OpenAM Audit Logging
OpenAM writes log messages generated from audit events triggered by its components, instances, and other Open Identity Platform-based stack products.
Audit Log Format
This chapter presents the audit log format for each topic-based file, event names, and audit constants used in its log messages.
Access Log Format
| Schema Property | Description |
|---|---|
|
Specifies a universally unique identifier (UUID) for the message object, such as |
|
Specifies the timestamp when OpenAM logged the message, in UTC format to millisecond precision: |
|
Specifies the name of the audit event. For example, |
|
Specifies the UUID of the transaction, which identifies an external request when it comes into the system boundary. Any events generated while handling that request will be assigned that transaction ID, so that you may see the same transaction ID even for different audit event topics. For example, OpenAM supports a feature where trusted OpenAM deployment with multiple instances, components, and Open Identity Platform stack products can propagate the transaction ID through each call across the stack. OpenAM reads the `X-ForgeRock-TransactionId` HTTP header and appends an integer to the transaction ID. Note that this feature is disabled by default. When enabled, this feature should filter the `X-ForgeRock-TransactionId` HTTP header for connections from untrusted sources. |
|
Specifies the universal identifier for authenticated users. For example, |
|
Specifies a unique random string generated as an alias for each OpenAM session ID and OAuth 2.0 token. In releases prior to OpenAM 13.0.0, the OpenAM 13.0.0 extends this property to handle OAuth 2.0 tokens. In this case, whenever OpenAM generates an access or grant token, it also generates unique random value and logs it as an alias. In this way, it is possible to trace back an access token back to its originating grant token, trace the grant token back to the session in which it was created, and then trace how the session was authenticated. An example of a `trackingIds` property in an OAuth 2.0/ OpenID Connect 1.0 environment is: `[ "1979edf68543ead001", "8878e51a-f2aa-464f-b1cc-b12fd6daa415", "3df9a5c3-8d1e-4ee3-93d6-b9bbe58163bc" ]` |
|
Specifies the IP address of the OpenAM server. For example, |
|
Specifies the port number used by the OpenAM server. For example, |
|
Specifies the client IP address. |
|
Specifies the client port number. |
|
Specifies the protocol associated with the request operation. Possible values: |
|
Specifies the request operation. For CREST operations, possible values: |
|
Specifies the detailed information about the request operation. For example, |
|
Specifies if the request was sent over secure HTTP. For example, |
|
Specifies the HTTP method requested by the client. For example, |
|
Specifies the path of the HTTP request. For example, |
|
Specifies the HTTP query parameter string. For example, |
|
Specifies the HTTP header for the request. For example, (Note: Line feeds added for readability purposes):
|
|
Not used. |
|
Specifies the HTTP header for the response. |
|
Specifies the response status of the request. Normally, |
|
Specifies the response status code, depending on the protocol. For CREST, HTTP failure codes are displayed but not HTTP success codes. For PLL endpoints, PLL error codes are displayed. |
|
Specifies the message associated with |
|
Specifies the time to execute the access event, usually in millisecond precision. |
|
Specifies the elapsed time units of the response. For example, |
|
Specifies the OpenAM service utilized. For example, |
|
Specifies the realm where the operation occurred. For example, the Top Level Realm ( |
Activity Log Format
| Property | Description |
|---|---|
|
Specifies a universally unique identifier (UUID) for the message object, such as |
|
Specifies the timestamp when OpenAM logged the message, in UTC format to millisecond precision: |
|
Specifies the name of the audit event. For example, |
|
Specifies the UUID of the transaction, which identifies an external request when it comes into the system boundary. Any events generated while handling that request will be assigned that transaction ID, so that you may see the same transaction ID for same even for different audit event topics. For example, |
|
Specifies the universal identifier for authenticated users. For example, |
|
Specifies an array containing a random context ID that identifies the session and a random string generated from an OAuth 2.0/OpenID Connect 1.0 flow that could track an access token ID or an grant token ID. For example, |
|
Specifies the user to run the activity as. May be used in delegated administration. For example, |
