There are 4 types of audit logs, listed below. They are kept in separate directories. Since log files are tenant-specific, they are stored in tenant-specific subdirectories.
Runtime Audit Log in JSON: Contains user registrations and authentications performed by the runtime Server, in JSON format. By default, Runtime Server audit logging is turned on.
Directory: TOMCAT_HOME/logs/auditlogs/<tenant_id>.Runtime Audit Log in CSV: Contains user registrations and authentications performed by the runtime Server, designed to be consumed by Digipass S3 Smart Sense and Digipass S3 Smart Analytics. The data is stored in a modified CSV format where "|" replaces ",". By default, CSV audit logging is turned on.
Directory: TOMCAT_HOME/logs/csvauditlogs/<tenant_id>.Server Admin Console Audit Log: Contains operations performed by administrative users:
Editing Properties/Policies
Export/Import Operations
Create/Delete Operations
Activate Policies
By default, the Admin Console audit logging is turned on. To disable Admin Console audit logs, see Admin Tenant Properties in the reference to Server Properties.
Directory: TOMCAT_HOME/logs/admin-auditlogs/<tenant_id>
Command-Line Tool Audit Log: Contains operations performed by command-line tools.
Editing Properties/Policies
Export/Import Operations
Create/Delete Operations
Activate Policies
You can find these logs on the server where the command-line tools were downloaded in the directory <NNL_HOME>/admin/logs/admin-auditlogs.
The Runtime audit logs are high volume so they roll over when they reach 100 MB or once a day. The Admin Console and the Command-Line tool audit logs roll over every day. Past audit logs are automatically compressed in .gz files.