Using Audit Log


The BMC AMI Resident Security Server (RSS) Audit Log is a database of audit log records written by one or more RSS applications. You can audit log records to be searched based on multiple search criteria and the record details displayed.

Use the Audit Log to review the details of your product activity. You can audit log records and search based on multiple search criteria and the record details displayed.

One line is displayed for each audit log record matching the search criteria. You can perform the following tasks:

  • Enter a value in the Search box to search through all the columns.
  • Click a column heading to sort in ascending or descending order.
  • Click a button to copy the Audit Log details to your clipboard or to export to XLSX, CSV, or PDF formats for offline processing.

The following image shows an example of the Audit Log:

AuditLogDisplay_spe2101.png

The following columns are displayed:

Column

Description

System

The System ID from which the record was written

Date

The start date of the record

Time

The starting time of the record

Application

The name of the RSS application that wrote the audit log record

User ID

The user ID against which the audit log record was written

Reference

The change reference entered for the activity that generated the audit log record

Log

Specific text within the Audit log message text

The number of entries is displayed at the bottom-left corner of the table:

auditLog_entryCount.png

Some entries have additional information. Click View to open the Audit Log Details pop-up window, such as in the following example:

auditLog_details.png

(SPE2307) The comment that you enter in the Confirm PAM Access Request dialog box in BMC AMI Security Privileged Access Manager is prefixed by the text Comment:. and displayed in the RSS audit log.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*