|
Specifies the identifier of an object that has been created, updated, or deleted. For OpenAM 13.0.0, only session changes are recorded, so that the session |
|
Specifies the state change operation invoked: |
|
Not used. |
|
Not used. |
|
Not used. |
|
Not used. |
|
Specifies the OpenAM service utilized. Normally, |
|
Specifies the realm where the operation occurred. For example, the Top Level Realm ( |
Authentication Log Format
| Property | Description |
|---|---|
|
Specifies a universally unique identifier (UUID) for the message object, such as |
|
Specifies the timestamp when OpenAM logged the message, in UTC format to millisecond precision: |
|
Specifies the name of the audit event. For example, |
|
Specifies the UUID of the transaction, which identifies an external request when it comes into the system boundary. Any events generated while handling that request will be assigned that transaction ID, so that you may see the same transaction ID for same even for different audit event topics. For example, |
|
Specifies the universal identifier for authenticated users. For example, |
|
Specifies an array containing a random context ID that identifies the session and a random string generated from an OAuth 2.0/OpenID Connect 1.0 flow that could track an access token ID or an grant token ID. For example, |
|
Specifies the outcome of a single authentication module within a chain, either |
|
Specifies the array of accounts used to authenticate, such as |
|
Not used |
|
Specifies the JSON representation of the details of an authentication module or chain. OpenAM creates an event as each module completes and a final event at the end of the chain. For example, |
|
Specifies the OpenAM service utilized. Normally, |
|
Specifies the realm where the operation occurred. For example, the Top Level Realm ( |
Config Log Format
| Property | Description |
|---|---|
|
Specifies a universally unique identifier (UUID) for the message object. For example, |
|
Specifies the timestamp when OpenAM logged the message, in UTC format to millisecond precision: |
|
Specifies the name of the audit event. For example, |
|
Specifies the UUID of the transaction, which identifies an external request when it comes into the system boundary. Any events generated while handling that request will be assigned that transaction ID, so that you may see the same transaction ID for different audit event topics. For example, |
|
Not used. |
|
Not used. |
|
Specifies the user to run the activity as. May be used in delegated administration. For example, |
|
Specifies the identifier of a system object that has been created, modified, or deleted. For example, |
|
Specifies the state change operation invoked: |
|
Specifies the JSON representation of the object prior to the activity. For example, |
|
Specifies the JSON representation of the object after the activity. For example, |
|
Specifies the fields that were changed. For example, |
|
Not used. |
|
Not used. |
|
Specifies the realm where the operation occurred. For example, the Top Level Realm ( |
Audit Log Event Names
The following section presents the predefined names for the audit events:
| Topic | EventName |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Audit Log Components
The following section presents the predefined audit event components that make up the log messages:
| Event Component | |
|---|---|
|
OAuth 2.0, OpenID Connect 1.0, and UMA |
|
Core Token Service |
|
Web and Java EE policy agents |
|
Authentication service |
|
Dashboard service |
|
Server information service |
|
Users component |
|
Groups component |
|
Mobile authentication |
|
Trusted devices |
|
Policies |
|
Realms and sub-realms |
|
Session service |
|
Scripting service |
|
Batch service |
|
Configuration |
|
Secure Token Service: REST and SOAP |
|
Recording service |
|
Auditing service |
|
RADIUS server |
Audit Log Failure Reasons
The following section presents the predefined audit event failure reasons:
| Failure | Description |
|---|---|
|
Incorrect/invalid credentials presented. |
|
Invalid credentials entered. |
|
Authentication chain does not exist. |
|
No user profile found for this user. |
|
User is not active. |
|
Maximum number of failure attempts exceeded. User is locked out. |
|
User account has expired. |
|
Login timed out. |
|
Authentication module is denied. |
|
Limit for maximum number of allowed sessions has been reached. |
|
Realm does not exist. |
|
Realm is not active. |
|
Role-based authentication: user does not belong to this role. |
|
Authentication type is denied. |
|
Cannot create a session. |
|
Level-based authentication: Invalid authentication level. |