Requirement:
To view audit events, you must belong to a group that has the following enforced filter:
/All Filters/ArcSight Administration/ESM/System Health/Events/Audit/ArcSight Audit Events
This event filter is added to the group’s ACL Editor settings on the Events tab and applies to audit events for all resources. Refer to Adding or Removing Enforced Filters for instructions.
To view internal audit events on cases:
Through an active channel, query viewer, or data monitor using the proper filter, you can view details on modifications done to cases.
Refer to Monitoring Events for the different ways to create an event viewer.
Use the following fields in your event viewer to capture audit events related to the case:
Field or Column |
Displayed Information |
---|---|
Name |
Event name, for example, |
File Name |
The case’s name |
Target User Name |
The user who made the change |
Device Custom String3 |
For the “ |
Device CustomString4 |
For the “ |
Device CustomString5 |
For the “ |
Tip: After the event viewer retrieves the data:
Copy the resource ID of interest displayed in Device Custom String4.AttachedToID
).
Paste the ID into the Console’s search box and go to the actual case resource on the Navigator panel.