Reference of syslog messages for audit logging

eperi sEcure Platform generates syslog messages for certain user actions. You can use these messages for the audit logging of your company.

The prerequisite is that syslog messaging is configured and activated in eperi sEcure Platform. How to do this is explained in section Syslog Integration settings.

In the following, all syslog messages are listed that are generated for corresponding user actions.

Table 1. Syslog messages of eperi sEcure Platform
User/System activity Message text
Administrator activated/deactivated the Change Request status for a certain category (e.g. "Salesforce") user@ipaddress Activated/Deactivated ChangeRequest status for changeRequestStatus.Category
Administrator activated a syslog configuration entry user@ipaddress enabled syslog configuration: configName
Administrator activated TLS for proxy user@ipaddress activated TLS for proxy proxyName
Administrator added a new SSO Rewriting Rule user@ipaddress New SSO Rewriting Rule <'regularExpression','Replacement'> added
Administrator added or removed permission(s) to a role user@ipaddress changed the permission assignments for role 'role-name'
Administrator assigned or unassigned Admin Role(s) to an Active Directory Group user@ipaddress changed the Role assignments for AD Group 'distinguishedName'
Administrator changed advanced proxy settings user@ipaddress changed advanced proxy settings. key = value
Administrator changed assignment of apps to proxy user@ipaddress changed assignment of apps to proxy.

