Xerox 6400XF WorkCentre 6400 System Administrator Guide - Page 79

Audit Log, Enabling Audit Log, Saving an Audit Log, Interpreting the Audit Log - download

Page 79 highlights

Audit Log Security When the Audit Log feature is enabled, the printer begins recording events that happen on the printer. You can download the Audit Log as a tab-delimited text file, and review it to find security breaches and assess the printer's security. Enabling Audit Log Notes: • • Secure HTTP (SSL) must be enabled before you can enable Audit Log. For details, see Enabling Secure HTTP (SSL) on page 65. If your printer is locked, you must log in as a system administrator. For details, see Accessing CentreWare IS on page 17. 1. In CentreWare IS, click Properties > Security > Audit Log. 2. Click Enabled under Enabling Audit Log on machine. 3. Click Apply. Saving an Audit Log Note: If your printer is locked, you must log in as a system administrator. For details, see Accessing CentreWare IS on page 17. 1. In CentreWare IS, click Properties > Security > Audit Log. 2. Click Save. 3. Right-click the Download Log link and save the compressed auditfile.txt.gz file to your computer. 4. Extract the Auditfile.txt text file, and open it in a spreadsheet application that can read a tab- delimited text file. Interpreting the Audit Log The Audit Log is formatted into ten columns • Index: Column 1 lists a unique value that identifies the event. • Date: Column 2 lists the date that the event happened in mm/dd/yy format. • Time: Column 3 lists the time that the event happened in hh:mm:ss format. • Event ID: Column 4 lists the type of event. The number corresponds to a unique description. For details, see Audit Log Event Identification Numbers on page 174. • Event Description: Column 5 lists an abbreviated description of the type of event. For details, see Audit Log Event Identification Numbers on page 174. Notes: • • • One audit log entry is recorded for each network destination within a Workflow Scanning scan job. For Server Fax jobs: One audit log entry is recorded for each Server Fax job. For Email jobs: One audit log entry is recorded for each SMTP recipient within the job. WorkCentre 6400 Multifunction Printer 79 System Administrator Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184

Security
WorkCentre 6400 Multifunction Printer
System Administrator Guide
79
Audit Log
When the Audit Log feature is enabled, the printer begins recording events that happen on the printer.
You can download the Audit Log as a tab-delimited text file, and review it to find security breaches and
assess the printer’s security.
Enabling Audit Log
Notes:
Secure HTTP (SSL) must be enabled before you can enable Audit Log. For details, see
Enabling Secure HTTP (SSL)
on page 65.
If your printer is locked, you must log in as a system administrator. For details, see
Accessing CentreWare IS
on page 17.
1.
In CentreWare IS, click
Properties
>
Security
>
Audit Log
.
2.
Click
Enabled
under
Enabling Audit Log on machine
.
3.
Click
Apply
.
Saving an Audit Log
Note:
If your printer is locked, you must log in as a system administrator. For details, see
Accessing
CentreWare IS
on page 17.
1.
In CentreWare IS, click
Properties
>
Security
>
Audit Log
.
2.
Click
Save
.
3.
Right-click the
Download Log
link and save the compressed
auditfile.txt.gz
file to your computer.
4.
Extract the
Auditfile.txt
text file, and open it in a spreadsheet application that can read a tab-
delimited text file.
Interpreting the Audit Log
The Audit Log is formatted into ten columns
Index
: Column 1 lists a unique value that identifies the event.
Date
: Column 2 lists the date that the event happened in mm/dd/yy format.
Time
: Column 3 lists the time that the event happened in hh:mm:ss format.
Event ID
: Column 4 lists the type of event. The number corresponds to a unique description. For
details, see
Audit Log Event Identification Numbers
on page 174.
Event Description
: Column 5 lists an abbreviated description of the type of event. For details, see
Audit Log Event Identification Numbers
on page 174.
Notes:
One audit log entry is recorded for each network destination within a Workflow Scanning
scan job.
For Server Fax jobs: One audit log entry is recorded for each Server Fax job.
For Email jobs: One audit log entry is recorded for each SMTP recipient within the job.