Audit-On-Connect

To trace Audit on Connect activity:

1.Determine when the suspect activity will start and how long it will take to finish.

2.When the suspect activity is about to begin, type the hours and minutes you expect the activity to take in the Run AOC Trace for fields and click Start Trace.

If you type 0 hours and 0 minutes, the trace will not occur.

3.Click Refresh any time you want to check on the activity that's occurred so far. This displays the latest trace data on the page.

Trace data does not automatically display when AOC tracing is on. You need to click Refresh whenever you want to see the latest trace data.

While AOC tracing is on, it captures whether or not any activity occurs. If no trace data appears, then no activity occurred. This could mean:

you miscalculated when you should turn on AOC tracing to capture the activity you're looking for

your suspicions are true: something is wrong with Audit on Connect and it's not running when expected

The trace data from the last time you refreshed remains on the page until you click Delete Trace Data.

53

Page 61
Image 61
Symantec Security Expressions Server manual