Hitachi

JP1 Version 12 JP1/IT Desktop Management 2 Administration Guide


A.10 Outputting audit logs

Audit logs in JP1/IT Desktop Management 2 indicate who executed what operations, as well as when and from where those operations were executed. You can use audit logs to evaluate and assess internal controls. Note that the information necessary for running JP1/IT Desktop Management 2 is stored in the audit logs. This topic explains audit logs that are output from management servers. For details about audit logs of the distribution function using Remote Install Manager, see the JP1/IT Desktop Management 2 Distribution Function Administration Guide.

Tip

Audit logs are output not only from JP1/IT Desktop Management 2, but also from other JP1 products and OS (Windows event log). By using JP1/Audit Management - Manager#1 to collect and manage audit logs, you can use audit logs for evaluation and audit of the internal control. You can link with JP1/Audit Management - Manager only when the OS language for the management server is Japanese or English#2.

#1: JP1/Audit Management - Manager is a program that collects and manages audit logs to support evaluation and audit of the internal control for the whole system. In version 9 or earlier, this product was called JP1/NETM/Audit - Manager.

#2: If the language set in the OS of the management server is English, audit logs are output in UTF-8. Therefore, characters in audit logs might not be displayed properly in JP1/Audit Management - Manager.

Organization of this subsection

(1) Types of events output to audit logs

The following table describes the types of events that are output to audit logs and when JP1/IT Desktop Management 2 outputs audit logs. Events to be output to audit logs are classified by an event type identifier.

Event type

Description

When JP1/IT Desktop Management 2 outputs audit logs

StartStop

This event type indicates that this is an audit log related to the start and end of software.

  • Start and end of the JP1/IT Desktop Management 2 - Manager service

  • Startup failure of the JP1/IT Desktop Management 2 - Manager service

  • Abnormal end of the JP1/IT Desktop Management 2 - Manager service

Authentication

This event type indicates that this is an audit log related to the authentication results of a JP1/IT Desktop Management 2 - Manager user.

  • Success or failure in login to JP1/IT Desktop Management 2 - Manager

  • Logout from JP1/IT Desktop Management 2 - Manager

ConfigurationAccess

This event type indicates that this is an audit log related to operations performed by an administrator, such as a user account registration or agent setup.

  • Registration or removal of user accounts

  • Locking or unlocking of user accounts

  • Permission changes

  • Normal or abnormal end during setup of JP1/IT Desktop Management 2 - Manager

  • Normal or abnormal end during agent setup

  • Normal or abnormal end in license information registration

  • Success or failure in setting an ID and password for the support service site

  • Success in setting or removing a search authentication ID and password

  • Success or failure in setting an ID and password for AMT linkage

  • Success in setting or removing an ID and password for connecting to Active Directory

  • Success or failure in setting an ID and password for connecting to a mail server

  • Success in setting an ID and password for connecting to an operation log storage folder when the folder is located on a network

  • Success or failure in adding MDM settings

  • Success or failure in changing an ID or password for a MDM settings server or proxy

  • Success or failure in removing MDM settings

  • Normal or abnormal end to configuration of revision history

  • Success or failure in setting an ID and password for connecting to the output folder for saving the revision history

  • Success or failure in changing the automatic update of the network filter list

  • Success or failure in setting the JP1/NETM/NM - Manager linkage

  • Success or failure in changing the operation log settings

  • Success or failure in changing the range of targets subject to automatic updates of the network filter list

  • Success or failure in executing the distributelicense command

  • Success or failure in setting a component of an agent to be distributed

  • Success or failure in setting the asset status of hardware assets associated with deleted devices

  • Success or failure in changing the device maintenance settings

ExternalService

This event type indicates that this is an audit log related to the results of communication with external services such as Active Directory, mail sending, and the support service site.

  • Success or failure in connecting to Active Directory

  • Success or failure in connecting to JP1/NETM/NM

  • Success or failure in sending mail

  • Success or failure in connecting to the support service site

  • Success or failure in connecting to MDM products

ContentAccess

This event type indicates that this is an audit log related to operations such as changing the security policy, exporting device information, or collecting information from the support service.

  • Normal or abnormal end of the security policy change

  • Success or failure in exporting device information

  • Success in importing and exporting asset information

  • Failure in importing and exporting asset information

  • Success or failure in adding update programs

  • Success or failure in updating information in the SAMAC software dictionary

  • Success or failure in adding antivirus software information

  • Success or failure in updating action definition files by an administrator

  • Success or failure in updating the agent

  • Success or failure in removing operation logs

  • Normal or abnormal termination of an import of the network control list

  • Normal or abnormal termination of an export of the network control list

Maintenance

This event type indicates that this is an audit log related to database operation.

