Audit the actions performed in Certificate Manager.
To audit logs
- Log in as an administrator with the global_admin role.
- Go to Administer > Audit Log.
- Define log views. - Unfold the Columns list to select the properties you want to display as columns.
- Click Show Filter Options to display a filtering form below each column name.
- Select Show Filter Options / Remove all filters to remove all filters.
- Select Show Filter Options / <column> to remove the filters on the <column> column.
- Click Show Filter Options to hide the filtering options and keep the filters.
- Click Items per page at the bottom of the page, select the number of items to view per page: 10, 25, 50, or 100.
- Click Reset layout to remove all the column and filter customizations.
- Click the refresh icon to rerun the query with the current filters.
 Column headers display a sorting icon when the column values can be sorted with a click. 
- On the main grid, check the following log details. - Performed By: The identifier of the user or internal component that performed the event. 
- Logged At: The event time and date.
- Logs: A summary description of the event.
- Audit Code: The internal code of the audit log. See below for the supported values.
 
Administration logs
The following logs record administration events.
| Audit Code | Log | 
|---|---|
| AUDIT_1114 | Events retention period set to  | 
| AUDIT_1115 | Reports settings updated. Retention period:  | 
| AUDIT_1116 | Plugin  | 
| AUDIT_1117 | Public Enrollment Forms   | 
| AUDIT_1119 | Address  | 
| AUDIT_1120 | Single address created:  | 
| AUDIT_1121 | Mapped address created:  | 
| AUDIT_1122 | List of addresses created:  | 
| AUDIT_1124 | Address deleted:  | 
| AUDIT_1125 | Address  | 
| AUDIT_1126 | Address  | 
| AUDIT_1127 | New addresses imported in list of address  | 
| AUDIT_1128 | Imported single address  | 
| AUDIT_1129 | Imported list of addresses  | 
| AUDIT_1168 | License with order number:  | 
| AUDIT_1169 | License with order number:  | 
| AUDIT_1170 | Entitlement usage updated for  | 
Authentication and authorization logs
The following logs record authentication and authorization events.
| Audit Code | Log | 
|---|---|
| AUDIT_1010 | Auth provider  | 
| AUDIT_1011 | Auth provider  | 
| AUDIT_1012 | LDAP login failed for user:  | 
| AUDIT_1013 | LDAP login failed as user:  | 
| AUDIT_1017 | API token created for user  | 
| AUDIT_1018 | API token deleted for user  | 
| AUDIT_1023 | Roles updated for user  | 
| AUDIT_1030 | API token deleted for user  | 
| AUDIT_1031 | API token updated for user  | 
| AUDIT_1032 | All API tokens deleted for user  | 
| AUDIT_1033 | All API tokens deactivated for user  | 
| AUDIT_1036 | Created initial user with username:  | 
| AUDIT_1037 | Created user with username:  | 
| AUDIT_1039 | Created LDAP user with username:  | 
| AUDIT_1040 | Created external user username:  | 
| AUDIT_1041 | Deleted user:  | 
| AUDIT_1042 | Updated user:  | 
| AUDIT_1043 | Updated LDAP user:  | 
| AUDIT_1044 | Updated external user:  | 
| AUDIT_1046 | Updated account password for user:  | 
| AUDIT_1047 | Updated last login for user:  | 
| AUDIT_1048 | Successful login by User:  | 
| AUDIT_1057 | Failed login attempt for user:  | 
| AUDIT_1058 | Failed login attempt for user:  | 
| AUDIT_1059 | Maximum login attempts exceeded. Rejected login attempt for user:  | 
| AUDIT_1060 | Login denied. Tenant id not found for user  | 
| AUDIT_1061 | Global role created:  | 
| AUDIT_1062 | Custom role created:  | 
| AUDIT_1063 | Custom role updated:  | 
| AUDIT_1064 | Authority role created:  | 
| AUDIT_1065 | Composite role created:  | 
| AUDIT_1066 | Role deleted:  | 
| AUDIT_1067 | Role updated:  | 
| AUDIT_1068 | Role  | 
| AUDIT_1069 | Role  | 
| AUDIT_1070 | Certificate role created:  | 
| AUDIT_1071 | Certificate role updated:  | 
| AUDIT_1092 | Failed login attempt for user:  | 
| AUDIT_1093 | Failed login attempt. User does not exist. | 
Automation logs
The following logs record rule and report events.
