There are 2 main categories of logs in SPS:System Logs
- which contain operational information related to your SPS appliance and would be relevant to administrators for troubleshooting purposes.Session Audit Logs
- which contain a record of the user sessions hosted by the SPS appliance, and would be relevant to auditors.
To set up archiving for System Logs:
Login to the SPS web interface, and navigate to Basic Settings | Management | Syslog
Here you can configure the settings for a Syslog server, such as Syslog-NG or Splunk.
To setup archiving for Session Audit Data:
Login to the SPS web interface, and navigate to Basic Settings | Management | Universal SIEM forwarder
Here is where you can configure a SIEM compatible forwarder to archive the session data.
More information on this configuration can be found in the SPS Administration Guide
It is also possible to customization the log archiving to suit your particular needs. More information on this can be found in the SPS Administration Guide under the Customize system logging in One Identity Safeguard for Privileged Sessions section.
If you need assistance with product customization, please contact our Professional Services team.