To generate an activity audit log report
- From the Safeguard for Privileged Passwords desktop Home page, select Activity Center.
-
Use the query tiles to specify the content of the report. By default the audit log returns all activity occurring within the last 24 hours. For more information, see Applying search criteria.
-
Click Run.
The information displayed by default depends on the type of activity report generated. (You can change the columns displayed by selecting the Columns in the upper right of the window.)
For example, the "All Activity" report displays the following information for each event.
- State: The left-most column displays one of the following regarding the availability of a recorded session:
- Blank: Indicates that there is no recorded session available.
- (green dot): Indicates that a live session is taking place. A Security Policy Administrator can click this button to launch the Desktop Player to follow what is happening in the current session.
- Play: Indicates that there is a recorded session available locally on the appliance. Clicking this button launches the Desktop Player to play back the selected recording.
-
Download: Indicates that there is a recorded session available on the archive server. Clicking this button downloads the recording for play back.
NOTE: These icons only appear on an "All Activity" or "Session Specific Activity" report.
- User: The name of the user who triggered the event.
- Date: The date and time the event occurred.
- Activity Category: The category that defines the type of activity that occurred.
-
Event: The event that occurred. Double-click an event to view or hide event details.
- State: The left-most column displays one of the following regarding the availability of a recorded session:
Actions once a report is generated
Once a report is generated, you can use the buttons above the grid as described below.
- Time frames: To rerun the report using a different time frame, select one of the following links, specify the time range, then click Run.
- Last 24 Hours (default)
- Last 7 Days
- Last 30 Days
- Last 60 Days
- Last 90 Days
-
Custom
- Workflow: Select an access request event and click Workflow to audit the transactions that occurred during the request's workflow from request to approval to review. For session requests, you can also replay a recorded session or live session from the Request Workflow dialog. For more information, see Replaying a session.
- Run: Select to generate the report using the specified time frame.
- Export: Right-click to select Export as CSV or Export as JSON to the location of your choice. Different information may be returned based on whether you select CSV or JSON. For example, JSON includes details of accounts discovered and CSV includes only the count of accounts. The time is set according to the user time zone. You can convert timestamps another time, if necessary. For more information, see Converting time stamps.
- Schedule: Select to schedule the generation of the activity audit log report. For more information, see Scheduling an activity audit log report.
- Save: Select to save the current search criteria to reuse the search later. For more information, see Saving search criteria.
- Column: Select to display a list of columns that can be displayed in the grid. Select the check box for data to be included in the report. Clear the check box for data to be excluded from the report. The additional columns available depend on the type of activity included in the report.