user@ipaddress Added: appName1, Deleted: appName2

Administrator changed his password user@ipaddress changed his password
Administrator changed his password. The new password contains more than 11 digits. Check for permutations of blacklisted entries is skipped, since the password entered contains more than 11 digits.
Administrator changed Key Rotation settings to "Choose a random key per encryption" user@ipaddress set key rotation mode to RANDOM.
Administrator changed Key Rotation settings to "Generate a new key per encryption" user@ipaddress set key rotation mode to UNIQUE.
Administrator changed Key Rotation settings to a key available in the Keys tab user@ipaddress set key rotation mode to FIXED with keyID 'keyID'.
Administrator changed password settings user@ipaddress Password settings changed successfully.
Administrator changed the authentication method of an app user@ipaddress changed the authentication method of app appName to authenticationMethod
Administrator changed the description of an Active Directory Group user@ipaddress has modified Active Directory Group 'distinguishedName'
Administrator changed the description of a role user@ipaddress has modified role 'role-name'
Administrator changed the password of an administrator user@ipaddress changed the password of administrator 'user'
Administrator changed the password of a user user@ipaddress changed the password of the user 'username'
Administrator changed the port for a proxy user@ipaddress changed port for proxy proxyName to nnnn
Administrator changed the Role assignments for an administrator user@ipaddress changed the Role assignments for administrator 'login'
Administrator completed the creation of 10000 new data encryption keys user@ipaddress completed the creation of '10000' new data encryption keys to be used in random key mode.
Administrator created an AES key user@ipaddress created AES key name
Administrator created an AES key for HSM user@ipaddress created AES key name (HSM)
Administrator created a new administrator user@ipaddress has created new administrator 'user'
Administrator created a new app user@ipaddress New App (appName) was successfully created
Administrator created a new reverse or forward proxy user@ipaddress New reverseproxy/forwardproxy (proxyName) was successfully created
Administrator created a new role user@ipaddress has created new role 'role-name'
Administrator created a new Token Profile Tokenprofile (Name of Token Profile) was successfully created
Administrator created a new user (in the Authentication tab of the eperi sEcure Admin Console) user@ipaddress New user was succesfully created.
Administrator created or changed the configuration of the Token Database user@ipaddress Successfully created/changed the Token Database configuration.
Administrator created or imported an Active Directory Group Mapping user@ipaddress has created new Active Directory Group 'distinguishedName'
Administrator deactivated TLS for proxy user@ipaddress deactivated TLS for proxy proxyName
Administrator deleted a key user@ipaddress deleted the key 'keyname' with key id 'keyID' and algorithm 'algorithm'
Administrator deleted all AdGroups user@ipaddress deleted all AdGroups
Administrator deleted an Active Directory Group user@ipaddress deleted the AdGroup 'distinguishedName'
Administrator deleted an administrator user@ipaddress deleted the administrator 'user'
Administrator deleted an app user@ipaddress deleted the app 'appName' successfully.
Administrator deleted an app template All versions of the template "templateID" have been successfully deleted
Administrator deleted a proxy user@ipaddress proxyType (proxyName) was successfully deleted.
Administrator deleted a role (in the Administrators tab) user@ipaddress deleted the role 'role-name'
Administrator deleted a sylog configuration entry user@ipaddress deleted syslog configuration: configName
Administrator deleted a Token Profile Token profile "Name of Token Profile" has been successfully deleted
Administrator deleted a user user@ipaddress deleted the user 'username'
Administrator disabled a syslog configuration entry user@ipaddress disabled syslog configuration: configName
Administrator edited a sylog configuration entry user@ipaddress changed syslog configuration oldConfigName to configName
Administrator exported an app template user@ipaddress Template templateName was successfully exported
Administrator exported the eperi sEcure Platform Relying Party Trust Metadata user@ipaddress exported the eperi sEcure Platform Relying Party Trust Metadata
Administrator exported the eperi sEcure Platform SSO ID Provider Metadata user@ipaddress exported the eperi sEcure Platform SSO ID Provider Metadata
Administrator exported the Security Configuration (This message is only available up to Release 3.18.13.) user@ipaddress exported the security configuration
Administrator generated new SSO Encryption and Signature validation certificates user@ipaddress Generated new SSO Encryption and Signature validation certificates
Administrator generated several AES keys via batch process user@ipaddress started batch process pid for creating AES keys with prefix prefix, start - end
Administrator imported a certificate into the Trusted Store user@ipaddress imported a trusted certificate (thumbprint)
Administrator imported a new SSO ID Provider configuration user@ipaddress New SSO ID Provider configuration imported.
Administrator imported a PKCS#12 container user@ipaddress imported a key pair, name name[,warnings]
Administrator imported a template user@ipaddress imported template (id: id, version version)
Administrator imported new Relying Party Trust Metadata user@ipaddress New Relying Party Trust Metadata imported
Administrator imported the security configuration (from a release <= 3.18.13) user@ipaddress imported the security configuration
Administrator logged in to the eperi sEcure Admin Console user@ipaddress has logged in successfully.
Administrator logged out of the eperi sEcure Admin Console user@ipaddress has logged out.
Administrator modified an Active Directory Group Mapping user@ipaddress has modified new Active Directory Group 'distinguishedName'
Administrator modified a role user@ipaddress has modified role 'roleName'
