McAfee EPOCDE-AA-BA Product Guide - Page 112

ePolicy Orchestrator Log Files, The Audit Log, Working with the Audit Log, Viewing the Audit Log

Page 112 highlights

11 Other important server information ePolicy Orchestrator Log Files ePolicy Orchestrator Log Files Your ePolicy Orchestrator server maintains log files that chronicle various kinds of events and actions going on within the system. Contents The Audit Log The Server Task log The Threat Event Log The Audit Log Use the Audit Log to maintain and access a record of all McAfee ePO user actions. The Audit Log entries are displayed in a sortable table. For added flexibility, you can also filter the log so that it displays only failed actions, or only entries that are within a certain age. The Audit Log displays seven columns: • Action - The name of the action the McAfee ePO user attempted. • Completion Time - The time the action finished. • Details - More information about the action. • Priority - Importance of the action. • Start Time - The time the action was initiated. • Success - Whether the action was successfully completed. • User Name - User name of the logged-on user account that was used to take the action. Audit Log entries can be queried against. You can create queries with the Query Builder wizard that target this data, or you can use the default queries that target this data. For example, the Failed Logon Attempts query retrieves a table of all failed logon attempts. Working with the Audit Log Use these tasks to view and purge the Audit Log. The Audit Log records actions taken by McAfee ePO users. Tasks • Viewing the Audit Log on page 112 Use this task to view a history of administrator actions. Available data depends on how often and by what age the Audit Log is purged. • Purging the Audit Log on page 113 Use this task to purge the Audit Log. You can only purge Audit Log records by age. When you purge the Audit Log, the records are deleted permanently. • Purging the Audit Log on a schedule on page 113 Use this task to purge the Audit Log with a scheduled server task. Viewing the Audit Log Use this task to view a history of administrator actions. Available data depends on how often and by what age the Audit Log is purged. 112 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

ePolicy Orchestrator Log Files
Your ePolicy Orchestrator server maintains log files that chronicle various kinds of events and actions
going on within the system.
Contents
The Audit Log
The Server Task log
The Threat Event Log
The Audit Log
Use the Audit Log to maintain and access a record of all McAfee ePO user actions. The Audit Log
entries are displayed in a sortable table. For added flexibility, you can also filter the log so that it
displays only failed actions, or only entries that are within a certain age.
The Audit Log displays seven columns:
Action
— The name of the action the McAfee ePO user attempted.
Completion Time
— The time the action finished.
Details
— More information about the action.
Priority
— Importance of the action.
Start Time
— The time the action was initiated.
Success
— Whether the action was successfully completed.
User Name
— User name of the logged-on user account that was used to take the action.
Audit Log entries can be queried against. You can create queries with the Query Builder wizard that
target this data, or you can use the default queries that target this data. For example, the Failed
Logon Attempts query retrieves a table of all failed logon attempts.
Working with the Audit Log
Use these tasks to view and purge the Audit Log. The Audit Log records actions taken by McAfee ePO
users.
Tasks
Viewing the Audit Log
on page 112
Use this task to view a history of administrator actions. Available data depends on how
often and by what age the Audit Log is purged.
Purging the Audit Log
on page 113
Use this task to purge the Audit Log. You can only purge Audit Log records by age. When
you purge the Audit Log, the records are deleted permanently.
Purging the Audit Log on a schedule
on page 113
Use this task to purge the Audit Log with a scheduled server task.
Viewing the Audit Log
Use this task to view a history of administrator actions. Available data depends on how often and by
what age the Audit Log is purged.
11
Other important server information
ePolicy Orchestrator Log Files
112
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide