Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Audit logs

Want to summarize with AI?

Log in

Use audit logs to review supported user authentication and configuration actions in Cyber Vision.


Understand the user actions that Cyber Vision records and the information available for each audit event.

Cyber Vision records supported user actions in the audit log. Audit records help administrators review user activity and configuration changes.

Examples of recorded actions include:

  • User authentication

  • Creation of an organization hierarchy level

  • Assignment of a network to an organization hierarchy level

Note

Cyber Vision does not currently record every user action. For example, sensor onboarding actions might not appear in the audit log.

Table 1. Feature History Table

Feature

Release Information

Feature Description

Audit logs

Release 5.6.x

Cyber Vision records supported user authentication and configuration actions. Authorized users can review and export audit records and configure the audit-log retention period.

Table 2. Audit record details

Field

Description

Date

Shows when the audited event occurred.

Username

Identifies the user who performed the action.

Type

Identifies the category of the audited event.

Status

Shows whether the action succeeded or failed.

Description

Provides details about the audited action. Select View more to display additional information.


View audit logs

View audit records to review user activity and configuration changes in Cyber Vision.

Cyber Vision displays the actions that it currently supports for auditing. The Audit page is available from the user menu.

Before you begin

Ensure that your user role has Read permission for Audit.

Procedure

  1. In the upper-right corner of the Cyber Vision interface, select your username to open the user menu.

  2. Select Audit.

  3. Review the audit records.

    The table displays the date, username, event type, status, and description for each recorded event.

  4. Use the available actions as required:

    • Select View more to display the complete description of an event.
    • Select the filter icon to narrow the displayed audit records.
    • Select Export to download the audit records.

Cyber Vision displays the available audit records. If you export the records, Cyber Vision downloads the audit data.

What to do next

Configure the audit-log retention period if you need to change how long Cyber Vision retains audit records.


Configure audit log retention

Set the number of days that Cyber Vision retains audit records.

Cyber Vision retains audit records for 90 days by default. You can configure the retention period from 7 through 365 days.

Before you begin

Ensure that your user role has Write permission for Audit.

Procedure

  1. In the upper-right corner of the Cyber Vision interface, select your username to open the user menu.

  2. Select Audit.

  3. Select the settings icon.

  4. In Retention period, enter a value from 7 through 365 days.

  5. Select Save.

Cyber Vision retains audit records for the configured number of days.

What to do next

Review the Audit page periodically to monitor recorded user activity and configuration changes.