12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

13Managing <strong>McAfee</strong> DLP systemsManaging users and groupsMonitoring audit logsAudit logs record all user activity on the <strong>McAfee</strong> DLP systems. Administrative permissions are requiredto view the logs.Audit logs are located on the User Administration pages. The log elements can be rearranged by clickingheaders, and the Filter by feature in the navigation pane can be used to sort the results.Auditing live usersThe Live Users feature records all activity in all live sessions. Administrator permissions are required toview the records.Live user records are available on the User Administration | Live Users page. The Session Id links directly tothe records of the users who are logged in.Audit log actionsAll user actions are sorted into categories when they are logged.Table 13-5 Summary of Audit Log ActionsCategoryDevicesStatisticsAliasCapture filtersConfigurationActionsView, add, edit, deleteView, view details, view system logs, delete system logsCreate, modify, delete alias; view alias listCreate, modify, delete, update, apply capture filters; view capture filter list;restore factory defaultsShow, modify system configuration; modify IP managementUsers and user groups View, delete user audit logs; view user and use group accounts; add localand LDAP users; add, modify, delete, view, search for users; add, modify,delete user groups; view users group members and group listsPermissionsServersCasesPolicies/rulesSearchDiscoverSummariesDashboardIncidentsReportsLoginStatistics/ResultsUtilitiesView group, task, policy, user permissions; update user and taskpermissions; view, update failover setupView, create, modify, delete, update DHCP and LDAP servers; add LDAPdomainView cases, view opening of casesCreate, modify, delete, view policies; export/import policies and rules; view,download exported policies, rules, reports; view runtime, configuration ofrules; view policy deployment status and error; view policy scheduleCreate, view, schedule, deschedule search; view search list, details,document, object; create document, email, FTP, image search; view searchdetailFetch, upload, attach file; show, cancel file uploadView incident, user, location, risk, network, case summariesDisplay, delete, save, create dashboard views; export dashboardDetect view incident annotations, history, attributes, matches; mark incidentfor deletion, as false positive, as read/unreadView, create, show reports and scheduled reportsLog on, logoutView, delete, modify, who exports files/results, modify results per pageView utilities, kernel version, system uptime, application version; show help,view status/version information; show disk capacity; display flow statistics278 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!