Audit Classifications
The following tables provide Audit classification information. This table lists descriptions and examples.
| Classification | Description | Examples Of |
|---|---|---|
Startup and Shutdown | Logs reporting on activity pertaining to the starting and stopping of a system, device, application, or other relevant object. |
|
Configuration | Logs reporting on activity pertaining to the state or configuration of a system where not related to a Policy. |
|
Policy | Logs reporting on activity pertaining to the policy of a network, system, device, or other relevant object. Includes configuration changes related to a Policy |
|
| Account Created | Logs reporting on activity related to user or system/computer account creation. |
|
| Account Modified | Logs reporting on the modification of a user or group outside granting/revoking access. No group level or access level changes. |
|
| Account Deleted | Logs reporting on activity related to user or system/computer account deletion. |
|
Access Granted | Logs reporting on activity related to granting of access rights and privileges. |
|
Access Revoked | Logs reporting on activity related to revocation of access rights and privileges. |
|
Authentication Success | Logs reporting success user and system authentication activity. User or system gaining access through any method of authentication. |
|
Authentication Failure | Logs reporting failed user and system authentication activity. Due to bad credentials or unauthorized attempt (user not allowed to log in) |
|
Access Success | Logs reporting successful read, write, or execute access on files, programs, and other relevant objects. |
|
Access | Logs reporting failed read, write, or execute access on files, programs, and other relevant objects. Client Applications, Desktop Applications, Scripts |
|
Other Audit Success | Logs reporting on successful audited activity not otherwise classifiable. |
|
Other Audit Failure | Logs reporting on failed audited activity not otherwise classifiable. |
|
Other Audit | Logs reporting on audited activity not otherwise classifiable. |
|
Audit Classification Defaults
This table gives Audit Classification defaults for Risk Rating (RR), Event Forwarding, and LogMart Forwarding.
| Classification | Default Risk Rating * | Default Event Forwarding ** | Default LogMart Forwarding |
|---|---|---|---|
| Startup and Shutdown | 0 / 3 (Critical Service) | If RR > 0 | If RR > 0 |
| Configuration | 2 | Yes | Yes |
| Policy | 2 | Yes | Yes |
| Account Created | 3 | Yes | Yes |
| Account Modified | 1 | Yes | Yes |
| Account Deleted | 0 | Yes | Yes |
| Access Granted | 3 / 5 if admin privilege granted | Yes | Yes |
| Access Revoked | 0 | No | Yes |
| Authentication Success | 0 / 1 if privileged user | If RR > 0 | Yes |
| Authentication Failure | 0 | Yes | Yes |
| Access Success | 0 | No | Yes |
| Access Failure | 1 | Yes | Yes |
| Other Audit Success | 0 | No | No |
| Other Audit Failure | 1 | Yes | Yes |
| Other Audit | 0 | No | No |
* This is the usual Risk Rating assigned to a Common Event associated with this classification. However, Risk Ratings varies by Common Event within the same classification. This value is a general default, not strictly enforced.
** This is the default setting for forwarding the log to the Platform Manager assigned to a Common Event associated with this classification.