Configure audit settings
This feature is not supported for BlackBerry UEM Cloud.
- In the management console, on the menu bar, click Settings > Infrastructure > Audit settings.
-
In the right pane, click
.
-
In the Administrator event audit settings section:
- In the Administrator event auditing drop-down list, click Enabled.
- In the Administrator audit record retention field, type the maximum number of days to keep a record.
- In the Maximum number of records field, type the maximum number of records to display in the UI. If the number of records exceeds this value, then the administrator must shorten the date range or select a category to reduce the number of records.
- In the Daily delete time (UTC) field, choose the time of day to delete records.
-
In the Security event audit settings section:
- In the Security event auditing drop-down list, click Enabled.
- In the Security audit record retention field, type the maximum number of days to keep a record.
- In the Daily delete time (UTC) field, choose the time of day to delete old records.
-
To stop auditing a security event, click
beside the event type.
-
To add security events to audit, click
. Select the events and click Add.
- Optionally, if a drop-down list is available in the Setting column beside an event type, choose the condition to log the event.
- Click Save.
- Restart the BlackBerry UEM Core service on every computer that hosts a BlackBerry UEM instance.
- Log in to the management console again.
- To export all security audit events to a .csv file, in the Security event auditing settings section, click Export.
- To delete audit records before the next daily delete time, in the Administrator event auditing settings section or the Security event auditing settings section, click Delete.
- To disable administrator event auditing and purge all records, in the Administrator event auditing drop-down list, click Disabled.
- To disable security event auditing and purge all records, in the Security event auditing drop-down list, click Disabled.