  • Success or failure in backing up databases

  • Success or failure in restoring databases

  • Success or failure in reorganizing databases

ManagementAction

This event type indicates that this is an audit log related to the following: the results of judgment and of executing action items for security status, and the results of executing action items for smart devices.

  • The results of judgment and of executing action items for security status

  • Results of executing action items for smart devices

(2) Audit log output format

The items of an audit log are output in the following order: "CALFHM", which indicates the output is in the audit log format, the revision number of the audit logs, and related output items. The following table describes the values and details of items output to audit logs.

Output item

Value

Description

Item name

Output attribute name

Common specification identifier

--

CALFHM

This identifier indicates that the output is in audit log format.

Common specification revision number

--

1.0

The revision number is used to manage audit logs.

Sequence number

seqnum

Sequence number

Sequence number for audit logs

Message ID

msgid

An ID of a message that has been made public

A message ID for each product

Date and time

date

Log output date and time

YYYY-MM-DDThh:mm:ss.sssTZD

  • YYYY: year (4-byte number)

  • MM: month (2-byte number)

  • DD: date (2-byte number)

  • T: delimiter (fixed)

  • hh: hour (2-byte number)

  • mm: minute (2-byte number)

  • ss: second (2-byte number)

  • sss: millisecond (3-byte number)

  • TZD: time zone

Program name

progid

JP1/ITDM2

The name of the product in which an event occurred

Component name

compid

One of the following is output:

  • Installer

  • Setup

  • Gui

  • Api

  • ManagerService

  • Utility

  • AgentControl

  • Agent

  • RelayManagerService (relay service of management server)

The name of the component in which an event occurred

Process ID

pid

An ID of a process

The process ID that detected the occurrence of an event

Location

ocp:ipv4 or ocp:host

The IP address or computer name of a management server

An IP address or host computer name of the server on which an event occurred

Audit event type

ctgry

One of the following is output:

  • StartStop

  • Authentication

  • ConfigurationAccess

  • ExternalService

  • ContentAccess

  • Maintenance

  • ManagementAction

This identifier classifies events to be output to audit logs.

Audit event results

result

One of the following is output:

  • Success

  • Failure

  • Occurrence (other than success or failure)

Results of events that occurred

Subject identifier

subj:uid or subj:euid

A user account or Administrator

Information about the user who caused an event to occur

Object information

obj

One of the following is output:

  • User (user account)

  • Role (permissions)

  • Setup (JP1/IT Desktop Management 2 - Manager setup)

  • Config (agent configuration)

  • Policy (security policy)

  • DeviceInfo (device information)

  • DataBase (database)

  • UpdateInfo (update program information)

  • AntivirusInfo (antivirus software information)

  • ActionDefinition (JP1/IT Desktop Management 2 - Manager action definition file)

  • Agent

  • AssetInfo (asset information)

  • SecurityInfo (operation log)

  • NetCtrlInfo (network control)

Information about the object that caused an event to occur

Action information

op

One of the following is output:

  • Start

  • Stop

  • Login

  • Logout

  • Add

  • Update

  • Delete

  • Request

  • Response

  • Import

  • Export

  • Backup

  • Maintain (reorganization)

  • Recovery (restore)

Action information about the user who caused an event to occur

Permissions information

auth

Either of the following is output:

  • User permissions for JP1/IT Desktop Management 2

  • Administrator (OS permissions)

Permissions information is not output if permissions have not been obtained.

Request source

from:ipv4

An IP address of a computer that performs operations in an operation window

The IP address of the server on which an event occurred

Message text

msg

Any message

A message that describes an event in detail

Legend: --: Not applicable

(3) Audit log save format

This section describes the save format for audit logs. Audit logs are output to JDNAUDTn.LOG (where n is a number in the range from 1 through 9).

When the size of a given log file (JDNAUDTn.LOG) reaches a certain level, audit logs are output to a different output file. For example, when the size of JDNAUDT1.LOG reaches a certain level, audit logs are then output to JDNAUDT2.LOG. In this way, output files for audit logs change sequentially. When the size of JDNAUDT9.LOG reaches a certain level, the existing audit logs stored in JDNAUDT1.LOG are deleted, and new audit logs are output to JDNAUDT1.LOG, restarting the sequence.