Set audit policies
Use
Audit Policy Properties
to specify what security-related information is recorded while the system is being used. Audit policies include whether access checks are audited, whether access grants, denies, or both are audited, and so on. Audit messages are sent to FactoryTalk Diagnostics
, and are viewed using the FactoryTalk Diagnostics
Viewer. To set up audit policies
- InFactoryTalk Administration ConsoleExplorer, expandSystem>Policies>System Policies.
- Right-clickAudit Policyand selectProperties.
- InAudit Policy Properties,for each policy setting listed choose eitherEnabledorDisabled.
- Audit changes to configuration and control system
- Enabled(default) - Generates audit messages when configuration and control system changes occur across theFactoryTalksystem.
- Disabled -Does not route audit messages toFactoryTalk Diagnosticslog files, even if logging destinations are configured for audit messages on theMessage Routingtab in.FactoryTalk DiagnosticsSetup
Any changes made to the value of theAudit changes to configuration and control systempolicy itself are always recorded, regardless of whether audit logging is enabled or disabled. If enabled, audit information is sent toFactoryTalk Diagnostics. - Audit security access failures
- Enabled- Generates audit messages when users fail to access objects or features because of insufficient security permissions.
- Disabled(default) - Does not generate audit messages when users fail to access secured objects or features.
- Audit security access successes
- Enabled- Generates audit messages when users succeed in accessing objects or features because of sufficient security permissions.
- Disabled(default) - Does not generate audit messages when users succeed in accessing objects or features because of sufficient security permissions.
When enabled, this policy might generate a large number of audit messages. Enable this policy only if there is a specific reason, for example, testing or troubleshooting whether users are able to access particular features or objects in the system. If enabled, audit information is sent toFactoryTalk Diagnostics.
- SelectOK.
Provide Feedback