Audit the actions performed in Certificate Manager.
To audit logs
Log in as an administrator with the required permissions.
See Browsing roles for the permissions granted to each ad administrator role.
- Go to Administer > Audit Log.
- Define log views.
- Unfold the Columns list to select the properties you want to display as columns.
- Click Show Filter Options to display a filtering form below each column name.
- Select Show Filter Options / Remove all filters to remove all filters.
- Select Show Filter Options / <column> to remove the filters on the <column> column.
- Click Show Filter Options to hide the filtering options and keep the filters.
- Click Items per page at the bottom of the page, select the number of items to view per page: 10, 25, 50, or 100.
- Click Reset layout to remove all the column and filter customizations.
- Click the refresh icon to rerun the query with the current filters.
Column headers display a sorting icon when the column values can be sorted with a click.
- On the main grid, check the following log details.
- Performed By: The identifier of the user or internal component that performed the event.
- Logged At: The event time and date.
- Logs: A summary description of the event.
- Audit Code: The internal code of the audit log. See below for the supported values.
Administration logs
The following logs record administration events.
Audit Code | Log |
|---|---|
AUDIT_1114 | Events retention period set to |
AUDIT_1115 | Reports settings updated. Retention period: |
AUDIT_1116 | Plugin |
AUDIT_1117 | Public Enrollment Forms |
AUDIT_1119 | Address |
AUDIT_1120 | Single address created: |
AUDIT_1121 | Mapped address created: |
AUDIT_1122 | List of addresses created: |
AUDIT_1124 | Address deleted: |
AUDIT_1125 | Address |
AUDIT_1126 | Address |
AUDIT_1127 | New addresses imported in list of address |
AUDIT_1128 | Imported single address |
AUDIT_1129 | Imported list of addresses |
AUDIT_1168 | License with order number: |
AUDIT_1169 | License with order number: |
AUDIT_1170 | Entitlement usage updated for |
Authentication and authorization logs
The following logs record authentication and authorization events.
Audit Code | Log |
|---|---|
AUDIT_1010 | Auth provider |
AUDIT_1011 | Auth provider |
AUDIT_1012 | LDAP login failed for user: |
AUDIT_1013 | LDAP login failed as user: |
AUDIT_1017 | API token created for user |
AUDIT_1018 | API token deleted for user |
AUDIT_1023 | Roles updated for user |
AUDIT_1030 | API token deleted for user |
AUDIT_1031 | API token updated for user |
AUDIT_1032 | All API tokens deleted for user |
AUDIT_1033 | All API tokens deactivated for user |
AUDIT_1036 | Created initial user with username: |
AUDIT_1037 | Created user with username: |
AUDIT_1039 | Created LDAP user with username: |
AUDIT_1040 | Created external user username: |
AUDIT_1041 | Deleted user: |
AUDIT_1042 | Updated user: |
AUDIT_1043 | Updated LDAP user: |
AUDIT_1044 | Updated external user: |
AUDIT_1046 | Updated account password for user: |
AUDIT_1047 | Updated last login for user: |
AUDIT_1048 | Successful login by User: |
AUDIT_1057 | Failed login attempt for user: |
AUDIT_1058 | Failed login attempt for user: |
AUDIT_1059 | Maximum login attempts exceeded. Rejected login attempt for user: |
AUDIT_1060 | Login denied. Tenant id not found for user |
AUDIT_1061 | Global role created: |
AUDIT_1062 | Custom role created: |
AUDIT_1063 | Custom role updated: |
AUDIT_1064 | Authority role created: |
AUDIT_1065 | Composite role created: |
AUDIT_1066 | Role deleted: |
AUDIT_1067 | Role updated: |
AUDIT_1068 | Role |
AUDIT_1069 | Role |
AUDIT_1070 | Certificate role created: |
AUDIT_1071 | Certificate role updated: |
AUDIT_1092 | Failed login attempt for user: |
AUDIT_1093 | Failed login attempt. User does not exist. |
Automation logs
The following logs record rule and report events.
