Is it possible to determine which user tampered with the audit log in AIQUM?
Applies to
Active IQ Unified Manager - AIQUM
Answer
- It is not possible, since alert is not triggered based on a recorded change in the database
- AIQUM stores the audit log in the mysql database and generates a signature based on the log file when doing so
- AIQUM will compare the current signature result with the already stored one on a regular basis
- When there is a mismatch an alert is triggered:
Audit log File audit.<DATETIME>.gz got tampered