Audit the actions performed in Certificate Manager.
To audit logs
- Log in as an administrator with the global_admin role.
- Go to Administer > Audit Log.
- Define log views.
- Unfold the Columns list to select the properties you want to display as columns.
- Click Show Filter Options to display a filtering form below each column name.
- Select Show Filter Options / Remove all filters to remove all filters.
- Select Show Filter Options / <column> to remove the filters on the <column> column.
- Click Show Filter Options to hide the filtering options and keep the filters.
- Click Items per page at the bottom of the page, select the number of items to view per page: 10, 25, 50, or 100.
- Click Reset layout to remove all the column and filter customizations.
- Click the refresh icon to rerun the query with the current filters.
- On the main grid, check the following log details.
- Performed By: The identifier of the user or internal component that performed the event.
- Logged At: The event time and date.
- Logs: A summary description of the event.
- Audit Code: The internal code of the audit log. See below for the supported values.
Administration logs
The following logs record administration events.
Audit Code | Log |
---|---|
AUDIT_1114 | Events retention period set to |
AUDIT_1115 | Reports settings updated. Retention period: |
AUDIT_1116 | Plugin |
AUDIT_1117 | Public Enrollment Forms |
AUDIT_1119 | Address |
AUDIT_1120 | Single address created: |
AUDIT_1121 | Mapped address created: |
AUDIT_1122 | List of addresses created: |
AUDIT_1124 | Address deleted: |
AUDIT_1125 | Address |
AUDIT_1126 | Address |
AUDIT_1127 | New addresses imported in list of address |
AUDIT_1128 | Imported single address |
AUDIT_1129 | Imported list of addresses |
AUDIT_1168 | License with order number: |
AUDIT_1169 | License with order number: |
AUDIT_1170 | Entitlement usage updated for |
Authentication and authorization logs
The following logs record authentication and authorization events.
Audit Code | Log |
---|---|
AUDIT_1010 | Auth provider |
AUDIT_1011 | Auth provider |
AUDIT_1012 | LDAP login failed for user: |
AUDIT_1013 | LDAP login failed as user: |
AUDIT_1017 | API token created for user |
AUDIT_1018 | API token deleted for user |
AUDIT_1023 | Roles updated for user |
AUDIT_1030 | API token deleted for user |
AUDIT_1031 | API token updated for user |
AUDIT_1032 | All API tokens deleted for user |
AUDIT_1033 | All API tokens deactivated for user |
AUDIT_1036 | Created initial user with username: |
AUDIT_1037 | Created user with username: |
AUDIT_1039 | Created LDAP user with username: |
AUDIT_1040 | Created external user username: |
AUDIT_1041 | Deleted user: |
AUDIT_1042 | Updated user: |
AUDIT_1043 | Updated LDAP user: |
AUDIT_1044 | Updated external user: |
AUDIT_1046 | Updated account password for user: |
AUDIT_1047 | Updated last login for user: |
AUDIT_1048 | Successful login by User: |
AUDIT_1057 | Failed login attempt for user: |
AUDIT_1058 | Failed login attempt for user: |
AUDIT_1059 | Maximum login attempts exceeded. Rejected login attempt for user: |
AUDIT_1060 | Login denied. Tenant id not found for user |
AUDIT_1061 | Global role created: |
AUDIT_1062 | Custom role created: |
AUDIT_1063 | Custom role updated: |
AUDIT_1064 | Authority role created: |
AUDIT_1065 | Composite role created: |
AUDIT_1066 | Role deleted: |
AUDIT_1067 | Role updated: |
AUDIT_1068 | Role |
AUDIT_1069 | Role |
AUDIT_1070 | Certificate role created: |
AUDIT_1071 | Certificate role updated: |
AUDIT_1092 | Failed login attempt for user: |
AUDIT_1093 | Failed login attempt. User does not exist. |
Automation logs
The following logs record rule and report events.