| Audit Code | Log | 
|---|---|
| AUDIT_1201 | 
 | 
| AUDIT_1205 | 
 | 
| AUDIT_1209 | 
 | 
| AUDIT_1250 | Generated certificate report:  | 
| AUDIT_1251 | Created report:  | 
| AUDIT_1252 | Updated report:  | 
| AUDIT_1253 | Deleted report:  | 
| AUDIT_1254 | Report Schedule  | 
| AUDIT_1255 | Report Schedule  | 
| AUDIT_1256 | Report Schedule  | 
| AUDIT_1257 | Delete report execution at  | 
| AUDIT_1258 | Successfully renewed certificate  | 
Certificate logs
The following logs record certificate events.
| Audit Code | Log | 
|---|---|
| AUDIT_1434 | Certificate  | 
| AUDIT_1435 | Certificate  | 
| AUDIT_1436 | Certificate  | 
| AUDIT_1437 | Certificate  | 
| AUDIT_1472 | Custom Field created:  | 
| AUDIT_1473 | Custom Field deleted:  | 
| AUDIT_1474 | Custom Field updated:  | 
| AUDIT_1480 | Certificate exported: Common Name  | 
| AUDIT_1491 | <n | 
| AUDIT_1492 | New certificate issued by authority: <a | 
| AUDIT_1493 | Certificate  | 
| AUDIT_1494 | Certificate  | 
| AUDIT_1498 | Certificate view  | 
| AUDIT_1499 | Certificate view  | 
| AUDIT_1500 | Certificate view  | 
Certificate policy logs
The following logs record Access Tags events.
| Audit Code | Log | 
|---|---|
| AUDIT_1481 | Certificate Access Tag  | 
| AUDIT_1482 | Certificate Access Tag  | 
| AUDIT_1483 | Certificate Access Tag  | 
Control logs
The following logs record events on authorities, key managers, and discovery scanners.
| Audit Code | Log | 
|---|---|
| AUDIT_1301 | CA Gateway added:  | 
| AUDIT_1302 | CA Gateway updated:  | 
| AUDIT_1303 | CA Gateway deleted:  | 
| AUDIT_1304 | Authority added:  | 
| AUDIT_1305 | Authority updated:  | 
| AUDIT_1306 | Authority deleted:  | 
| AUDIT_1371 | Successfully uploaded certificate with Private key Id:  | 
| AUDIT_1375 | Key pair deactivated at Key Manager  | 
| AUDIT_1376 | Verification request submitted for domain  | 
| AUDIT_1377 | Key manager with plugin  | 
| AUDIT_1378 | Key manager updated:  | 
| AUDIT_1379 | Key manager deleted:  | 
| AUDIT_1382 | Status updated for domain  | 
| AUDIT_1383 | Re-verify request submitted for domain  | 
| AUDIT_1384 | Discovery scanner added:  | 
| AUDIT_1385 | Discovery scanner updated:  | 
| AUDIT_1386 | Discovery scanner deleted:  | 
| AUDIT_1387 | 
 | 
| AUDIT_1388 | Discovery scanner < | 
Destination logs
The following logs record destination events.
| Audit Code | Log | 
|---|---|
| AUDIT_1495 | Destination  | 
| AUDIT_1496 | Destination  | 
| AUDIT_1497 | Destination  | 
Public form logs
The following logs record Public Enrollment Form events.
| Audit Code | Log | 
|---|---|
| AUDIT_1504 | Public form  | 
| AUDIT_1505 | Public form  | 
| AUDIT_1506 | Public form  | 
| AUDIT_1507 | Certificate request (ID:  | 
| AUDIT_1508 | Certificate request (ID:  | 
| AUDIT_1509 | Certificate request (ID:  | 
| AUDIT_1510 | Certificate request (ID:  | 
| AUDIT_1511 | Error rejecting certificate request (ID:  | 
| AUDIT_1512 | Error approving certificate request (ID:  | 
| AUDIT_1513 | New Certificate request created. | 
| AUDIT_1514 | Certificate request (ID:  | 
| AUDIT_1515 | New Certificate request created with key algorithm  | 
| AUDIT_1516 | New Certificate request created key algorithm  | 
| AUDIT_1517 | New Certificate request created with key algorithm  | 
| AUDIT_1518 | Deleted  | 
| AUDIT_1519 | Certificate request (ID:  | 
| AUDIT_1520 | Certificate request (ID:  | 
| AUDIT_1521 | Pkcs12 for Certificate Request (ID:  | 
Source logs
The following logs record source events.
| Audit Code | Log | 
|---|---|
| AUDIT_1501 | Source deleted:  | 
| AUDIT_1502 | Source with plugin  | 
| AUDIT_1503 | Source updated:  |