Reference of syslog messages for audit logging
eperi sEcure Platform generates syslog messages for certain user actions. You can use these messages for the audit logging of your company.
The prerequisite is that syslog messaging is configured and activated in eperi sEcure Platform. How to do this is explained in section Syslog Integration settings.
In the following, all syslog messages are listed that are generated for corresponding user actions.
| User/System activity | Message text |
|---|---|
| Administrator activated/deactivated the Change Request status for a certain category (e.g. "Salesforce") | user@ipaddress Activated/Deactivated ChangeRequest status for changeRequestStatus.Category |
| Administrator activated a syslog configuration entry | user@ipaddress enabled syslog configuration: configName |
| Administrator activated TLS for proxy | user@ipaddress activated TLS for proxy proxyName |
| Administrator added a new SSO Rewriting Rule | user@ipaddress New SSO Rewriting Rule <'regularExpression','Replacement'> added |
| Administrator added or removed permission(s) to a role | user@ipaddress changed the permission assignments for role 'role-name' |
| Administrator assigned or unassigned Admin Role(s) to an Active Directory Group | user@ipaddress changed the Role assignments for AD Group 'distinguishedName' |
| Administrator changed advanced proxy settings | user@ipaddress changed advanced proxy settings. key = value |
| Administrator changed assignment of apps to proxy | user@ipaddress
changed assignment of apps to
proxy. user@ipaddress Added: appName1, Deleted: appName2 |
| Administrator changed his password | user@ipaddress changed his password |
| Administrator changed his password. The new password contains more than 11 digits. | Check for permutations of blacklisted entries is skipped, since the password entered contains more than 11 digits. |
| Administrator changed Key Rotation settings to "Choose a random key per encryption" | user@ipaddress set key rotation mode to RANDOM. |
| Administrator changed Key Rotation settings to "Generate a new key per encryption" | user@ipaddress set key rotation mode to UNIQUE. |
| Administrator changed Key Rotation settings to a key available in the Keys tab | user@ipaddress set key rotation mode to FIXED with keyID 'keyID'. |
| Administrator changed password settings | user@ipaddress Password settings changed successfully. |
| Administrator changed the authentication method of an app | user@ipaddress changed the authentication method of app appName to authenticationMethod |
| Administrator changed the description of an Active Directory Group | user@ipaddress has modified Active Directory Group 'distinguishedName' |
| Administrator changed the description of a role | user@ipaddress has modified role 'role-name' |
| Administrator changed the password of an administrator | user@ipaddress changed the password of administrator 'user' |
| Administrator changed the password of a user | user@ipaddress changed the password of the user 'username' |
| Administrator changed the port for a proxy | user@ipaddress changed port for proxy proxyName to nnnn |
| Administrator changed the Role assignments for an administrator | user@ipaddress changed the Role assignments for administrator 'login' |
| Administrator completed the creation of 10000 new data encryption keys | user@ipaddress completed the creation of '10000' new data encryption keys to be used in random key mode. |
| Administrator created an AES key | user@ipaddress created AES key name |
| Administrator created an AES key for HSM | user@ipaddress created AES key name (HSM) |
| Administrator created a new administrator | user@ipaddress has created new administrator 'user' |
| Administrator created a new app | user@ipaddress New App (appName) was successfully created |
| Administrator created a new reverse or forward proxy | user@ipaddress New reverseproxy/forwardproxy (proxyName) was successfully created |
| Administrator created a new role | user@ipaddress has created new role 'role-name' |
| Administrator created a new Token Profile | Tokenprofile (Name of Token Profile) was successfully created |
| Administrator created a new user (in the Authentication tab of the eperi sEcure Admin Console) | user@ipaddress New user was succesfully created. |
| Administrator created or changed the configuration of the Token Database | user@ipaddress Successfully created/changed the Token Database configuration. |
| Administrator created or imported an Active Directory Group Mapping | user@ipaddress has created new Active Directory Group 'distinguishedName' |
| Administrator deactivated TLS for proxy | user@ipaddress deactivated TLS for proxy proxyName |
| Administrator deleted a key | user@ipaddress deleted the key 'keyname' with key id 'keyID' and algorithm 'algorithm' |
| Administrator deleted all AdGroups | user@ipaddress deleted all AdGroups |