Audit Code | Log |
---|---|
AUDIT_1201 |
|
AUDIT_1205 |
|
AUDIT_1209 |
|
AUDIT_1250 | Generated certificate report: |
AUDIT_1251 | Created report: |
AUDIT_1252 | Updated report: |
AUDIT_1253 | Deleted report: |
AUDIT_1254 | Report Schedule |
AUDIT_1255 | Report Schedule |
AUDIT_1256 | Report Schedule |
AUDIT_1257 | Delete report execution at |
AUDIT_1258 | Successfully renewed certificate |
Certificate logs
The following logs record certificate events.
Audit Code | Log |
---|---|
AUDIT_1434 | Certificate |
AUDIT_1435 | Certificate |
AUDIT_1436 | Certificate |
AUDIT_1437 | Certificate |
AUDIT_1472 | Custom Field created: |
AUDIT_1473 | Custom Field deleted: |
AUDIT_1474 | Custom Field updated: |
AUDIT_1480 | Certificate exported: Common Name |
AUDIT_1491 | <n |
AUDIT_1492 | New certificate issued by authority: <a |
AUDIT_1493 | Certificate |
AUDIT_1494 | Certificate |
AUDIT_1498 | Certificate view |
AUDIT_1499 | Certificate view |
AUDIT_1500 | Certificate view |
Certificate policy logs
The following logs record Access Tags events.
Audit Code | Log |
---|---|
AUDIT_1481 | Certificate Access Tag |
AUDIT_1482 | Certificate Access Tag |
AUDIT_1483 | Certificate Access Tag |
Control logs
The following logs record events on authorities, key managers, and discovery scanners.
Audit Code | Log |
---|---|
AUDIT_1301 | CA Gateway added: |
AUDIT_1302 | CA Gateway updated: |
AUDIT_1303 | CA Gateway deleted: |
AUDIT_1304 | Authority added: |
AUDIT_1305 | Authority updated: |
AUDIT_1306 | Authority deleted: |
AUDIT_1371 | Successfully uploaded certificate with Private key Id: |
AUDIT_1375 | Key pair deactivated at Key Manager |
AUDIT_1376 | Verification request submitted for domain |
AUDIT_1377 | Key manager with plugin |
AUDIT_1378 | Key manager updated: |
AUDIT_1379 | Key manager deleted: |
AUDIT_1382 | Status updated for domain |
AUDIT_1383 | Re-verify request submitted for domain |
AUDIT_1384 | Discovery scanner added: |
AUDIT_1385 | Discovery scanner updated: |
AUDIT_1386 | Discovery scanner deleted: |
AUDIT_1387 |
|
AUDIT_1388 | Discovery scanner < |
Destination logs
The following logs record destination events.
Audit Code | Log |
---|---|
AUDIT_1495 | Destination |
AUDIT_1496 | Destination |
AUDIT_1497 | Destination |
Public form logs
The following logs record Public Enrollment Form events.
Audit Code | Log |
---|---|
AUDIT_1504 | Public form |
AUDIT_1505 | Public form |
AUDIT_1506 | Public form |
AUDIT_1507 | Certificate request (ID: |
AUDIT_1508 | Certificate request (ID: |
AUDIT_1509 | Certificate request (ID: |
AUDIT_1510 | Certificate request (ID: |
AUDIT_1511 | Error rejecting certificate request (ID: |
AUDIT_1512 | Error approving certificate request (ID: |
AUDIT_1513 | New Certificate request created. |
AUDIT_1514 | Certificate request (ID: |
AUDIT_1515 | New Certificate request created with key algorithm |
AUDIT_1516 | New Certificate request created key algorithm |
AUDIT_1517 | New Certificate request created with key algorithm |
AUDIT_1518 | Deleted |
AUDIT_1519 | Certificate request (ID: |
AUDIT_1520 | Certificate request (ID: |
AUDIT_1521 | Pkcs12 for Certificate Request (ID: |
Source logs
The following logs record source events.
Audit Code | Log |
---|---|
AUDIT_1501 | Source deleted: |
AUDIT_1502 | Source with plugin |
AUDIT_1503 | Source updated: |