Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Viewing Forcepoint DLP Logs > The Forcepoint DLP audit log
The Forcepoint DLP audit log
Administrator Help | Forcepoint DLP | Version 8.8.2
Use the Main > Logs > Audit Log page in the Data Security module of the Security Manager to review actions performed by administrators in the system. For example, the audit log can show when administrators:
*
*
*
*
(Configure auditing for viewing incident details on the Settings > Authorization > Administrators page. Select Audit incident detail views.)
The audit log can be used to investigate unauthorized or irregular changes to the system that might jeopardize employee privacy or breach an IT security compliance policy.
By default, the displayed actions are sorted by date and time. If a filter is used, the number of displayed actions is shown at the top of the list.
*
Administration - Displays actions performed by administrators during the designated period, such as adding a new access role or configuring user directories. Also displays actions made on administrators, such as adding a new administrator or changing an administrator's permissions.
*
Log on/Log out - Displays log on and log out actions so you know which administrators where active during the designated period.
*
Status - Displays actions performed on status reports and logs, such as deleting an entry or creating an audit record.
*
Policy management - Displays actions performed on policies, such as updating predefined policies, editing quick policies, or creating a new policy.
*
Reporting - Displays actions performed on reports during the designated period, such as editing or creating a new report.
*
Incident management - Displays actions performed on incidents, such as deleting incidents.
*
Archiving - Displays actions performed on incident archives, such as deleting or restoring an archive.
*
System modules - Displays actions performed on system modules, such as editing a configuration or adding a module.
Retention of audit logs
Audit log records are kept indefinitely by default. However, an automatic service can be configured in the SQL Server database to delete old audit log records. When enabled, cleanup occurs daily at 6:00am in which logs older than a configured number of days are deleted.
Use the following steps to configure automatic cleanup in the SQL Server database.
1.
2.
Update PA_CONFIG_PROPERTIES set value = <number of days> where NAME = 'DELETE_AUDIT_RECORDS_OLDER_THAN_DAYS';
Replace <number of days> with the age, in days, after which old audit log records should be deleted. Cleanup does not occur if this property is missing or its value is less than one.
3.
 

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Viewing Forcepoint DLP Logs > The Forcepoint DLP audit log
Copyright 2021 Forcepoint. All rights reserved.