| Administrator deleted an Active Directory Group | user@ipaddress deleted the AdGroup 'distinguishedName' |
| Administrator deleted an administrator | user@ipaddress deleted the administrator 'user' |
| Administrator deleted an app | user@ipaddress deleted the app 'appName' successfully. |
| Administrator deleted an app template | All versions of the template "templateID" have been successfully deleted |
| Administrator deleted a proxy | user@ipaddress proxyType (proxyName) was successfully deleted. |
| Administrator deleted a role (in the Administrators tab) | user@ipaddress deleted the role 'role-name' |
| Administrator deleted a sylog configuration entry | user@ipaddress deleted syslog configuration: configName |
| Administrator deleted a Token Profile | Token profile "Name of Token Profile" has been successfully deleted |
| Administrator deleted a user | user@ipaddress deleted the user 'username' |
| Administrator disabled a syslog configuration entry | user@ipaddress disabled syslog configuration: configName |
| Administrator edited a sylog configuration entry | user@ipaddress changed syslog configuration oldConfigName to configName |
| Administrator exported an app template | user@ipaddress Template templateName was successfully exported |
| Administrator exported the eperi sEcure Platform Relying Party Trust Metadata | user@ipaddress exported the eperi sEcure Platform Relying Party Trust Metadata |
| Administrator exported the eperi sEcure Platform SSO ID Provider Metadata | user@ipaddress exported the eperi sEcure Platform SSO ID Provider Metadata |
| Administrator exported the Security Configuration (This message is only available up to Release 3.18.13.) | user@ipaddress exported the security configuration |
| Administrator generated new SSO Encryption and Signature validation certificates | user@ipaddress Generated new SSO Encryption and Signature validation certificates |
| Administrator generated several AES keys via batch process | user@ipaddress started batch process pid for creating AES keys with prefix prefix, start - end |
| Administrator imported a certificate into the Trusted Store | user@ipaddress imported a trusted certificate (thumbprint) |
| Administrator imported a new SSO ID Provider configuration | user@ipaddress New SSO ID Provider configuration imported. |
| Administrator imported a PKCS#12 container | user@ipaddress imported a key pair, name name[,warnings] |
| Administrator imported a template | user@ipaddress imported template (id: id, version version) |
| Administrator imported new Relying Party Trust Metadata | user@ipaddress New Relying Party Trust Metadata imported |
| Administrator imported the security configuration (from a release <= 3.18.13) | user@ipaddress imported the security configuration |
| Administrator logged in to the eperi sEcure Admin Console | user@ipaddress has logged in successfully. |
| Administrator logged out of the eperi sEcure Admin Console | user@ipaddress has logged out. |
| Administrator modified an Active Directory Group Mapping | user@ipaddress has modified new Active Directory Group 'distinguishedName' |
| Administrator modified a role | user@ipaddress has modified role 'roleName' |
| Administrator modified some details of an administrator (This message is created additionally to the message for a specific change, e.g. when changing the password of an administrator.) | user@ipaddress has modified administrator 'user' |
| Administrator removed a SSO Proxy Rewriting rule | user@ipaddress Removed SSO Proxy Rewriting rule <'RegularExpression','Replacement'> |
| Administrator restarted a proxy | user@ipaddress restarted proxy successfully |
| Administrator selected a different TLS Key | user@ipaddress selected a different TLS Key. |
| Administrator set the status of an administrator to Active | user@ipaddress set state of administrator 'user' to ACTIVE |
| Administrator set the status of an administrator to Inactive | user@ipaddress set state of administrator 'user' to INACTIVE |
| Administrator started a proxy | user@ipaddress started proxy successfully |
| Administrator started the creation of 10000 new data encryption keys | user@ipaddress started the creation of '10000' new data encryption keys to be used in random key mode. |
| Administrator stopped a proxy | user@ipaddress stopped proxy successfully |
| Administrator updated the login delay settings | user@ipaddress Login Delay has been successfully updated |
| After eperi sEcure Platform was started, a user entered a wrong RAM password in the eperi sEcure Admin Console. | unknown user@ipaddress has entered wrong RAM password on start up. |
| Automatic import of a template | imported template (id: id, version version) |
| End of a batch process for creating AES keys | finished batch process pid |
| Login to eperi sEcure Platform failed | null@ipaddress Login failed due to wrong password or nonexistent user |
