Configuring Logs in the Console
81
NOTE
The Certificate System does not provide any tool or utility for archiving log files.
The Certificate System provides a command-line utility,
signtool
, that signs log files before archiving
them as a means of tamper detection. For details, see
Section 3.9.10, “Signing Log Files”
.
Signing log files is an alternative to the signed audit logs feature. Signed audit logs creates audit logs
that are automatically signed; using
signtool
manually signs archived logs. See
Section 3.9.1.6,
“Signed Audit Log”
for details about signed audit logs.
By default, rotated log files are not deleted.
3.9.6. Configuring Logs in the Console
This procedure describes how to configure system, transaction, and audit logs.
To configure logs for a Certificate System instance:
1. Open the Console.
2. In the navigation tree of the
Configuration
tab, select
Log
.
The
Log Event Listener Management
tab lists the currently configured listeners.
3. To create a new log instance, click
Add
, and select a module plug-in from the list in the
Select
Log Event Listener Plug-in Implementation
window.
To delete a log instance, select a listener to delete in the
Log Event Listener
list. Click
Delete
.
To modify an existing log instance, select a listener to modify in the
Log Event Listener
list. Click
Edit/View
.
4. Change the fields in the
Log Event Listener Editor
window.
•
Log Event Listener ID
. The unique name that identifies the listener. The names can have
any combination of letters (aA to zZ), digits (0 to 9), an underscore (_), and a hyphen (-), but it
cannot contain other characters or spaces.
•
type
. The type of log file. Set
transaction
to create a listener that records audit logs. For error
and system logs, select
system
.
•
enabled
. Select to enable; deselect to disable. Only enabled logs actually record events.
•
level
. Sets the log level. The choices are
Debug
,
Information
,
Warning
,
Failure
,
Misconfiguration
,
Catastrophe
, and
Security
. The level field does not have a drop-down
list. It is a simple text field that needs to be filled in with one of the above categories. For more
information, see
Section 3.9.3, “Log Levels (Message Categories)”
.
•
fileName
. The full path, including the filename, to the file to write messages. The server should
have read/write permission to the file.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...