AUDIT TRAIL is active in admin structure and i have created an alarm list and configured it as COMMON ALARM AND EVENT LIST:AUDIT TRAIL.
All services are running. But still it is not working. How to rectify this?
Voted best answer
When you enable Audit Trail, select "Log Selected Audit Event Classes" and check it. Leave "Log Generic Audit Events" unchecked. When you do this, you will see that some of the categories in the list below gets automatically selected. From SV 5.0 SP2 Rev C onwards, only "AuditEvent_OperatorAction" category is free, so check only with Operator Actions and uncheck others.
Please check "800xA System Mesage server event collector" service status- It should be in the service state to collect the audit events.
Please check any filter applied to tracking events in the audit list,If so remove it and recheck again.
Please check AUDIT_TRAIL feature available in the license file.If not,though operator actions are free,it will not work,unless until it is present in the license file.
Please referSV 5.0 SP2 Rev C - Sys_Config manual for more details on Audit Trail Configuration.
If you still couldn't manage to fix this issue,pleae contact your nearest regional support center for the assistance.
I agree with previous answer. I also believe we've had issues with Soft Alarm service "loosing" the audit license; try restarting the Soft Alarm service and its corresponding Event Collector service providers.
With a valid audit license you are entitled to enable any audit event category. Without a license you can enable audit; but only those categories included by system default, eg "AuditEvent_OperatorAction".
Contact support if you can't work it out.
We are also having problem with audit log. We have full licence for the audit log, and made audit log list last month. The audit list last log is from 10 august and no more logs are getting in. I have restarted all of the services and one of ther servers (not primary), but without result.
Any ideas what to do?
Source: audit log