Audit: Configuration Reference
Select an Audit Service Configuration Instance
Select from the following list of configuration instances to find the values in that category.
- sas.audit.reporting.activities configures the copy of activity records from the audit service to CAS and sets their retention period.
- sas.audit.archive.process configures the archive transfer job, retention in the CAS database audit service, and retention in the audit archive.
- sas.audit.archive.system specifies the location of the audit archive and the available-storage limit.
- sas.audit.purge enables purge and sets the audit purge schedule.
- sas.audit.record determines whether READ actions create audit records and specifies the amount of information that is stored in activity records.
- sas.audit.reporting configures the copy of records to the CAS server for reporting.
- sas.audit.poller polls the pending audit data retrieval jobs list and sends the oldest for processing.
Audit Activities
sas.audit.reporting.activities
|
Definition |
Description |
Default |
|
enabled |
Enables the copying of records from the audit database to CAS for the creation of reports. |
True |
|
query.page.size |
Specifies the number of records that are copied from the audit database to CAS for the creation of reports. |
5,000 |
|
refresh.schedule |
Schedules the job that copies records from the audit database to CAS. |
*/30 * * * * The default value uses standard cron syntax to refresh CAS every 30 minutes. A value of 0 */1 * * * refreshes CAS every hour. |
|
retention |
Specifies the length of time that activity records are retained in the SystemData database in CAS. The retention value must be equal to, or less than, the value of activity.retention in sas.audit.archive.process. |
180d |
sas.audit.archive.process
|
Definition |
Description |
Default Value |
|
activity.retention |
Specifies the length of time that activity records are retained in the audit database. The value of activity.retention must be greater than, or equal to, the retention value in sas.audit.reporting.activities. |
365d One year |
|
activity.retention.in.archive |
Specifies the length of time that activity records are retained in the audit archive. |
1827d Five years |
|
audit.retention |
Specifies the length of time that audit records are retained in the audit database. The value of audit.retention must be greater than, or equal to, the retention value in sas.audit.reporting. IMPORTANT Increasing the value of audit.retention increases the volume of data in the audit database. The increased volume in the audit database leads to a decrease in system performance. Instead of increasing retention in the audit database, SAS recommends that you attach a persistent volume and set the property storageType to Local. The PV makes audit data available without increasing database volume. |
7d |
|
audit.retention.in.archive |
Specifies the length of time that audit records are retained in the audit archive. |
1827d |
|
batchSize |
Specifies the maximum number of audit and activity records that are processed in a single batch by an instance of the archive job. Also specifies the maximum number of records in a daily archive file. |
1,000 |
|
enabled |
Enables or disables the transfer of audit and activity records from the audit database to the audit archive. |
On |
|
scanSchedule |
Schedules the job that transfers audit and activity records from the audit database to the audit archive. |
0 0 * * * Cron syntax transfers records to the archive each night at midnight. See also sas.audit.archive.system. |
|
storageType |
The default value
|
none | local |
Audit Entries
sas.audit.archive.system
|
Definition |
Description |
Default Value |
|
storage.local.destination |
Specifies the audit archive storage location. |
/auditData |
|
storage.local.remainingSpaceThreshold |
Specifies the percentage of available storage in the archive PV that triggers a notification. For example, a value of 20 generates a notification in SAS Environment Manager when the size of the archive file system exceeds 80% of the PV. When the threshold is exceeded, transfers from the database to the archive continue as scheduled until PV storage reaches 100%. When the PV is full, transfers cease, timed-out records in the database are discarded, and another notification is generated. |
25 |
sas.audit.archive.process
|
Definition |
Description |
Default Value |
|
activity.retention |
Specifies the length of time that activity records are retained in the audit database. The value of activity.retention must be greater than, or equal to, the retention value in sas.audit.reporting.activities. |
365d One year |
|
activity.retention.in.archive |
Specifies the length of time that activity records are retained in the audit archive. |
1827d Five years |
|
batchSize |
Specifies the maximum number of audit and activity records that are processed in a single batch by an instance of the archive job. Also specifies the maximum number of records in a daily archive file. |
1,000 |
|
enabled |
Enables or disables the transfer of audit and activity records from the audit database to the audit archive. |
On |
|
scanSchedule |
Schedules the job that transfers audit and activity records from the audit database to the audit archive. |
0 0 * * * Cron syntax transfers records to the archive each night at midnight. See also sas.audit.archive.system. |
|
storageType |
The default value
|
none | local |
sas.audit.purge
|
Definition |
Description |
Default Value |
|
enabled |
Enables the purging of records from the audit archive. |
On |
|
purgeSchedule |
Schedules the job that purges expired records from the audit archive. |
0 0 * * * Cron syntax purges the archive each night at midnight. |
sas.audit.record
|
Definition |
Description |
Default |
|
activities.exclusion list |
Comma-separated list of service names for which activity events will not be recorded. |
None |
|
activity.recording.level |
Specifies a value that
determines the number of activity records that are created in
response to incoming activity events. Valid values are
|
high |
|
audit.exclusion.list |
Comma-separated list of service names for which resource-type audit events will not be recorded. |
None |
|
audit.recording.level |
Specifies a value that
determines the number of audit records that are created by
incoming resource and security events. Valid values are
IMPORTANT Do not set audit.recording.level to HIGH. The HIGH setting results in a large increase in new audit records, which can degrade system performance and overload the audit database. To generate audit records for READ events, use the following services.list configuration property to target a small subset of SAS Viya services. To learn how resource and security events become audit records, see Configure the Creation of Audit Records. |
Disabled |
|
services.list |
Specifies a comma-separated list of serviceNames. All READ events from each named service generate audit or activity records in the audit database. These READ-access records are created without regard to activity.recording.level or audit.recording.level. To return a list of valid serviceNames, use the following command:
|
None |
sas.audit.reporting
|
Definition |
Description |
Default |
|
app.list |
Specifies the applications whose audit records are copied from the audit database into SystemData. The records in SystemData are read by CAS to generate the User Activity Report and other reports. The value of this configuration instance is a comma-separated list of serviceNames. To return a list of available serviceNames, enter the following command:
|
reports, dataPlans, casManagement, casAccessManagement, SASLogon |
|
enabled |
Enables the copying of audit records from the audit database to CAS. |
True |
|
include.app.records |
Determines whether audit records from SAS applications are copied from the audit database to CAS. |
true |
|
query.page.size |
Specifies the maximum number of audit records that are copied from the audit database to CAS in a single job. |
5,000 |
|
refresh.schedule |
Schedules the job that copies audit records into CAS. |
0 */2 * * * The default value uses standard cron syntax to refresh the audit database every two hours. A value of */30 * * * * refreshes the database every 30 minutes. |
|
retention |
Specifies the length of time that audit records are retained in SystemData as source data for reports that are generated by CAS. The retention value must be equal to, or less than, the value of the audit.retention value in sas.audit.archive.process. |
7d |
sas.audit.poller
|
Definition |
Description |
Default |
|
schedule |
Schedules poller job to check for jobs that are in progress or eligible to be retried. Jobs that don't complete are rerun three times before being marked as failed. |
|
The schedule uses 6-field cron format.