Auditing
The Auditing screen allows you to filter and query auditing data within Passwordstate, which can be many different types of activities that occur when using the software. This page contains all auditing data in the system, and should be used by Security Administrators to track down issues or gather information for any event that has occurred within Passwordstate.
All auditing data is stored permanently in Passwordstate unless deliberately purged. To maintain high performance of Passwordstate, older data is automatically archived and typically not used unless you purposely search for this archived data on this screen.
Filtering can be done by:
- Platform - Events generated through the website, the Mobile App, the API, Windows Service or Browser Extension
- Instance - If you are licensed for the High Availability (HA) module, you can toggle between the Primary and the HA website with this option
- Archived Data - By default, you will be searching for all live auditing data in the system, but you can toggle this option to search through archived data
- Password List - Filter on events specific to a selected Password List, or multiple Password Lists at once. Or leave blank to look for any unrelated Password List related data.
- Activity Type - Not all audit events relate to passwords i.e. there's audit events for sending emails, failed authentication attempts, etc. Passwordstate has over 150 different types of activities to filter on
- Site Location Activity - All standard activity in Passwordstate is referred to as "Internal" and this should be the default setting when looking in auditing data. If you have purchased the Remote Site Locations Module, you will have more sites to choose from in this drop down list.
- Select Time Range - Click in this field to choose a date range from a pop up calendar
In addition to reporting on auditing data on the screen, you can export the data for further analysis to a CSV file if required.
Auditing data is generally the main feature which can make a database grow in size, and if needed there is a Purge Audit Records button on this page you can use to learn how to clean up excessive auditing data.
Note: The Telerik Grid and Filter controls here prevent filtering while using special characters - for security reasons. If you're wanting to filter using a backslash
(\)here, simply type the backslash twice i.e.domain\\userid.