Audit Code | Log |
|---|---|
AUDIT_1201 |
|
AUDIT_1205 |
|
AUDIT_1209 |
|
AUDIT_1250 | Generated certificate report: |
AUDIT_1251 | Created report: |
AUDIT_1252 | Updated report: |
AUDIT_1253 | Deleted report: |
AUDIT_1254 | Report Schedule |
AUDIT_1255 | Report Schedule |
AUDIT_1256 | Report Schedule |
AUDIT_1257 | Delete report execution at |
AUDIT_1258 | Successfully renewed certificate |
Certificate logs
The following logs record certificate events.
Audit Code | Log |
|---|---|
AUDIT_1434 | Certificate |
AUDIT_1435 | Certificate |
AUDIT_1436 | Certificate |
AUDIT_1437 | Certificate |
AUDIT_1472 | Custom Field created: |
AUDIT_1473 | Custom Field deleted: |
AUDIT_1474 | Custom Field updated: |
AUDIT_1480 | Certificate exported: Common Name |
AUDIT_1491 | <n |
AUDIT_1492 | New certificate issued by authority: <a |
AUDIT_1493 | Certificate |
AUDIT_1494 | Certificate |
AUDIT_1498 | Certificate view |
AUDIT_1499 | Certificate view |
AUDIT_1500 | Certificate view |
Certificate policy logs
The following logs record Access Tags events.
Audit Code | Log |
|---|---|
AUDIT_1481 | Certificate Access Tag |
AUDIT_1482 | Certificate Access Tag |
AUDIT_1483 | Certificate Access Tag |
Control logs
The following logs record events on authorities, key managers, and discovery scanners.
Audit Code | Log |
|---|---|
AUDIT_1301 | CA Gateway added: |
AUDIT_1302 | CA Gateway updated: |
AUDIT_1303 | CA Gateway deleted: |
AUDIT_1304 | Authority added: |
AUDIT_1305 | Authority updated: |
AUDIT_1306 | Authority deleted: |
AUDIT_1371 | Successfully uploaded certificate with Private key Id: |
AUDIT_1375 | Key pair deactivated at Key Manager |
AUDIT_1376 | Verification request submitted for domain |
AUDIT_1377 | Key manager with plugin |
AUDIT_1378 | Key manager updated: |
AUDIT_1379 | Key manager deleted: |
AUDIT_1382 | Status updated for domain |
AUDIT_1383 | Re-verify request submitted for domain |
AUDIT_1384 | Discovery scanner added: |
AUDIT_1385 | Discovery scanner updated: |
AUDIT_1386 | Discovery scanner deleted: |
AUDIT_1387 |
|
AUDIT_1388 | Discovery scanner < |
Destination logs
The following logs record destination events.
Audit Code | Log |
|---|---|
AUDIT_1495 | Destination |
AUDIT_1496 | Destination |
AUDIT_1497 | Destination |
Public form logs
The following logs record Public Enrollment Form events.
Audit Code | Log |
|---|---|
AUDIT_1504 | Public form |
AUDIT_1505 | Public form |
AUDIT_1506 | Public form |
AUDIT_1507 | Certificate request (ID: |
AUDIT_1508 | Certificate request (ID: |
AUDIT_1509 | Certificate request (ID: |
AUDIT_1510 | Certificate request (ID: |
AUDIT_1511 | Error rejecting certificate request (ID: |
AUDIT_1512 | Error approving certificate request (ID: |
AUDIT_1513 | New Certificate request created. |
AUDIT_1514 | Certificate request (ID: |
AUDIT_1515 | New Certificate request created with key algorithm |
AUDIT_1516 | New Certificate request created key algorithm |
AUDIT_1517 | New Certificate request created with key algorithm |
AUDIT_1518 | Deleted |
AUDIT_1519 | Certificate request (ID: |
AUDIT_1520 | Certificate request (ID: |
AUDIT_1521 | Pkcs12 for Certificate Request (ID: |
Source logs
The following logs record source events.
Audit Code | Log |
|---|---|
AUDIT_1501 | Source deleted: |
AUDIT_1502 | Source with plugin |
AUDIT_1503 | Source updated: |