| Migration Status of Default Admin | Default Admin Migration Status: migrated / not migrated |
| Password change failed because both new passwords do not match | user@ipaddress failed in changing his password due to invalid input. Both new passwords do not match. |
| Password change failed because the new password is not valid according to the password policy | user@ipaddress failed in changing his password due to invalid input. Your password must be at least 12 characters long and must include 1 uppercase letter(s), 1 number(s). |
| Password change failed because the old password is incorrect | user@ipaddress failed in changing his password due to invalid input. The old password is incorrect. |
| Start the Gateway | eperi sEcure Platform is starting up |
| Stop the Gateway | eperi sEcure Platform is shutting down |
| The "Detokenization Logging" was automatically stopped after 24 hours. | Detokenization logging stopped after 24 hours |
| The "Detokenization Logging" was started because the eperi eperi sEcure Platform detected 5 tokens within 30 seconds which do not exist in the eperi sEcure Platform database. As soon as "Detokenization Logging" is started, all successful and unsuccessful detokenization processes within the next 24 hours are logged in the separate log file .../tomcat/webapps/ROOT/log/detokenization.log. | Detokenization logging started |
| The Default Admin Password was updated to the Administrator Table | Default Admin Password was updated to the Administrator Table |
| The Default Admin was added to the Administrator Table | Default Admin was added to the Administrator Table |
| User/System activity | Message text |
|---|---|
| Administrator approved a Change Request Configuration | user@ipaddress Approved the ChangeRequest Config: changeRequest.Operation for changeRequest.DisplayName |
| Administrator cleared cached metadata | user@ipaddress cleared cached metadata successfully. |
| Administrator created a new CREATE / DELETE Change Request | user@ipaddress created a new CREATE / DELETE Change Request for name |
| Administrator created a new Salesforce field configuration | user@ipaddress created a new salesforce field configuration name |
| Administrator created a new Salesforce field configuration which was approved by another Administrator | user@ipaddress created a new salesforce field configuration and was approved by login |
| Administrator deleted a Change Request Configuration | user@ipaddress Deleted the ChangeRequest Config: changeRequest.Operation for changeRequest.Name |
| Administrator deleted a Salesforce field configuration | user@ipaddress Deleted the salesforce field configuration name |
| Administrator deleted a Salesforce field configuration which was approved by another Administrator | user@ipaddress Deleted a salesforce field configuration and was approved by login |
| Administrator disabled Solr indexing | user@ipaddress Disabled indexing. |
| Administrator enabled Solr indexing | user@ipaddress Enabled indexing. |
| Administrator rejected a Change Request Configuration | user@ipaddress Rejected the ChangeRequest Config: changeRequest.Operation for name |
| Administrator removed the Salesforce validation rules | user@ipaddress removed the Salesforce validation rules. |
| Administrator updated the Salesforce metadata configuration | user@ipaddress Updated the Salesforce metadata configuration. |
| User/System activity | Message text |
|---|---|
| Administrator activated a SharePoint field (in the SharePoint tab) | user@ipaddress activated the SharePoint field: fieldName |
| Administrator added a SharePoint field (in the SharePoint tab) | user@ipaddress added a SharePoint field: fieldName |
| Administrator changed in the "SharePoint Web Application" app the value of the field "Blacklist" | user@ipaddress changed in the SharePoint app 'appName' the field 'Blacklist' from 'blacklistEntry1' to 'blacklistEntry2' |
| Administrator changed in the "SharePoint Web Application" app the value of the field "Blacklist message" | user@ipaddress changed in the SharePoint app 'appName' the field 'Blacklist message' from 'blacklistMessage1' to 'blacklistMessage2' |
| Administrator changed in the "SharePoint Web Application" app the value of the field "Fully qualified eperi sEcure Platform hostname" | user@ipaddress changed in the SharePoint app 'appName' the field 'Fully qualified Sharepoint hostname' from 'hostName1' to 'hostName2' |
| Administrator changed in the "SharePoint Web Application" app the value of the field "URL prefix" | user@ipaddress changed in the SharePoint app 'appName' the field 'URL prefix' from 'prefix1' to 'prefix2' |
| Administrator deactivated a SharePoint field (in the SharePoint tab) | user@ipaddress deactivated the SharePoint field: fieldName |
| Administrator deleted a SharePoint field (in the SharePoint tab) | user@ipaddress deleted the SharePoint field: fieldName |
