You can generate access and activity audits for your organization s Cisco ScanCenter account. You can also configure email alerts to notify you of failed Cisco ScanCenter login attempts. You must have the correct role to be able to perform these tasks. For more information on roles, see Role Permissions. Email Alerts, page 1 Access Audit, page 2 Activity Audit, page 3 Report Execution, page 4 Report Management, page 5 Log Extraction Audit, page 6 Email Alerts In the Audit menu, click Access Settings to display the Access Settings page. OL-22629-06 1
Access Audit When a user account is locked, following a series of failed login attempts, the user is instructed to send an email to an administrator to unlock the account. Enter the administrate email address to display in the Contact email in the login failure message box. If no address is provided, the organization super user s email address is displayed. Select the Enable email alerts check box to send an email whenever there is a failed login attempt. Enter up to five email addresses in the boxes. Step 6 In the Max frequency drop-down, choose the number of email alerts to batch together (1 to 20). Step 7 In the Period drop-down, choose the delay between emails in hours (1 to 24). Step 8 Click Save to apply your changes. Alternatively, navigate away from the page to abandon your changes. Access Audit Generating an access audit enables you to see all the login attempts that have occurred in Cisco ScanCenter over a period of time, from a day up to a year. In the Audit menu, click ScanCenter Access. 2 OL-22629-06
Activity Audit c) Enter an end date in the box or click the Calendar icon to choose a date Step 6 Step 7 Step 8 Clear the All Admins check box and choose an admin user in the or select an Admin drop-down list. Alternatively, select the All Admins check box to include all admin users. Select the Unsuccessful Login check box to include unsuccessful login attempts in the audit. Alternatively, clear the check box to exclude unsuccessful login attempts. Select the Successful Login check box to include successful login attempts in the audit. Alternatively, clear the check box to exclude successful login attempts. Activity Audit Generating an activity audit enables you to see all the administration activity that has taken place in Cisco ScanCenter over a period of time, from a day up to a year. provide a record of changes to administration, configuration, filtering, and policy. The audit is downloaded as a CSV file containing the username, category type, action, log time, and a description for each logged event. In the Audit menu, click ScanCenter Activity. OL-22629-06 3
Report Execution Step 6 Clear the All Admins check box and choose an admin user in the or select an Admin drop-down list. Alternatively, select the All Admins check box to include all admin users. Clear the All Categories check box and choose a category in the or select a Category drop-down list. The available categories are: Administration Filtering Policy HTTPS Inspection Spyware Policy Web Virus Policy Step 7 Alternatively, select the All Categories check box to include all categories. Clear the All Actions check box and choose an action in the or select an Action drop-down. The available actions are: INSERT UPDATE DELETE Step 8 Alternatively, select the All Actions check box to include all actions. Report Execution Generating a report execution audit enables you to see all the reports that have been run in Cisco ScanCenter over a period of time, from a day up to a year. The audit is downloaded as a CSV file containing the username, report name, and log time. In the Audit menu, click Report Execution to display the Report Execution page. 4 OL-22629-06
Report Management Report Management Generating a report management audit enables you to see who's created, modified, or deleted what reports and report related entities in Cisco ScanCenter over a period of time, from a day up to a year. The audit is downloaded as a CSV file containing the username, entity type, entity name, action, and log time. In the Audit menu, click Report Management to display the Report Management page. OL-22629-06 5
Log Extraction Audit Log Extraction Audit Generating a log extraction audit enables you to see all the log extractions that have been run in Cisco ScanCenter over a period of time, from a day up to a year. The audit is downloaded as a CSV file containing log date, access IP address, event type, quantity, and HTTP status code. In the Audit menu, click Log Extraction. 6 OL-22629-06