Generate XDAS Event

Sends an Identity Manager XDAS event to NetIQ Audit service.

Fields

XDAS Event Name

Identity Manager supports the following XDAS events:

Create Account, Delete Account, Disable Account, Enable Account | Query Account, Modify Account, Modify Security Token, Create Session, Terminate Session, Query Session, Modify Session, Create Data Item, Delete Data Item, Query Data Item Attribute, Modify Data Item Attribute, Install Service, Remove Service, Query Service Config, Modify Service Config, Disable Service, Enable Service, Invoke Service, Terminate Service, Query Process Context, Modify Process Context, Create Peer Association, Terminate Peer Association, Query Association Context, Modify Association Context, Receive Data Via Association, Send Data Via Association, Create Data Item Association, Terminate Data Item Association, Query Data Item Association, Modify Data Item Association, Query Data Item Content, Modify Data Item Content, Request Workflow Approval, Receive Workflow Approval, Escalate Workflow Approval, Send Workflow Notification, Create Role, Delete Role, Disable Role, Enable Role, Query Role, Modify Role, Start System, Shutdown System, Resource Exhaustion, Resource Corruption, Backup Datastore, Restore Datastore, Configure Audit Service, Audit Datastore Full, Audit Datastore Corrupt, Authentication Session, Unauthentication Session, Federate Identity, Unfederate Identity, Create Access Token, Destroy Access Token

Level

Level of the event.

Valid event levels are defined in the following table:

Level

Description

log-emergency

Events that cause the Identity Manager engine or driver to shut down.

log-alert

Events that require immediate attention.

log-critical

Events that can cause parts of the Identity Manager engine or driver to malfunction.

log-error

Events describing errors that can be handled by the Identity Manager engine or driver.

log-warning

Negative events that do not represent a problem.

log-notice

Events (positive or negative) that an administrator can use to understand or improve use and operation.

log-info

Positive events of any importance.

log-debug

Events of relevance (for support or engineers) to debug the Identity Manager engine or driver operations.

Strings

Specify user-defined string, integer, and binary values to include with the event. You can enter the strings manually, or select the Edit the Strings icon Edit the Strings icon to open the Named String Builder and specify the strings. For more information about the Named String Builder, see Section 4.9, Named String Builder. For this action to complete successfully, it is mandatory that you specify at least one string in the action.

The Generate XDAS Event action supports the following strings:

String Name

Description

Observer.Account.Domain

Identity Manager stores this value in the Observer.Account.Domain field in the XDAS event.

Observer.Account.Name

Identity Manager stores this value in the Observer.Account.Name field in the XDAS event.

Observer.Account.Id

Identity Manager stores this value in the Observer.Account.Id field in the XDAS event.

Observer.Entity.SysAddr

Identity Manager stores this value in the Observer.Entity.SysAddr field in the XDAS event.

Observer.Entity.SysName

Identity Manager stores this value in the Observer.Entity.SysName field in the XDAS event.

Observer.Entity.SvcName

Identity Manager stores this value in the Observer.Entity.SvcName field in the XDAS event.

Observer.Entity.SvcComp

Identity Manager stores this value in the Observer.Entity.SvcComp field in the XDAS event.

Initiator.Account.Domain

Identity Manager stores this value in the Initiator.Account.Domain field in the XDAS event.

Initiator.Account.Name

Identity Manager stores this value in the Initiator.Account.Name field in the XDAS event.

Initiator.Account.Id

Identity Manager stores this value in the Initiator.Account.Id field in the XDAS event.

Initiator.Entity.SysAddr

Identity Manager stores this value in the Initiator.Entity.SysAddr field in the XDAS event.

Initiator.Entity.SysName

Identity Manager stores this value in the Initiator.Entity.SysName field in the XDAS event.

Initiator.Entity.SvcName

Identity Manager stores this value in the Initiator.Entity.SvcName field in the XDAS event.

Initiator.Entity.SvcComp

Identity Manager stores this value in the Initiator.Entity.SvcComp field in the XDAS event.

Initiator.Assertions

Identity Manager stores this value in the Initiator.Assertions field in the XDAS event.

Target.Account.Domain

Identity Manager stores this value in the Target.Account.Domain field in the XDAS event.

Target.Account.Name

Identity Manager stores this value in the Target.Account.Name field in the XDAS event.

Target.Account.Id

Identity Manager stores this value in the Target.Account.Id field in the XDAS event.

Target.Entity.SysAddr

Identity Manager stores this value in the Target.Entity.SysAddr field in the XDAS event.

Target.Entity.SysName

Identity Manager stores this value in the Target.Entity.SysName field in the XDAS event.

Target.Entity.SvcName

Identity Manager stores this value in the Target.Entity.SvcName field in the XDAS event.

Target.Entity.SvcComp

Identity Manager stores this value in the Target.Entity.SvcComp field in the XDAS event.

Target.Data

Identity Manager stores this value in the Target.Data field in the XDAS event.

Action.Event.CorrelationID

Identity Manager stores this value in the Action.Event.CorrelationID field in the XDAS event.

Action.Event.Subevent

Identity Manager stores this value in the Action.Event.Subevent field in the XDAS event.

Action.Time.Offset

Identity Manager stores this value in the Action.Time.Offset field in the XDAS event.

Example