The Security Events Service console provides a centralized management interface for monitoring and controlling the flow of security events between Omnissa services and third-party products.
From the console, you can:
- Manage sources and view their event streams
- Manage subscribers and view their event streams
- Generate reports
Managing Sources
You can view all sources, and create, edit, or delete external sources, from the Sources tab in the Security Events Service console. Sources are of two types:
- Internal Sources are the Omnissa services that generate security events, such as Workspace ONE UEM and Omnissa Access. Internal sources are preconfigured in the Security Events Service.
- External Sources are third-party identity or security products, such as Okta or any other product that implements the SSF CAEP standard, that you configure to send events to the Security Events Service. See Configuring Sources in the Security Events Service to add Okta or another third-party product as a source.
View, edit, create, or delete sources
-
In the Omnissa Intelligence console, select Workspace Security > Security Events.
-
Click Launch Security Events.
The Security Events console appears in a new tab.
-
Select the Sources tab.

-
To view or update a source, select it in the left pane.
For external sources, the Source Details section in the right pane provides the configuration details. To edit the configuration, click Edit.
You can also view the list of CAEP events that the Security Events Service requests as well as the ones that the external source delivers.
-
To add an external source, click Add External Source.
See Configuring Sources in the Security Events Service to add Okta or another third-party product as a source.
Monitor the health of internal sources
You can view the health status of internal sources in the Sources tab. For the Security Events Service to receive events from a source, its status must be Healthy. For example:

-
Workspace ONE UEM: The status indicates whether the environment is properly configured for the Security Events Service to receive device compliance signals from Workspace ONE UEM.
Status values include:
- Healthy: The environment is properly configured.
- Unhealthy: There is an issue with the configuration. Click Reset to restore the configuration. Then check the status after a couple of minutes by clicking Check Status. If the issue persists after resetting, contact Omnissa Support for assistance.
Note: If you attempt to reset multiple times in quick succession, you might need to wait a few minutes before trying again. - Unknown: The status could not be determined. Click Check Status to refresh the status. If the issue persists, wait a few minutes and then try again.
- Not Configured: The environment is not configured for the Security Events Service to receive device compliance signals from Workspace ONE UEM. Contact Omnissa Support to configure Workspace ONE UEM as a source.
-
Workspace ONE Access: The status indicates whether the environment is properly configured for the Security Events Service to receive events from Omnissa Access. The status must be Healthy.
View active streams
You can view a source's event stream by selecting the source in the Sources tab and scrolling to the Events section in the right pane.
For example:

UUID: The stream’s unique identifier
Status: Enabled or Deactivated
Last Successful Send: The time when an event was last received successfully from the source
Last Failed Send: The time when the last error occurred while receiving an event from the source. You can view details about the error.
Note that a Last Failed Send entry continues to appear even after subsequent successful receipts.
Last Verification Request: The last time the Security Events Service sent a verification request to the source
Last Verification Received: The last time a verification response was received from the source
Last Verification Failure: The error code, if the last verification attempt failed
Events Delivered: The type of events delivered by the source
Managing Subscribers
You can view, edit, create, and delete subscribers from the Subscribers tab in the Security Events Service.
View, edit, create, or delete subscribers
-
In the Omnissa Intelligence console, select Workspace Security > Security Events.
-
Click Launch Security Events.
The Security Events console appears in a new tab.
-
Select the Subscribers tab.

-
To view or update a subscriber, select it in the left pane.
In the Subscriber details section in the right pane, you can view:
- The information required to configure the third-party product, including the OAuth 2.0 credentials and the SSF Well-known URL
- The source of events
- The events you authorized the Security Events service to transmit
You can also make the following changes:
- Regenerate the client secret, if required
Note: When you regenerate the secret, the previous secret is immediately invalidated, and existing integrations stop working. Make sure that you copy the secret before exiting the page, or you will have to regenerate the secret again. - Edit the subscriber name
- (Okta only) Update the Audience URL
-
To add a subscriber, click Add and follow the wizard to create a new subscriber.
The process is similar to the process you followed to create the first subscriber. See Configuring Subscribers in the Security Events Service.
View active streams
You can view a subscriber's event stream by selecting the subscriber in the Subscribers tab and scrolling to the Events section in the right pane.
Note: If Okta is the subscriber, the stream is empty until you complete the integration in the Okta console to configure Okta as the receiver.
For example:

Status: Enabled or Deactivated (controlled by the receiver)
Estimated Queue Depth: The number of pending events (estimated)
UUID: The stream’s unique identifier
Last Successful Send: The time when a signal was last transmitted successfully
Last Failed Send: The time when the last error occurred during transmission. You can view details about the error.
Note that a Last Failed Send entry continues to appear even after subsequent successful transmissions.
Last Verification Date: The last time the connection was verified. A value appears only if the receiver requests verification information. When Okta is the subscriber, a value does not appear.
Delivery Endpoint URL: The receiver URL
Events Delivered: The type of events delivered to the receiver (the intersection of the events transmitted and events requested)
If you want to rename the stream to a more friendly name than the default UUID name, click the edit icon next to the stream title and enter the new name.

Generating Reports
You can view audit events in the Reports tab to monitor activity or troubleshoot errors.
-
In the Omnissa Intelligence console, select Workspace Security > Security Events.
-
Click Launch Security Events.
The Security Events console appears in a new tab.
-
Select the Reports tab.
-
From the Event menu, select the type of report you want to generate.
-
Select the timeframe and the type of action, then click Show Results.
-
To view details of an event, click the View Details link in the Details column.
-
To export the report as a CSV file, click the Export link at the top-right of the page.
Admin Tasks Report
The Admin Tasks report includes audit events related to administration and configuration. For example, it includes events for creating, updating, or deleting subscribers in the Security Events Service. It also includes events created when subscriber credentials are regenerated.
For example:

Message Flows Report
The Message Flows report contains events that the Security Events Service received from the source and published to the receiver.
Published events are categorized by success and failure.
For example:

Stream Management Report
The Stream Management report shows audit events related to creating, updating, and deleting streams. You can create the report by subscriber.
For example:

Was this page helpful?