24-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 24 System Maintenance
Viewing the Audit Trail
Viewing the Audit Trail
You can track the activities of the appliance’s users by analyzing the appliance’s log files. To set the
appliance’s audit trail logs, navigate to
Admin
>
System Maintenance
>
View Audit Trail
. For typical
use, it is best to leave this page set to its defaults.
You can view the user audit trails either by selecting a number of days, hours, and minutes, or you can
view a specific interval by selecting a start and ending date and time.
View an Audit Trail
Step 1
Click the appropriate radio button:
•
Last: DD-HH-MM
•
Start/End: YY-MM-DD-HH-MM
Step 2
From the list, select the user or user group.
Step 3
Click
Submit
.
Retrieving Raw Messages
You can retrieve raw messages from either an archive server (see
Configuring and Performing Appliance
Data Backups, page 6-24
) or from thedatabase running on the Local Controller. These two method offer
different advantages:
•
Archive server.
Retrieving raw messages, or event data, from an archive server is much faster than
retrieving from the database. Therefore, it is the recommended option if it is available and it covers
the time period you are investigating. However, this option is only available if you have enabled
data archiving and waited the requisite time for the initial archival operation to occur; it is a
scheduled operation that runs nightly around 2:00 a.m. Once the initial archive is performed, the
event data is written to the archive server frequently, often within 5 to 8 minutes after the MARS
Appliance receives the message. That data is not archived in real-time identifies another limitation
to this option, and that is the historical period that can be studied. If you need to view data that is
more current than an hour old, you should select the Database option to ensure that correct data is
retrieved. For all other periods, the archive server option is recommended. To enable archiving, see
Configuring and Performing Appliance Data Backups, page 6-24
.
•
Database
. Retrieving event data from the local files provides slower performance than the archive
server. However, it provides access to the most current data received. When you select this option,
you can specify where you want the retrieved records to be written: in the default local directory or
the a remote server, if one is available.
This section contains the following topics:
•
Retrieve Raw Messages From Archive Server, page 24-4
•
Retrieve Raw Messages From a Local Controller, page 24-5