|
Auditing Failed User Logons
An audit log can be best described as a simple log of changes, typically used for tracking temporal information. The eG manager can now be configured to create and maintain audit logs in the eG database, so that all key configuration changes to the eG Enterprise system, which have been effected via the eG user interface, are tracked.
The eG audit logs reveal critical change details such as what has changed, who did the change, and when the change occurred, so that administrators are able to quickly and accurately identify unauthorized accesses/modifications to the eG Enterprise system.
By default, audit logging is disabled. To enable the capability, follow the steps given below:
Login to the eG administrative interface.
Click on the icon available in the Admin tab. Then, select the Manager option in the Settings tile. Now select the Auditing option from the MANAGER SETTINGS tree.
In the Auditing section of the page, set the Enable auditing flag to Yes.
Then, set the Include activities from admin command line interface flag to Yes if you want to maintain log for activities performed via the admin command line interface.
Click the Update button to save the changes.
Subsequent to this, every configuration change that the user makes will be automatically logged in the database. To view the details logged and analyze their implications, eG Enterprise provides an exclusive Audits menu in its administrative interface, using which you can generate a variety of AUDIT LOG REPORTS.
To view the details of user logons to the eG Enterprise system that failed, use the FAILED LOGON reports. Using such a report, you can figure out which were the login attempts that failed and why. The reasons can bring to light network connection issues that need to be repaired, or login attempts that are rather ‘suspect’.
To access this page, click on the icon available in the Admin tab. Then, select the Failed Logons option in the Audits tile.
To generate a report on failed logons using the FAILED LOGON REPORT page, do the following:
Select a Timeline for the report. The default Timeline for the report is 24 hours. You can choose any other fixed period from the Timeline list, or select the Any option from this list. Choosing the Any timeline, allows you to provide a Start Date and End Date and time for report generation. If you change the Timeline settings, then make sure that you click the button at its end, to register the changes.
Next, select the User whose login attempts you want to audit. By default, the All option is displayed here, indicating that the report provides the details of failed login attempts of all users to the eG Enterprise system. However, if only one user had had problems logging in till date, then, by default, that user's name is displayed in the User list.
Administrators can configure the target environment for monitoring by directly logging into the eG administrative interface or by using the admin command line interface provided by the eG manager. This is why, by default, the audit log not only captures user logins via the web-based eG management console, but also those logins that are performed via the eG Admin Command Line Interface.
While generating audit log reports, you have the option of viewing the details of failed logins across both these interfaces, or only those that pertain to a particular interface. To indicate your choice, use the Interface drop-down list in this page. The options available in the Interface list are as follows:
Web: Select this option to view the details of login failures that occurred when attempting to login via the web-based eG management console;
Command Line: Select this option to view the details of login failures that occurred when attempting to login via the admin command line interface;
All: Select this option to view the details of all login failures, regardless of interface used to login.
If required, you can choose not to maintain audit logs for activities performed via the admin command line interface by setting the Include activities from the admin command line interface flag in the AUDITLOG section of the MANAGER SETTINGS page to No. In this case therefore, the Interface drop-down list will not appear in this page.
Finally, click the Show button to generate the report.
- The resulting report provides details of every login made by the chosen user(s) that failed. These details include:
the name of the user
the IP address of the host from which the user attempted to login to the eG management console
the exact time of login attempt
the reason for the login failure
Note:
In a redundant setup, the auditlog report will have an additional MANAGER NAME column, which displays the IP or host name of the manager to which a record pertains.
If the report runs across pages, then the hyperlinked page numbers and the First Page, Next Page, Previous Page, and Last Page links at the bottom of the page will aid navigation.
You can print the report by clicking on the icon in this page, or save the report as a PDF file by clicking on the icon. You can even save the report as a CSV file by clicking on the icon here. To schedule the printing/mailing of the audit logon report, click on the icon.
|