Chapter 7: Using the SafeWord 2008 Management Console
Managing and viewing audit logs
164
Choosing logs to monitor
You may choose to monitor all available audit logs or a particular subset, say,
for an end user.
Figure 108:
The Audit
Log Monitor
1
To monitor a specific user’s events, specify the user and the types of audit
logs that you wish to monitor.
2
Click the
Find
button. The Monitor Results: Audit Log Entries window
appears displaying all authentication activity performed by the user. The
administrator can review the authentication process with the end user, and
use the audit logs to debug the user’s authentication problem.
Important: By default, the Audit Log Monitor refreshes every 60 seconds. You may
find that a different refresh period works better for your particular environment. To
manually set the refresh period, change the value in the
Monitor_interval_in_seconds
property in the Console’s
client.ini
file (in
<install_dir>\AdminConsole). After changing the value, restart the Monitoring tool
for the changes to take effect.
Managing audit log archives
Every system event is recorded into audit logs which, over time, can become
quite large, and can negatively affect system performance. To avoid this,
configure SafeWord to remove the log entries from the database and save
them to a local file after a set period of time.
The Admin Server handles all archiving operations by constantly monitoring
the age of audit logs stored in the database. Once particular audit log entries
reach a certain age, they are removed from the database and archived to a
local file. Once archived, the Console and the command line reporting tool
cannot retrieve them.
Each time audit logs are archived, a file is created and given a name based on
the date and time of the first log in the archived set. To manage your audit log
archive sets, from the Console, select
File > Log Archives
. The Manage Audit
Log Archives window appears.