Administrator modified some details of an administrator (This message is created additionally to the message for a specific change, e.g. when changing the password of an administrator.) user@ipaddress has modified administrator 'user'
Administrator removed a SSO Proxy Rewriting rule user@ipaddress Removed SSO Proxy Rewriting rule <'RegularExpression','Replacement'>
Administrator restarted a proxy user@ipaddress restarted proxy successfully
Administrator selected a different TLS Key user@ipaddress selected a different TLS Key.
Administrator set the status of an administrator to Active user@ipaddress set state of administrator 'user' to ACTIVE
Administrator set the status of an administrator to Inactive user@ipaddress set state of administrator 'user' to INACTIVE
Administrator started a proxy user@ipaddress started proxy successfully
Administrator started the creation of 10000 new data encryption keys user@ipaddress started the creation of '10000' new data encryption keys to be used in random key mode.
Administrator stopped a proxy user@ipaddress stopped proxy successfully
Administrator updated the login delay settings user@ipaddress Login Delay has been successfully updated
After eperi sEcure Platform was started, a user entered a wrong RAM password in the eperi sEcure Admin Console. unknown user@ipaddress has entered wrong RAM password on start up.
Automatic import of a template imported template (id: id, version version)
End of a batch process for creating AES keys finished batch process pid
Login to eperi sEcure Platform failed null@ipaddress Login failed due to wrong password or nonexistent user
Migration Status of Default Admin Default Admin Migration Status: migrated / not migrated
Password change failed because both new passwords do not match user@ipaddress failed in changing his password due to invalid input. Both new passwords do not match.
Password change failed because the new password is not valid according to the password policy user@ipaddress failed in changing his password due to invalid input. Your password must be at least 12 characters long and must include 1 uppercase letter(s), 1 number(s).
Password change failed because the old password is incorrect user@ipaddress failed in changing his password due to invalid input. The old password is incorrect.
Start the Gateway eperi sEcure Platform is starting up
Stop the Gateway eperi sEcure Platform is shutting down
The "Detokenization Logging" was automatically stopped after 24 hours. Detokenization logging stopped after 24 hours
The "Detokenization Logging" was started because the eperi eperi sEcure Platform detected 5 tokens within 30 seconds which do not exist in the eperi sEcure Platform database. As soon as "Detokenization Logging" is started, all successful and unsuccessful detokenization processes within the next 24 hours are logged in the separate log file .../tomcat/webapps/ROOT/log/detokenization.log. Detokenization logging started
The Default Admin Password was updated to the Administrator Table Default Admin Password was updated to the Administrator Table
The Default Admin was added to the Administrator Table Default Admin was added to the Administrator Table
Table 2. Syslog messages of the Salesforce-Adapter
User/System activity Message text
Administrator approved a Change Request Configuration user@ipaddress Approved the ChangeRequest Config: changeRequest.Operation for changeRequest.DisplayName
Administrator cleared cached metadata user@ipaddress cleared cached metadata successfully.
Administrator created a new CREATE / DELETE Change Request user@ipaddress created a new CREATE / DELETE Change Request for name
Administrator created a new Salesforce field configuration user@ipaddress created a new salesforce field configuration name
Administrator created a new Salesforce field configuration which was approved by another Administrator user@ipaddress created a new salesforce field configuration and was approved by login
Administrator deleted a Change Request Configuration user@ipaddress Deleted the ChangeRequest Config: changeRequest.Operation for changeRequest.Name
Administrator deleted a Salesforce field configuration user@ipaddress Deleted the salesforce field configuration name
Administrator deleted a Salesforce field configuration which was approved by another Administrator user@ipaddress Deleted a salesforce field configuration and was approved by login
Administrator disabled Solr indexing user@ipaddress Disabled indexing.
Administrator enabled Solr indexing user@ipaddress Enabled indexing.
Administrator rejected a Change Request Configuration user@ipaddress Rejected the ChangeRequest Config: changeRequest.Operation for name
Administrator removed the Salesforce validation rules user@ipaddress removed the Salesforce validation rules.
Administrator updated the Salesforce metadata configuration user@ipaddress Updated the Salesforce metadata configuration.
Table 3. Syslog messages of the SharePoint Adapter
User/System activity Message text
Administrator activated a SharePoint field (in the SharePoint tab) user@ipaddress activated the SharePoint field: fieldName
Administrator added a SharePoint field (in the SharePoint tab) user@ipaddress added a SharePoint field: fieldName
Administrator changed in the "SharePoint Web Application" app the value of the field "Blacklist" user@ipaddress changed in the SharePoint app 'appName' the field 'Blacklist' from 'blacklistEntry1' to 'blacklistEntry2'
Administrator changed in the "SharePoint Web Application" app the value of the field "Blacklist message" user@ipaddress changed in the SharePoint app 'appName' the field 'Blacklist message' from 'blacklistMessage1' to 'blacklistMessage2'
Administrator changed in the "SharePoint Web Application" app the value of the field "Fully qualified eperi sEcure Platform hostname" user@ipaddress changed in the SharePoint app 'appName' the field 'Fully qualified Sharepoint hostname' from 'hostName1' to 'hostName2'
Administrator changed in the "SharePoint Web Application" app the value of the field "URL prefix" user@ipaddress changed in the SharePoint app 'appName' the field 'URL prefix' from 'prefix1' to 'prefix2'
Administrator deactivated a SharePoint field (in the SharePoint tab) user@ipaddress deactivated the SharePoint field: fieldName
Administrator deleted a SharePoint field (in the SharePoint tab) user@ipaddress deleted the SharePoint field: fieldName