Auditing Administrator Changes to the ARM Database

(Requires ARM) Administrators often need to know when and what changes were made to EFT and who made them. The administrator Actions Log report provides information about administrator changes. When ARM expires, administrator changes are no longer audited.

EFT logs to the ARM database the following changes made to EFT:

  • The Date the action occurred, in MM/DD/YYYY HH:MM:SS format.

  • The affected feature or Function. (Refer to Functions Audited below.)

  • The type of Action (created, added, removed, modified, enabled, disabled, started, and stopped).

  • The Affected Area (Server, Site, Settings Template, User Account, Event Rule, Command, Group, VFS, Report).

  • The name of the affected object, Affected Name (Server Name, Site Name, Settings Template Name, User or administrator Account Name, Event Rule Name, Command Name, Group Name, Folder Name, Report Name).

  • The name of the administrator that made the change, Change Originator.

The data in the preconfigured report is arranged in columns, Date, Function, Action, Affected Area, Affected Name, and Change Originator, grouped by Site name, and sorted in reverse chronological order (newest change at the top).

Functions Audited

When the following functions are created, added, removed, modified, enabled, disabled, started, or stopped, the action is logged to the database. Many possible actions are grouped together. For example, modifying SSL cipher selection, changing SSL clear command channel values, or modifying SSL connection string all fall under "SSL settings." Also, intermediate states are not audited (for example, a toggle was checked, but later unchecked, rendering the transaction moot). Instead, only committed states are captured (once the administrator applies changes).

  • Administrator

  • Account details

  • Account expiration settings

  • AS2 protocol

  • AS2 settings

  • Auditing settings

  • Authentication settings

  • AWE Task

  • Ban On Invalid Login Settings

  • Connection limits

  • Custom command

  • Data sanitization (wiping)

  • Database refresh

  • Default Configuration File Path

  • Default User Database Refresh Interval

  • Delegated administrators

  • Disk limits

  • DoS prevention settings

  • Event Rule

  • File type limits

  • FIPS mode for SSH

  • Folder permissions

  • FTP Implicit Protocol

  • FTP Explicit Protocol

  • FTP protocol

  • FTP settings

  • Group assignment

  • Group (Permission)

  • HTTPS protocol

  • HTTPS settings

  • HTTP protocol

  • Invalid login settings

  • Inactive account settings

  • IP address ban list

  • Log settings

  • OpenPGP settings

  • OpenPGP key

  • Password

  • Password complexity

  • Password reset

  • Password expiration

  • Password History

  • Password initial reset

  • PASV port mode settings

  • Physical folder

  • Real-time monitoring

  • Remote administration

  • Server

  • Server service settings

  • Show Time In UTC/GMT

  • Settings Template

  • Site

  • Site listening IP

  • Site root folder

  • SMTP settings

  • Transfer limits

  • User Account

  • User kicked

  • Virtual folder

  • Web Services Interface

  • Web Transfer Client