Auditing Administrator Changes to the ARM Database

Administrators often need to know when and what changes were made to EFT Server and who made them. EFT Server includes a mechanism for auditing and reporting administrator changes and includes the Administrator Actions Log report.

Using ARM and the High Security Module (HSM), EFT Server logs the following changes made to EFT Server to the ARM database (if ARM and HSM are enabled and activated):

The data in the preconfigured report is arranged in columns, Date, Function, Action, Affected Area, Affected Name, and Change Originator, grouped by Site name, and sorted in reverse chronological order (newest change at the top).

illust_administratoractionlog.gif

Functions Audited

When the following functions are created, added, removed, modified, enabled, disabled, started, or stopped, the action is logged to the database. Many possible actions are grouped together. For example, modifying SSL cipher selection, changing SSL clear command channel values, or modifying SSL connection string all fall under "SSL settings." Also, intermediate states are not audited (e.g., a toggle was checked, but later unchecked, rendering the transaction moot). Instead, only committed states are captured (once the administrator applies changes).

  • SFTP protocol

  • SFTP settings

  • SFTP key

  • SFTP authentication settings

  • SSL protocol

  • SSL settings

  • SSL require client certificate

  • SSL certificate

  • SSL authentication settings

  • FIPS mode

  • HTTPS protocol

  • HTTPS settings

  • Web Transfer Client

  • AS2 protocol

  • AS2 settings

  • FTP protocol

  • FTP protocol settings

  • PASV port mode settings

  • Password

  • Password complexity

  • Password reset

 

  • Password expiration

  • Invalid login settings

  • Inactive account settings

  • Account expiration settings

  • Connection limits

  • Transfer limits

  • Disk limits

  • File type limits

  • IP address ban list

  • Group assignment

  • Group

  • Data sanitization (wiping)

  • Streaming repository encryption (EFS)

  • OpenPGP settings

  • Open PGP key

  • DMZ Gateway

  • DMZ Gateway settings

  • Authentication settings

  • Remote administration

  • Auditing settings

  • Log settings

 

  • SMTP settings

  • DoS prevention settings

  • Delegated Administrators

  • Server

  • Site

  • Settings Template

  • User Account

  • Real-time monitoring

  • User kicked

  • Web Services Interface

  • Site root folder

  • Site listening IP

  • Custom command

  • Event Rule

  • Physical folder

  • Virtual folder

  • Folder permissions

  • Administrator

  • Database refresh

  • Server service settings