Audit Log Viewer (Service)


 

There is a built-in audit log viewer that allows you to retrieve DeviceLock audit log records from a computer's local Windows event logging subsystem

 

The standard Windows event logging subsystem is used to store audit records, only if Event Log or Event & DeviceLock Logs is selected in the Audit log type parameter in Service Options. Otherwise, audit records are stored in the proprietary log and can be viewed using the server's audit log viewer.

 

The audit log stores events generated by a user's device-related activities that fall under the audit rules. Also, changes in a DeviceLock Service's configuration generate events in the audit log, if the appropriate flag is enabled in Service Options.

 

The columns of this viewer are defined as follows:

 

 

 

 

 

 

 

 

 

 

 

When you need to force moving the audit data from the current computer to the server, use Send Data to Server. This function is available only  if DeviceLock Enterprise Server is defined in Service Options and DeviceLock Log or Event & DeviceLock Logs is selected in the Audit log type parameter in Service Options.

 

Use Refresh to refresh the list of events.

 

To clear all events from the audit log, select Clear.

 

To filter records in this list, select Filter.