Red Hat Bugzilla – Bug 1155817
[RFE] Improve auditing and externalize audit logs
Last modified: 2018-10-16 11:27:09 EDT
Since this issue was entered in Red Hat Bugzilla, the release flag has been set to ? to ensure that it is properly evaluated for this release.
Connecting redmine issue http://projects.theforeman.org/issues/6752 from this bug
It may be possible to use foreman_hooks in the short term in order to do _something_ when audit records are created. Foreman_hooks is delivered with Satellite 6. The doco is missing, but you can read about it upstream at https://github.com/theforeman/foreman_hooks
Upstream bug component is Audit Log
Hi, I have a case where customer is requesting some additional feature in audit logs as below : The additional audit functionality requested is: - Auditing of all USER actions performed via the Web, hammer and API interfaces - Internal automated processes should be excluded from these audits - Ideally logs should be produced in XML format, although syslog-compatible format would also be acceptable. The User Audit logs need to include: - Event Timestamp - The activity that generated the entry - The item that has been changed due to the activity, with details of the change - The username of the user that initiated the activity - The status of the event, either success or failure Some example events that would trigger these new audit logs would be: - User login and logout from (including session timeout) the web interface - Account creation, modification, locking or deletion - Account role/attribute assignment/de-assignment - Modification of data (changes to hosts, host groups, locations, content views, activation keys etc) - Deletion of data Will it be possible to incorporate in Satellite 6.2 ? Thanks
Hello, More requirements on the audit logs : Customer requires more detailed activity details in the audit log which will describe what the user has actually modified. For example: Currently Satellite 6 reports in the UI that "User X modified view Y at Date/time". It doesn't say What the user actually modified inside the content view, but we require this detail for audit logging. Would it be possible to include this request in this RFE ? This is very important for the customer. Thank you
Thank you for the additional detail.
Per 6.3 planning, moving out non acked bugs to the backlog
*** Bug 1403137 has been marked as a duplicate of this bug. ***
*** Bug 1269261 has been marked as a duplicate of this bug. ***
*** Bug 980152 has been marked as a duplicate of this bug. ***
*** Bug 1539084 has been marked as a duplicate of this bug. ***
Upstream bug assigned to mhulan@redhat.com
Moving this bug to POST for triage into Satellite 6 since the upstream issue http://projects.theforeman.org/issues/6752 has been resolved.
putting this to verified since all the bugs related to the feature have been resolved
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2018:2927