Individual data changes to the process view are displayed in the document view in the form of a log.
To show recorded data changes:
The data changes log shows the following information.
Information | Meaning |
---|---|
Change history | This shows the affected object and the changed properties. To give a better overview, objects are grouped according to the table to which the dataset belongs. |
Change date | Time of action. |
Changed by | User who made the changes. |
Old value | Column value before the change. |
New value | Column value after the change. |
Icon | Meaning |
---|---|
Column | |
Table | |
Foreign key | |
Object |
Use the following functions to further track data changes
Select the entry for the object in the log and click . Loads the object and opens the overview form.
Use the TimeTrace function to track changes to an object that were made up to any point in the past. In its analysis, the TimeTrace function includes the data changes saved to the One Identity Manager database as well as the records stored in a One Identity Manager History Database. You can use this to find out who had which permissions at which point in time. You can apply historical data to the current object and restore the object to the status prior to the change.
Figure 40: Analyzing historical data
The prerequisite for using the TimeTrace is that data changes are logged within the process monitoring system. Data changes that are saved in the One Identity Manager database can be analyzed immediately. The One Identity Manager History Database must be declared in the One Identity Manager database if archived data is to be included in the TimeTrace function. Historical data is displayed in the TimeTrace view in the Manager.
To link a History Database into a TimeTrace
Data | Description |
---|---|
Server |
Database server. |
Windows authentication |
Specifies whether Windows authentication is used. This type of authentication is not recommended. If you decide to use it anyway, ensure that your environment supports Windows authentication. |
User |
Database user. |
Password |
Database user password. |
Database |
Database. |
Data | Description |
---|---|
Direct access (without Oracle client) | Set this option for direct access.
Deactivate this option for access via Oracle Clients. Which connection data is required, depends on how this option is set. |
Server | Database server. |
Port | Oracle instance port. |
Service name | Service name. |
User | Oracle database user. |
Password | Database user password. |
Data source | TNS alias name from TNSNames.ora. |
|
NOTE: Set the option Disabled to disable the connection at a later time. If a One Identity Manager History Database is disabled, it is not taken into account when determining change data in the TimeTrace. |
To display an object's change data:
All change time stamps in the time frame that has been loaded are now shown in the overview below the timeline.
|
NOTE: To show changes to assignments for an object, such as a person's assignment to a department, or a resource's assignment to an organization, select the relevant assignment form from the task view. In the TimeTrace view you can then also select a source for which you wish to show changes. There is an additional selection list Source in which you can select the relevant assignment or base object. |
To select a change time stamp on the timeline:
When you select a change time stamp in TimeTrace, the program's document view opens the object's master data form or the assignment form. Use the timeline or quick edit a label to choose if you want the object settings or assignments to be displayed in the master data form before or after the changes have been made.
If an object property has a historical value, this is indicated by an icon. A tooltip shows the current value of the property. Click Show this property's change history... from the context menu to display the recorded data for this property.
You can apply historical data to the current object and restore the object to the status prior to the change.
To apply the historic values:
Data | Meaning |
---|---|
Property | These properties are changed when you apply the historical value. The changes are made immediately or through templates. |
New value | Value of the property; the historical value will then be saved |
Old value | Shows the current value of the property. This value is overwritten if the historical value is saved. |
Configuration Parameter | Meaning |
---|---|
Common\DeferredOperation | Preprocessor-relevant configuration parameters to record deferred operations. If this parameter is enabled, you can defer running an operation. Changes to the parameter require recompiling the database. |
To run operations later rather than immediately, you can set a run time for individual operations in the Manager. A run time can be scheduled for various operations. As well as the standard operations such as creating, changing and deleting an object, you can arrange for customized methods and events to be run. The DBQueue Processor checks for scheduled operations and triggers the operation to run when the set time is reached.
To schedule an activation time
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy