Sun Java System Access Manager 7.1 Technical Overview

Access Manager Component Logs

The log files record a number of events for each of the Access Manager components using the Logging Service. Administrators typically review these log files on a regular basis. The default location for all Access Manager log files is /var/opt/SUNWam/logs when Access Manager is installed in a Solaris environment. (When installed on Windows, the directory is jes-install-dir\identity\logs; on HP-UX the directory is /var/opt/sun/identity/logs.) The following table provides a brief description of the log files produced by each Access Manager component.

Table 6–3 Access Manager Component Logs

Component 

Log Filename 

Information Logged 

Session 

  • amSSO.access

Session management attributes values such as login time, logout time, and time out limits. Also session creations and terminations. 

Administration Console 

  • amConsole.access

  • amConsole.error

User actions performed through the administration console such as creation, deletion and modification of identity-related objects, realms, and policies. amConsole.access logs successful console events while amConsole.error logs error events.

Authentication 

  • amAuthentication.access

  • amAuthentication.error

User logins and log outs, both successful and failed. 

Federation 

  • amFederation.access

  • amFederation.error

  • amLiberty.access

  • amLiberty.error

Federation-related events such as the creation of an authentication domain or the creation of a hosted provider entity. 

Authorization (Policy) 

  • amPolicy.access

  • amPolicy.error

  • amAuthLog

Policy-related events such as policy creation, deletion, or modification, and policy evaluation. amPolicy.access logs policy allows, amPolicy.error logs policy error events, and amAuthLog logs policy denies.

Policy Agent 

amAgent

Exceptions regarding resources that were either accessed by a user or denied access to a user. amAgent logs reside on the server where the policy agent is installed. Agent events are logged on the Access Manager machine in the Authentication logs.

SAML 

  • amSAML.access

  • amSAML.error

SAML-related events such as assertion and artifact creation or removal, response and request details, and SOAP errors. 

Command-line 

  • amAdmin.access

  • amAdmin.error

Event successes and errors that occur during operations using the command line tools. Examples are: loading a service schema, creating policy, and deleting users. 

Password Reset 

  • amPasswordReset.access

Password reset events. 

For detailed reference information about events recorded in each type of Access Manager log, see the Sun Java System Access Manager 7.1 Administration Guide.