Viewing audit logs, Viewing audit log entries by group or device, Audit log entries online and in log files – HP 3PAR Policy Manager Software User Manual

Page 40: Audited operations and activity

Advertising
background image

Viewing Audit Logs

As stated earlier, you can view all audit log entries, entries for a selected group, or a selected
device. By default, audit log entries are displayed for the Global (parent) group and all of its
subgroups (children), as shown in

Figure 31 (page 39)

.

To view audit log entries for only the Global (parent) group, on the View audit log entries for
<Group Name> page in the Audit Log tab, click Show audit log entries for the selected group
only.

The View audit log entries for <Group Name> page appears displaying audit log entries for only
the Global (parent) group.

Viewing Audit Log Entries by Group or Device

To view audit log entries for a specific group or device:
1.

On the View audit log entries for <Group Name> page in the Audit Log tab, click Explore
Device Groups.

2.

Select a group or device.

The View audit log entries for <Group Name> page appears displaying audit log entries for
the selected group.

Audit Log Entries Online and in Log Files

During the installation process (for Windows), you selected how many days worth of audit log
entries Policy Manager should show in the application pages. The View audit log entries for <Group
Name> page shows only audit log entries for that number of days. All audit log entries are available
on disk if configured as such in the PolicyManager.properties file.

By default, audit log entries are stored on the computer running Policy Manager in the
\3PAR\Secure Service Policy Manager\audit

directory. Each day a file is created and

all audit log messages generated by Policy Manager for that day (from 12:00 to 23:59) are saved
to the file. By default, the daily files are created with the following syntax:

SSPM_Audit_<yyyy>_<mm>_<dd>.txt

where:

yyyy

is the current four-digit year

mm

is the current month

dd

is the current day.

NOTE:

There are no bounds on how large audit log files can grow or how many files will be

stored on disk. 3PAR recommends that you keep track of disk use and space, and archive the files
as needed.

Audited Operations and Activity

As discussed earlier, Policy Manager generates audit log entries for the Policy Manager and
agents.

Policy Manager entries are generated when:

A Policy Manager user logs in to or logs out of the server.

A Policy Manager user accepts or denies a pending action.

An action pending approval times out before it is accepted or denied.

40

Using HP 3PAR Policy Manager

Advertising