Audit log

Who did what, when, from where and on what, with optional export to your syslog or SIEM over verified TLS.

Used by
Admin
Plan
Free
Status
Available
Category
Monitoring and security

What it is

Every action is recorded, admins included. The trail can be exported off the node in RFC 5424 syslog with octet-counted framing, which rsyslog, Graylog and Splunk understand.

What it is for

Investigating an incident, and protecting the trail if the node itself is compromised.

Limits

With syslog+tls:// the server certificate is always verified and there is no switch to skip it; a private CA can be uploaded for that destination only. If the destination is down entries are queued and the advisor warns.