Managing Audit Files
  • 31 Dec 2024
  • 4 Minutes à lire
  • Sombre
    Lumière
  • PDF

Managing Audit Files

  • Sombre
    Lumière
  • PDF

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

Individual audit records can be viewed in the live audit viewer, and filtered and exported using the OneSpan Authentication Server Appliance Configuration Tool.

Events generated by the OneSpan Authentication Server component for auditing are stored in the internal database. They are moved to an audit database on a monthly basis or until a maximum audit data size limit of 500 MB is reached. When this limit is exceeded, new audit data is stored in a new database part.

Parts of the database can be downloaded and deleted via the OneSpan Authentication Server Appliance Configuration Tool. Downloading is the same as the exporting, but uses a format compatible with OneSpan Authentication Server.

Live Audit Viewer

Figure:  Live Audit Viewer

Viewing audit files

To view and filter audit files

  1. Launch the OneSpan Authentication Server Appliance Configuration Tool and enter your credentials (see  Accessing OneSpan Authentication Server Appliance Configuration Tool and OneSpan Authentication Server Administration Web Interface).
  2. Navigate to Monitoring > Audit Logs.
  3. If required, you can filter by using simple or advanced filters:.

    • To use the simple filter, type the characters to be searched for in the message part of the audit message in the Filter box. Only lines with content that matches the filter entry will be listed. To clear the filter, click X.

    • To use the advanced filter, click the arrow to the right of the Filter box to open the Advanced Filter dialog (see Figure: Advanced audit filter fields). For more information about searching using the filter fields, see Table: Audit filter fields.

      Using the advanced filter

      Figure: Using the advanced filter

      Figure:  Advanced audit filter fields

 

Table:  Audit filter fields
TypeDescription
Start DateOnly records after the date specified are displayed.
End DateRecords up to and including the entered date are displayed.
Type is

Only audit messages of the selected type are displayed (see  Send Audit Messages to Syslog).

Source containsThis field is only relevant if you have a replication setup (see  Configuring replication). Only records generated from this server are displayed.
Category containsOnly records with a category matching the category entered in this field are displayed.
Code containsOnly records with a matching error code are displayed. For a list of possible error codes, refer to the OneSpan Authentication Server Appliance Administrator Reference.
Host containsOnly records with a matching IP address are displayed.
Hostname containsOnly records with a matching host name are displayed.
Description containsOnly records with a matching string in the Description field are displayed.
Field ... containsSelect a field in the drop-down list and enter the matching string to be searched for. Only matching records are displayed.

It is only possible to access the advanced filter when the simple filter is cleared. To clear the simple filter, click the X icon next to the Filter box.

Exporting and downloading auditing information

Exporting auditing information can be useful in the following cases:

  • One reporting system is used for all servers on a network.
  • Auditing information needs to be kept for a long time.

You can use filters to define which data should be exported.

To export audit files

  1. Launch the OneSpan Authentication Server Appliance Configuration Tool and enter your credentials (see  Accessing OneSpan Authentication Server Appliance Configuration Tool and OneSpan Authentication Server Administration Web Interface).
  2. Navigate to Monitoring > Audit Logs.
  3. Click Export. The Export Log dialog opens (see Figure: Exporting audit files). Fields are explained in Table: Audit export fields.
Exporting audit files

Figure:  Exporting audit files



Table:  Audit export fields
TypeDescription
Start dateOnly records after the date specified are exported.
End dateRecords up to and including the entered date are exported.
SourceThis field is only relevant if you have a replication setup (see  Configuring replication). Only records generated from this server are exported.
CategoryOnly records with a category matching the category entered in this field are exported.
HostAudit records can be exported for all servers, or the local host only.
Output Format

This is the data output format to use:

  • IDENTIKEY. Select this option for OneSpan Authentication Server compatibility. It allows you to import the exported data to an instance of OneSpan Authentication Server that is acting as a dedicated reporting server in a setup with multiple OneSpan Authentication Server and/or OneSpan Authentication Server Appliance instances.
  • CSV. The comma-separated values format allows the data to be imported by other auditing systems.

Although it is still called CSV format, the CSV option creates an export file that uses tab characters as the separator, not a comma!

To download audit files

  1. Launch the OneSpan Authentication Server Appliance Configuration Tool and enter your credentials (see  Accessing OneSpan Authentication Server Appliance Configuration Tool and OneSpan Authentication Server Administration Web Interface).
  2. Navigate to Monitoring > Log File Management and click Databases. Available audit files will be listed below.
  3. Click the download icon to the right of an available audit file to download it.

    Downloading audit files

    Figure:  Downloading audit files

    Downloading audit data is the same as exporting and uses the OneSpan Authentication Server–compatible format.

    It is not possible to remove database partitions manually. However, you can set up log files to be deleted automatically.

To configure automatic deletion of audit files

  1. Launch the OneSpan Authentication Server Appliance Configuration Tool and enter your credentials (see  Accessing OneSpan Authentication Server Appliance Configuration Tool and OneSpan Authentication Server Administration Web Interface).
  2. Navigate to Settings > Logging and Auditing.
  3. Select Delete audit logs and specify how long you want to keep audit logs.

Cet article vous a-t-il été utile ?

What's Next
Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle