Audit
StoneGate collects extensive information about changes in the system. The information
is stored in audit logs, the elements' history data and configuration snapshots, which provides
various ways to seek, view and generate reports about configuration changes and administrator
activity.
Audit logs
Audit logs contain information about the actions performed on the system and on
system-generated events.
By examining the audit logs it is possible to trace, for example, what kinds of administrator
actions have been performed and by whom. This data may prove to be important when trying to figure
out possible configuration errors and in other comparable events.
The audit logs can be browsed in the Log Browser. You can specify exactly what types of
actions interest you and in what time frame. This allows tracking accurately all given kinds of
system events or administrator actions and helps in maintaining the systems integrity.
The audited events include:
- Actions concerning elements configuration (creating, editing, deleting, importing or
exporting)
- Actions performed on the firewall and IPS engines (policy upload, control commands, etc.)
- Use of command line tools (e.g., backing up and restoring)
- Actions related to certificates
- Actions related to administrator login authentication
History
data
Element history data contains information about creation and last edition of an element or
a rule. This makes an easy to find changes done within some time period or by some certain
administrator.
Policy snapshots
Policy snapshots are configuration dumps from the time the configuration
is applied to security engines.
With the snapshot comparison tool, the administrator may compare the snapshot to another
snapshots from a different time, and this way review the changes that have been between the
snapshots.
Benefits
- Provides detailed accounting data, for example for external auditors
- Makes it possible to review events and determine what has happened before, during and after
some incident
- Provides a way to detect unusual and unauthorized events
- Helps to meet regulatory compliance