Table of Contents

Search

  1. Preface
  2. Introduction to Dynamic Data Masking Administration
  3. Authentication
  4. Security
  5. Connection Management
  6. JDBC Client Configuration
  7. ODBC Client Configuration
  8. Configuration for MicroStrategy
  9. Access Control
  10. Logs
  11. High Availability
  12. Server Control
  13. Performance Tuning
  14. Troubleshooting
  15. Appendix A: Database Keywords

Administrator Guide

Administrator Guide

Audit Trail and Reporting

Audit Trail and Reporting

The Dynamic Data Masking general audit trail and detailed audit trail log files contain information that you can use to verify changes a user made to the Dynamic Data Masking configuration.
The
auditTrail.log
file contains general audit information about changes in the configuration.
The detailed audit trail log file contains comprehensive audit information about modifications to the Dynamic Data Masking configuration properties. Dynamic Data Masking names the detailed audit file according to the year and month that it creates the file. For example, if Dynamic Data Masking creates a detailed audit file in April 2019, it names the file
2019_04.at
. You can use the detailed audit trail log files as input to the
audit
command and generate audit trail reports. The audit trail report shows all changes made by users for selected objects in the specified time frame.
The detailed audit file contains information about audit trail operations and their sources (the Management Console or the Server Control command line program) for the following Dynamic Data Masking objects.

Database

The detailed audit file contains information about the following audit trail operations and their sources for the Dynamic Data Masking database object:
Audit Trail Operation
Management Console
Server Control
Add
Yes
-
Remove
Yes
-
Copy
Yes
-
Move
Yes
-
Edit
Yes
-
Import
No
Yes
Export
No
Yes

Domain

The detailed audit file contains information about the following audit trail operations and their sources for the Dynamic Data Masking domain object:
Audit Trail Operation
Management Console
Server Control
Add
Yes
-
Copy
Yes
-
Move
Yes
-
Edit
Yes
-
Remove
Yes
-

Service

The detailed audit file contains information about the following audit trail operations and their sources for the Dynamic Data Masking service:
Audit Trail Operation
Management Console
Server Control
Add
Yes
-
Remove
Yes
-
Import
Yes
Yes
Export
Yes
Yes
Start
Yes
Yes
Stop
Yes
Yes

Authorization

The detailed audit file contains information about the following audit trail operations and their sources for Dynamic Data Masking authorization:
Audit Trail Operation
Management Console
Server Control
Edit
Yes
-

Host Port Security

The detailed audit file contains information about the following audit trail operations and their sources for Dynamic Data Masking host port security:
Audit Trail Operation
Management Console
Server Control
Edit
Yes
Yes

Server

The detailed audit file contains information about the following audit trail operations and their sources for the Dynamic Data Masking Server:
Audit Trail Operation
Management Console
Server Control
Edit (One of these operations: edit server, edit log level, edit Loggers, or Appenders)
Yes
Yes
Move
Yes
No
Remove
-
Yes
Backup
-
Yes
Restore
-
Yes
Lock
-
Yes
Support
No
Yes
License
Yes
-
Reload
-
Yes
Shutdown
-
Yes
Rename
-
Yes
Password
-
Yes
Network
-
Yes
Port
-
Yes
Login
Yes
Yes
Logout
Yes
Yes
Import in the command line can create or modify an object, Dynamic Data Masking audits it as an import operation. Import in the Management Console can modify an object, Dynamic Data Masking audits it as an edit operation.
Dynamic Data Masking audits Export in the command line as an export operation. Dynamic Data Masking does not audit Export in the Management Console.
Dynamic Data Masking 9.9.1 audit trail reports do not show connection rule or security rule set changes.

0 COMMENTS

We’d like to hear from you!