The Events tab is the live, searchable stream of normalised audit events captured by the collector — the fastest way to confirm the pipeline is working and to investigate recent activity on the appliance.

authentication, account_management, privilege_escalation, kernel_module, network_change, audit_configuration, and so on.modules, system-locale, identity, logins)./usr/bin/kmod, /usr/sbin/cron).Type in the search box and press Go! to filter the stream by category, audit key, executable or process name. Use it to answer questions like "show me every kernel-module load" or "what did /usr/bin/sudo do in the last few minutes".
The stream shows the most recent events held in memory. For long-term retention and correlation, forward events to a destination — this tab is for live inspection, not archival.