Enabling the administration server audit log and modifying administration audit log settings

This feature enables the administration server audit log and modify its settings.

Audit logging is used to improve the security of the directory server. The directory administrator and administrative group members who are assigned AuditAdmin or ServerConfigGroupMember role can use the records stored in the audit log to check for suspicious patterns of activity in an attempt to detect security violations. If security is violated, the administration server audit log (adminaudit.log is the default file name) can be used to determine how and when the problem occurred and perhaps the amount of damage done.

Note:
  • The Primary directory administrator and administrative group members with Audit administrator and Server configuration group member roles are the only users who can access the administration server audit log settings.
  • Failed connection attempts are audited only if they fail after reaching the LDAP server. Connections that fail in the SSL layer, network, or operating system layer are not audited.

To modify the administration audit log settings, use one of the following methods. Remember that individual log settings override the Default log settings.

Note: The administration server audit log audits binds, unbinds, searches, and extended operations.