Menu

View audit logs

To view the log of audit events, complete the following steps:

1. Navigate to History > Audit Log.

2. Search for the audit logs you want to view.

  • You can search for audit logs by selecting the audit event type and the log period.
    • Audit Type: Select the audit event type. Console/Server includes the history of device commands sent from the Admin Portal and the changes made due to batch tasks on the server. Device includes the history of policies applied to mobile devices, device enrollment, and the event occurred on devices, such as revoking the enrollment of the Knox Manage agent.
    • Log Date: Select the start and end date of the log period.
  • You can also search for audit logs by using the search field. Search within search results is available.

3. View the audit logs.

  • The View field displays the request ID. The request ID helps to track how the audit event is applied to a device. The first three letters of the request ID complies with the following rule:

    • The first letter: Mobile OS of the device (A: Android, I: iOS, W: Windows)
    • The second letter: Application type (A: Android/iOS Knox Manage agent, C: iOS Knox Manage Client)
    • The third letter: Start point of the process (S: Server, D: Device)

    E.g. AAS: The audit event started from the server and applied to the Knox Manage agent installed on the Android device.

  • The User ID field displays the source of the audit event. If the audit event type is Console/Server, refer to the following information:

    • When the audit event occurs while sending a device command or operating Knox Manage, the administrator’s ID is displayed.

    • When a device command is sent, the administrator’s ID is displayed.

    • When a scheduled task is performed on the server, “SYSTEM” or the batchuser ID is displayed.

  • The View field displays the request ID. The request ID helps to track how the audit event is applied to a device. The first three letters of the request ID complies with the following rule:
    • The first letter: Mobile OS of the device (A: Android, I: iOS, W: Windows)
    • The second letter: Application type (A: Android/iOS Knox Manage agent, C: iOS Knox Manage Client)
    • The third letter: Start point of the process (S: Server, D: Device)

E.g. AAS: The audit event started from the server and applied to the Knox Manage agent installed on the Android device.

  • The Device Name field displays the name of the device on which the audit event occurred. If there is no device or the audit event is a scheduled task, blank is displayed.
  • If you can click in the row of a log, you can view the following information.

Item

Description

Process Info

  • Request History: Detailed request of the audit event
  • Result Code: The audit event result and its code
  • Result History: Detailed result of the audit event. When you change a policy in the Admin Portal, a new event is recorded in the profile category. E.g.) When an Android policy is changed, all policy events to be saved in the request history of “Save General Policy” are displayed.

Log Data

This information appears only for the following audit events.

  • The Server type: Agent Request to lock screen (Device → Server), Agent Request to unlock device (Device → Server), Agent Request for work report (Device → Server), Handle multiple devices by sending device control
  • The Device type: Device Lock/Unlock History

4. To view the detailed flow of an audit event, click the request ID in the View field.

5. In the “Audit Event” window, view each audit log.

  • The request ID helps track how the audit event is applied to a device. Click to view more details.