Configure audit settings

You can enable auditing of administrator or security events in BlackBerry UEM. When auditing is enabled, you can choose how long you want to keep records, the number of results to display, and when to delete old records. When auditing is disabled, all records are deleted.

This feature is not supported for BlackBerry UEM Cloud.

Note: Enabling security event auditing requires significant database resources.
  1. In the management console, on the menu bar, click Settings > Infrastructure > Audit settings.
  2. In the right pane, click The Edit icon.
  3. In the Administrator event audit settings section:
    1. In the Administrator event auditing drop-down list, click Enabled.
    2. In the Administrator audit record retention field, type the maximum number of days to keep a record.
    3. In the Maximum number of records field, type the maximum number of records to display in the UI. If the number of records exceeds this value, then the administrator must shorten the date range or select a category to reduce the number of records.
    4. In the Daily delete time (UTC) field, choose the time of day to delete records.
  4. In the Security event audit settings section:
    1. In the Security event auditing drop-down list, click Enabled.
    2. In the Security audit record retention field, type the maximum number of days to keep a record.
    3. In the Daily delete time (UTC) field, choose the time of day to delete old records.
    4. To stop auditing a security event, click The Remove icon beside the event type.
    5. To add security events to audit, click The Add icon. Select the events and click Add.
    6. Optionally, if a drop-down list is available in the Setting column beside an event type, choose the condition to log the event.
  5. Click Save.
  • Restart the BlackBerry UEM Core service on every computer that hosts a BlackBerry UEM instance.
  • Log in to the management console again.
  • To export all security audit events to a .csv file, in the Security event auditing settings section, click Export.
  • To delete audit records before the next daily delete time, in the Administrator event auditing settings section or the Security event auditing settings section, click Delete.
  • To disable administrator event auditing and purge all records, in the Administrator event auditing drop-down list, click Disabled.
  • To disable security event auditing and purge all records, in the Security event auditing drop-down list, click Disabled.