bea.com | products | dev2dev | support | askBEA |
|
e-docs > WebLogic Server > Administration Console Online Help > Compatibility Security |
Administration Console Online Help |
WebLogic Auditing Provider-->General
Tasks Related Topics Attributes
Use this tab to configure a WebLogic Auditing provider for a security realm.
Note: The Administration Console refers to the WebLogic Auditing provider as the Default Auditor.
Auditing is the process whereby information about operating requests and the outcome of those requests are collected, stored, and disturbed for the purposes of non repudiation. In other words, auditing provides an electronic trail of computer activity. In the WebLogic Server security architecture, an Auditing provider is used to provide auditing services.
If configured, the WebLogic Server Security Framework will call through to an Auditing provider before and after security operations (such as authentication or authorization) have been performed, enabling audit event recording. The decision to audit a particular event is made by the Auditing provider itself and can be based on specific audit criteria and/or severity levels. The records containing the audit information may be written to output repositories such as an LDAP back-end, database, and a simple file.
All auditing information recorded by the WebLogic Auditing provider is saved in WL_HOME\yourdomain\DefaultAuditRecorder.log.
You can use a Custom Auditing provider instead of the WebLogic Auditing provider. For a Custom Auditing provider to be available through the WebLogic Server Administration Console, the MBean JAR file for the provider must be in the WL_HOME\lib\mbeantypes directory.
Configuring a WebLogic Auditing Provider
Introduction to WebLogic Security
Developing Security Providers for WebLogic Server
Securing a WebLogic Server Deployment
Upgrading Security in WebLogic Server Version 6.x to WebLogic Server Version 7.0
The Security page in the WebLogic Server documentation