Audit log
Who did what, when, from where and on what, with optional export to your syslog or SIEM over verified TLS.
- Used by
- Admin
- Plan
- Free
- Status
- Available
- Category
- Monitoring and security
What it is
Every action is recorded, admins included. The trail can be exported off the node in RFC 5424 syslog with octet-counted framing, which rsyslog, Graylog and Splunk understand.
What it is for
Investigating an incident, and protecting the trail if the node itself is compromised.
Limits
With syslog+tls:// the server certificate is always verified and there is no switch to skip it; a private CA can be uploaded for that destination only. If the destination is down entries are queued and the advisor warns.