microsoft Defender for Cloud Apps
If you need assistance with your Microsoft Defender for Cloud Apps integration, contact Microsoft Defender for Cloud Apps support.
Things to consider
- Event Reporting only stores data from the moment you turn it on. It doesn't include activity from before that point.
- Event Reporting keeps up to six months of activity history.
- You can't browse or search events inside Smartsheet. View them through the Events API or your connected SIEM.
- SIEM integration requires a syslog server that accepts TLS connections, with a firewall port open for incoming Smartsheet traffic.
- SIEM integration and a third-party integration that point to the same destination create duplicate events there.
- Turning on SIEM integration doesn't send your existing Event Reporting history to your SIEM. Only activity from the moment you connect streams there.