Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Audit Log
Administrator Help | Forcepoint Email Security | Version 8.5.x
The email protection system provides an Audit Log, which is an audit trail showing which administrators have accessed the Security Manager Email Security module and any changes made to policies and settings. The Audit Log additionally shows message actions taken by administrators, such as clearing a message queue or releasing, forwarding, or deleting email messages (added in version 8.5.3). Other actions shown in the audit log include changes made in the appliance CLI (added in version 8.5.3).
Monitoring administrator changes through the Audit Log enables you to ensure that system and message control is handled responsibly and in accordance with your organization's acceptable use policies. This information is available only to Super Administrators.
Access the Audit Log on the Audit tab of the page Main > Status > Logs to view the Audit Log and to export selected portions of it to a CSV or an HTML file, if desired.
Audit Log data
The following table details the system audit information that is collected and displayed in the Audit Log in table format:
 
Audit Log display options
The most recent records display when the Audit Log opens. The View from/To calendar controls are used to determine the date and time range to view. The calendar includes the following options:
*
*
*
*
*
*
View Audit Log records
1.
From the pull-down menu View, select the range of log entries to display; All, One Day, One Week, One Month, or Custom.
Selection of Custom enables the View from and To fields to specify the desired custom date and time range.
2.
Use the icons < and > to specify the time range.
3.
(If Custom was selected) Enter the desired date and time range in the fields, or use the calendar functionality.
4.
The Audit Log records for the selected time range display.
Configure display settings and navigate log entries
1.
From the pull-down menu Per page, select the number of entries to display; 25, 50, 100, or 200.
The default is 25.
2.
3.
Jump to a specific page; in the field Page, enter the page number and select Go.
Audit Log export options
Audit records are saved for 30 days. The Export option is used to preserve audit records longer than 30 days by exporting the log on a regular basis. Exporting does not remove records from the Audit Log; it transfers log data to a CSV or HTML file.
Export Audit Log records
1.
From the pull-down menu Export range, select a time period; Current page, Last 24 hours, Last 7 days, or Last 30 days.
Selection of Last 30 days exports the entire Audit Log file.
The Export Log dialog box displays.
2.
From the pull-down menu File type, select the desired output file type; CSV or HTML.
*
*
3.
The Export Log window closes and the selected data is exported.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2022 Forcepoint. All rights reserved.