1.8 Tracking Changes to Sensitive Information

1.8.1 Using iManager to Log Events

You can use Audit to log events that you consider important for security.

For example, you could log password changes for a particular Identity Manager driver (or driver set) by doing the following:

  1. In iManager, select eDirectory Administration > Modify Object > Log Level.

    The Log Level option

    Select from the drop-down list or select a tab, depending on your version of iManager.

  2. Select Log Specific Events.

    Log Level page
  3. To select the specific events, click the Log Events icon log events icon.

  4. Enable the Turn off logging to Driver Set, Subscriber and Publisher logs option to prevent logging Identity Manager events to eDirectory.

    Enabling this option improves the performance of the Identity Manager system.

  5. On the Events page, select the following:

    Checkboxes to select on Events page
    • In Operation Events, select Change Password.

      This item monitors direct changes to the NDS password.

    • In Transformation Events, select Password Set and Password Sync. These two items monitor events for the Universal Password and Distribution Password.

  6. Click OK twice.

1.8.2 Using Designer to Log Events

You can log events that apply to a driver set or to a driver.

Logging Events for a Driver Set

  1. In Designer, right-click a driver set, then select Properties.

    Properties of the driver set
  2. Select Driver Set Log Level, then select Log Specific Events.

    Setting the driver set log level
  3. Click the Select Events to Log icon.

    Select Events to Log icon
  4. Enable the Turn off logging to Driver Set, Subscriber and Publisher logs option to prevent logging Identity Manager events to eDirectory.

    Enabling this option improves the performance of the Identity Manager system.

  5. Select events to log, then click OK.

    List of the events to log

Logging Events for a Driver

  1. In Designer, right-click a driver, then select Properties.

  2. Select Driver Log Level, then select Log Specific Events.

    Setting the driver log level
  3. If you prefer, you can accept the settings for the driver set, then click OK.

    or

    Deselect Use log settings from the Driver Set, select Log specific events, then click OK.

  4. Click the Select Events to Log icon.

    Select Events to Log icon
  5. Select events to log, then click OK.

    Events to log