Audit Classifications
The following tables provide Audit classification information. This table lists descriptions and examples.
Classification | Description | Examples Of |
---|---|---|
Startup and Shutdown | Logs reporting on activity pertaining to the starting and stopping of a system, device, application, or other relevant object. |
|
Configuration | Logs reporting on activity pertaining to the state or configuration of a system where not related to a Policy. |
|
Policy | Logs reporting on activity pertaining to the policy of a network, system, device, or other relevant object. Includes configuration changes related to a Policy |
|
Account Created | Logs reporting on activity related to user or system/computer account creation. |
|
Account Modified | Logs reporting on the modification of a user or group outside granting/revoking access. No group level or access level changes. |
|
Account Deleted | Logs reporting on activity related to user or system/computer account deletion. |
|
Access Granted | Logs reporting on activity related to granting of access rights and privileges. |
|
Access Revoked | Logs reporting on activity related to revocation of access rights and privileges. |
|
Authentication Success | Logs reporting success user and system authentication activity. User or system gaining access through any method of authentication. |
|
Authentication Failure | Logs reporting failed user and system authentication activity. Due to bad credentials or unauthorized attempt (user not allowed to log in) |
|
Access Success | Logs reporting successful read, write, or execute access on files, programs, and other relevant objects. |
|
Access | Logs reporting failed read, write, or execute access on files, programs, and other relevant objects. Client Applications, Desktop Applications, Scripts |
|
Other Audit Success | Logs reporting on successful audited activity not otherwise classifiable. |
|
Other Audit Failure | Logs reporting on failed audited activity not otherwise classifiable. |
|
Other Audit | Logs reporting on audited activity not otherwise classifiable. |
|
Audit Classification Defaults
This table gives Audit Classification defaults for Risk Rating (RR), Event Forwarding, and LogMart Forwarding.
Classification | Default Risk Rating * | Default Event Forwarding ** | Default LogMart Forwarding |
---|---|---|---|
Startup and Shutdown | 0 / 3 (Critical Service) | If RR > 0 | If RR > 0 |
Configuration | 2 | Yes | Yes |
Policy | 2 | Yes | Yes |
Account Created | 3 | Yes | Yes |
Account Modified | 1 | Yes | Yes |
Account Deleted | 0 | Yes | Yes |
Access Granted | 3 / 5 if admin privilege granted | Yes | Yes |
Access Revoked | 0 | No | Yes |
Authentication Success | 0 / 1 if privileged user | If RR > 0 | Yes |
Authentication Failure | 0 | Yes | Yes |
Access Success | 0 | No | Yes |
Access Failure | 1 | Yes | Yes |
Other Audit Success | 0 | No | No |
Other Audit Failure | 1 | Yes | Yes |
Other Audit | 0 | No | No |
* This is the usual Risk Rating assigned to a Common Event associated with this classification. However, Risk Ratings varies by Common Event within the same classification. This value is a general default, not strictly enforced.
** This is the default setting for forwarding the log to the Platform Manager assigned to a Common Event associated with this classification.